EliseZeroTwo / SEH-Helper
Binary Ninja plugin for exploring Structured Exception Handlers
☆81Updated 5 months ago
Related projects ⓘ
Alternatives and complementary repositories for SEH-Helper
- ☆131Updated last year
- Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).☆115Updated 2 months ago
- ☆43Updated 2 years ago
- MalUnpack companion driver☆92Updated 5 months ago
- The Windbg extension that implements commands helpful to study Hyper-V on Intel processors.☆130Updated last month
- IOCTLpus can be used to make DeviceIoControl requests with arbitrary inputs (with functionality somewhat similar to Burp Repeater).☆85Updated 2 years ago
- BYOVD: Loading dbk64.sys and grabbing a handle to it☆149Updated 2 years ago
- A code parser for C-Style header files that lets you to parse function's prototypes and data types used in their parameters.☆93Updated 2 years ago
- Resolve DOS MZ executable symbols at runtime☆93Updated 3 years ago
- arbitrary kernel read/write in dbutil_2_3.sys, Proof of Concept Local Privilege Escalation to nt authority/system☆53Updated 3 years ago
- An x64dbg plugin which helps make sense of long C++ symbols☆59Updated last year
- a PE Loader and Windows API tracer. Useful in malware analysis.☆137Updated 2 years ago
- clone of armadillo patched for windows☆46Updated 3 weeks ago
- ☆31Updated 2 years ago
- Collection of obfuscation, tamper-proofing, and watermarking algorithms targeting LLVM IR.☆71Updated 5 years ago
- An example of how x64 kernel shellcode can dynamically find and use APIs☆103Updated 4 years ago
- Local OXID Resolver (LCLOR) : Research and Tooling☆33Updated 3 years ago
- ☆65Updated last year
- Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard☆237Updated 2 years ago
- Simple windows API logger☆98Updated 5 years ago
- Finding Truth in the Shadows☆84Updated last year
- File system minifilter driver for Windows to block symbolic link attacks.☆51Updated 3 years ago
- Static Binary Instrumentation tool for Windows x64 executables☆180Updated 3 weeks ago
- ☆17Updated 3 years ago
- Helper idapython code for reversing kmdf drivers☆67Updated 2 years ago
- Helper script for Windows kernel debugging with IDA Pro on VMware + GDB stub (including PDB symbols)☆62Updated last year
- A journal for $6,000 Riot Vanguard bounty.☆57Updated last year
- Binary Ninja plugin that can be used to apply Triton's dead store eliminitation pass on basic blocks or functions.☆58Updated 4 months ago
- A collection of tools, source code, and papers researching Windows' implementation of CET.☆74Updated 4 years ago
- Report and exploit of CVE-2023-36427☆87Updated 11 months ago