MartinDrab / IRPMonLinks
The goal of the tool is to monitor requests received by selected device objects or kernel drivers. The tool is quite similar to IrpTracker but has several enhancements. It supports 64-bit versions of Windows (no inline hooks are used, only moodifications to driver object structures are performed) and monitors IRP, FastIo, AddDevice, DriverUnload…
☆406Updated last year
Alternatives and similar repositories for IRPMon
Users that are interested in IRPMon are comparing it to the libraries listed below
Sorting:
- WinDBG Anti-RootKit Extension☆643Updated 5 years ago
- Windows NT x64 syscall fuzzer☆631Updated 3 weeks ago
- PatchGuard Research☆304Updated 7 years ago
- ☆228Updated 4 years ago
- DriverBuddy is an IDA Python script to assist with the reverse engineering of Windows kernel drivers.☆373Updated 6 years ago
- Research on Windows Kernel Executive Callback Objects☆315Updated 5 years ago
- zer0m0n driver for cuckoo sandbox☆368Updated 10 years ago
- Source code for File Test - Interactive File System Test Tool☆302Updated 5 months ago
- Syscall Monitor is a system monitor program (like Sysinternal's Process Monitor) using Intel VT-X/EPT for Windows7+☆748Updated 8 years ago
- Debug Child Process Tool (auto attach)☆321Updated 2 years ago
- Monitor activity of any driver☆352Updated 5 years ago
- Persistent IAT hooking application - based on bearparser☆264Updated 3 years ago
- Detecting execution of kernel memory where is not backed by any image file☆261Updated 7 years ago
- Detours with just single dependency - NTDLL☆669Updated 2 months ago
- A tool to help when dealing with Windows IOCTL codes or reversing Windows drivers.☆438Updated 7 years ago
- This driver implements the Intel Processor Trace functionality in Intel Skylake architecture for Microsoft Windows☆463Updated 7 years ago
- pdbex is a utility for reconstructing structures and unions from the PDB into compilable C headers☆887Updated 7 months ago
- Examples of leaking Kernel Mode information from User Mode on Windows☆628Updated 8 years ago
- Simpleator ("Simple-ator") is an innovative Windows-centric x64 user-mode application emulator that leverages several new features that w…☆395Updated 7 years ago
- XNTSV program for detailed viewing of system structures for Windows.☆468Updated this week
- Labeless is a multipurpose IDA Pro plugin system for labels/comments synchronization with a debugger backend, with complex memory dumping…☆574Updated last year
- windows syscall table from xp ~ 10 rs4☆356Updated 7 years ago
- Incident Response & Digital Forensics Debugging Extension☆387Updated 7 years ago
- Toy scripts for playing with WinDbg JS API☆244Updated last year
- Mirror of users section of rootkit.com☆302Updated 9 years ago
- kHypervisor is a lightweight bluepill-like nested VMM for Windows, it provides and emulating a basic function of Intel VT-x☆442Updated 4 years ago
- An IDA Plugin that help analyzing module that use COM☆230Updated 3 months ago
- ☆408Updated 8 years ago
- Source from VMDE paper, adapted to 2015☆189Updated 8 years ago
- The Windows Library for Intel Process Trace (WinIPT) is a project that leverages the new Intel Processor Trace functionality exposed by W…☆404Updated 2 years ago