Incident Response & Digital Forensics Debugging Extension
☆389Dec 11, 2018Updated 7 years ago
Alternatives and similar repositories for SwishDbgExt
Users that are interested in SwishDbgExt are comparing it to the libraries listed below
Sorting:
- WinDBG Anti-RootKit Extension☆645Jul 29, 2020Updated 5 years ago
- A tool to help when dealing with Windows IOCTL codes or reversing Windows drivers.☆437Aug 22, 2018Updated 7 years ago
- [ARCHIVED] mov rax, ${Thalium/IceBox}; jmp rax;☆76Jun 8, 2019Updated 6 years ago
- A windbg extension, extracting token related contents☆41Dec 23, 2020Updated 5 years ago
- A driver that hooks C: volume using symbolic link callback to track all FS access to the volume☆110Apr 24, 2020Updated 5 years ago
- Examples of leaking Kernel Mode information from User Mode on Windows☆633Jul 7, 2017Updated 8 years ago
- The goal of the tool is to monitor requests received by selected device objects or kernel drivers. The tool is quite similar to IrpTracke…☆408Dec 27, 2024Updated last year
- Hyper-V Research is trendy now☆198May 6, 2024Updated last year
- kernel pool windbg extension☆83Jul 23, 2015Updated 10 years ago
- Any useful windbg plugins I've written.☆117Apr 10, 2018Updated 7 years ago
- Elevation of privilege detector based on HyperPlatform☆123Mar 5, 2017Updated 8 years ago
- Syscall Monitor is a system monitor program (like Sysinternal's Process Monitor) using Intel VT-X/EPT for Windows7+☆747Jun 26, 2017Updated 8 years ago
- reverse engineering extension plugin for windbg☆121Sep 30, 2019Updated 6 years ago
- Papers, blogposts, tutorials etc for learning about Windows kernel exploitation, internals and (r|b)ootkits☆415Jan 2, 2020Updated 6 years ago
- PatchGuard Research☆304Oct 6, 2018Updated 7 years ago
- Recon 2015 Presentation from Alex Ionescu☆250Jan 27, 2016Updated 10 years ago
- Various extensions for WinDbg☆174Aug 26, 2014Updated 11 years ago
- DriverBuddy is an IDA Python script to assist with the reverse engineering of Windows kernel drivers.☆372Jan 8, 2020Updated 6 years ago
- ☆14Jan 10, 2017Updated 9 years ago
- pdbex is a utility for reconstructing structures and unions from the PDB into compilable C headers☆892Jun 18, 2025Updated 8 months ago
- ☆30May 23, 2017Updated 8 years ago
- codes for my blog post: https://secrary.com/Random/InstrumentationCallback/☆183Nov 30, 2017Updated 8 years ago
- Windows RPC Python fuzzer☆164Nov 14, 2017Updated 8 years ago
- The history of Windows Internals via symbols.☆181Nov 4, 2021Updated 4 years ago
- Sample extensions, scripts, and API uses for WinDbg.☆812Dec 27, 2025Updated 2 months ago
- PoC of BOOST-ed _EPROCESS.VadRoot iterating☆27May 21, 2014Updated 11 years ago
- This driver implements the Intel Processor Trace functionality in Intel Skylake architecture for Microsoft Windows☆466Apr 17, 2018Updated 7 years ago
- ☆408Mar 1, 2017Updated 9 years ago
- A sample on how to inject a DLL from a kernel driver☆61Sep 13, 2016Updated 9 years ago
- Windbg extension to find PatchGuard pages☆123Jun 24, 2014Updated 11 years ago
- Simple project that demonstrates how an ETW consumer can be created just by using NTDLL☆146Feb 23, 2019Updated 7 years ago
- idahunt is a framework to analyze binaries with IDA Pro and hunt for things in IDA Pro☆387Sep 21, 2023Updated 2 years ago
- A Windows kernel dump C++ parser library with Python 3 bindings.☆213Oct 5, 2025Updated 4 months ago
- 0CCh Windbg extension: include some useful commands☆114Aug 1, 2023Updated 2 years ago
- Windows Object Explorer 64-bit☆1,886Feb 10, 2026Updated 2 weeks ago
- Translates WinDbg "dt" structure dump to a C structure☆134Oct 16, 2016Updated 9 years ago
- A command tree based on commands and extensions for Windows Kernel Debugging.☆111Jul 10, 2020Updated 5 years ago
- ☆36Oct 29, 2020Updated 5 years ago
- CFB is a ProcMon-style tool designed to assist capturing IRPs sent to Windows drivers.☆333Mar 26, 2024Updated last year