A bunch of parsers for PE and PDB formats in C++
☆270May 15, 2024Updated 2 years ago
Alternatives and similar repositories for formatPE
Users that are interested in formatPE are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A bunch of architectural headers for i386 and AMD64☆43Oct 7, 2023Updated 2 years ago
- Analyze Windows x64 Kernel Memory Layout☆131Nov 19, 2020Updated 5 years ago
- The Universal C++ RunTime library, supporting kernel-mode C++ exception-handler and STL.☆405Jul 12, 2024Updated last year
- The functions interception library written on pure C and NativeAPI with UserMode and KernelMode support☆764Apr 24, 2025Updated last year
- Analyze patches in a process☆262Jul 28, 2021Updated 4 years ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- The most powerful and customizable binary pattern scanner☆251Nov 13, 2021Updated 4 years ago
- KSOCKET provides a very basic example how to make a network connections in the Windows Driver by using WSK☆545Sep 2, 2022Updated 3 years ago
- The Win32 Anti-Intrusion Library☆213May 30, 2019Updated 7 years ago
- ☆174Mar 9, 2022Updated 4 years ago
- The program draws with win32k gdi functions in the kernel while NtGdiDdDDISubmitCommand is being hooked.☆351Apr 27, 2020Updated 6 years ago
- A simple x86_64 AMD-v hypervisor type-2 Programmed with C++, with soon to be added syscall hooks. [W.I.P]☆112Aug 3, 2023Updated 2 years ago
- Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard☆272Aug 31, 2022Updated 3 years ago
- Windows kernel hacking framework, driver template, hypervisor and API written on C++☆1,816Nov 12, 2023Updated 2 years ago
- Easy Anti PatchGuard☆221Apr 9, 2021Updated 5 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- The Kernel-Mode Winsock library, supporting TCP, UDP and Unix sockets (DGRAM and STREAM).☆288Apr 30, 2026Updated last month
- C++ STL in the Windows Kernel with C++ Exception Support☆435Aug 16, 2023Updated 2 years ago
- Windows Anti-Rootkit Tool☆561May 9, 2026Updated last month
- C++ Exceptions in Windows Drivers☆220Dec 21, 2020Updated 5 years ago
- Using C++ STL on Windows kernle development☆89Feb 21, 2019Updated 7 years ago
- System call hook for Windows 10 20H1☆495Jun 26, 2021Updated 4 years ago
- C++ library for low-level Windows development☆82Apr 12, 2024Updated 2 years ago
- Mapping your code on a 0x1000 size page☆71May 20, 2022Updated 4 years ago
- C++17 PE manualmapper☆462Oct 2, 2021Updated 4 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Hypervisor based anti anti debug plugin for x64dbg☆1,606Jul 8, 2024Updated last year
- Reverse engineered source code of the autochk rootkit☆212Nov 1, 2019Updated 6 years ago
- Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.☆673Jan 28, 2025Updated last year
- Kernel driver for detecting Intel VT-x hypervisors.☆205Jul 11, 2023Updated 2 years ago
- https://key08.com/index.php/2021/10/19/1375.html☆71May 11, 2022Updated 4 years ago
- Kernel Lazy Importer☆141Apr 13, 2024Updated 2 years ago
- Process Monitor X v2☆656Jan 22, 2024Updated 2 years ago
- a Windows kernel Pdb parsing and downloading library that running purely in kernel mode without any R3 programs.☆180Sep 13, 2024Updated last year
- Manual mapping without creating any threads, with rw only access☆818Oct 29, 2019Updated 6 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Advanced driver monitoring utility.☆217May 23, 2026Updated 3 weeks ago
- Load your driver like win32k.sys☆257Aug 20, 2022Updated 3 years ago
- Using NtCreateFile and NtDeviceIoControlFile to realize the function of winsock(利用NtCreateFile和NtDeviceIoControlFile 实现winsock的功能)☆129Sep 9, 2022Updated 3 years ago
- Code Injection, Inject malicious payload via pagetables pml4.☆244Jul 7, 2021Updated 4 years ago
- Hide codes/data in the kernel address space.☆187May 8, 2021Updated 5 years ago
- 之前那份是7600的,每次编译搞得好麻烦。更新一个VS2017可以直接编译的。☆153Jun 5, 2019Updated 7 years ago
- Driver and WinDBG scripts to dump information about all resources and lookaside lists☆67Apr 4, 2020Updated 6 years ago