Empyreal96 / nt-info-depot
Webpage for a wealth of learning for many things Windows NT visit: https://empyreal96.github.io/nt-info-depot/index.html
☆84Updated 3 years ago
Related projects ⓘ
Alternatives and complementary repositories for nt-info-depot
- Native API online documentation, based on the System Informer (formerly Process Hacker) phnt headers☆163Updated last week
- PE Viewer☆152Updated 3 weeks ago
- Explore Kernel Objects on Windows☆200Updated 10 months ago
- A small tool that allows to run WinAPI functions through command line parameters☆176Updated 2 years ago
- masm32 kernel programming, drivers, tutorials, examples, and tools (credits Four-F)☆115Updated last year
- Single header version of System Informer's phnt library.☆186Updated last week
- Side-by-side comparison of the Windows and Linux (GNU) Loaders☆289Updated 2 months ago
- x86 Real-Mode MS-DOS Emulator using Windows Hypervisor Platform☆98Updated 4 months ago
- A header-only C++ library for accessing files in COFF binary format. (Including Windows PE/PE+ formats)☆188Updated last week
- x86/x64 Ring 0/-2 System Freezer/Debugger☆110Updated last month
- A global injection and hooking example☆125Updated last year
- Yet another PE Viewer☆138Updated last year
- Doom running in the NT kernel☆162Updated last year
- A tabbed UI for Microsoft's Hyper-V☆203Updated 3 months ago
- A DTrace on Windows Reimplementation☆328Updated 3 weeks ago
- Samples for the book Windows Kernel Programming, 2nd edition☆294Updated this week
- 🪅 Windows User Space Emulator☆389Updated this week
- Collection of undocumented Windows API declarations.☆290Updated 3 weeks ago
- Recon 2023 slides and code☆79Updated last year
- Advanced driver monitoring utility.☆201Updated 2 years ago
- Tooling to generate metadata for Win32 APIs in the Windows Driver Kit (WDK).☆96Updated this week
- msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA.☆148Updated 10 months ago
- Simple x86/x64 Assembler/Disassembler/Emulator☆170Updated 3 months ago
- Reimplement CreateProcessInternalW via Windows 10 20H1+/Windows 11 Base on NtCreateUserProcess-Post☆47Updated 2 months ago
- A WinDbg extension to trace COM interactions☆110Updated 9 months ago
- Bootkit for Windows Sandbox to disable DSE/PatchGuard.☆261Updated last month
- Comparing, discussing, and bypassing various techniques for suspending and freezing processes on Windows.☆114Updated 3 years ago
- An x64dbg plugin which marks XFG call signatures as data☆72Updated last year
- HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate oper…☆360Updated last year
- Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard☆239Updated 2 years ago