MartinDrab / IRPMon
The goal of the tool is to monitor requests received by selected device objects or kernel drivers. The tool is quite similar to IrpTracker but has several enhancements. It supports 64-bit versions of Windows (no inline hooks are used, only moodifications to driver object structures are performed) and monitors IRP, FastIo, AddDevice, DriverUnload…
☆383Updated 2 months ago
Alternatives and similar repositories for IRPMon:
Users that are interested in IRPMon are comparing it to the libraries listed below
- WinDBG Anti-RootKit Extension☆629Updated 4 years ago
- Research on Windows Kernel Executive Callback Objects☆285Updated 5 years ago
- Syscall Monitor is a system monitor program (like Sysinternal's Process Monitor) using Intel VT-X/EPT for Windows7+☆735Updated 7 years ago
- Detours with just single dependency - NTDLL☆619Updated 2 years ago
- windows syscall table from xp ~ 10 rs4☆352Updated 6 years ago
- Windows NT x64 syscall fuzzer☆597Updated last year
- Source code for File Test - Interactive File System Test Tool☆279Updated last week
- Persistent IAT hooking application - based on bearparser☆252Updated 2 years ago
- zer0m0n driver for cuckoo sandbox☆358Updated 9 years ago
- PatchGuard Research☆295Updated 6 years ago
- Monitor activity of any driver☆335Updated 4 years ago
- SimpleSvmHook is a research purpose hypervisor for Windows on AMD processors.☆375Updated 4 years ago
- pseudo-code to show how to disable patchguard with win10☆296Updated 7 years ago
- Examples of leaking Kernel Mode information from User Mode on Windows☆595Updated 7 years ago
- ☆224Updated 3 years ago
- DriverBuddy is an IDA Python script to assist with the reverse engineering of Windows kernel drivers.☆359Updated 5 years ago
- Defeating Patchguard universally for Windows 8, Windows 8.1 and all versions of Windows 10 regardless of HVCI.☆856Updated 5 years ago
- Detecting execution of kernel memory where is not backed by any image file☆256Updated 6 years ago
- pdbex is a utility for reconstructing structures and unions from the PDB into compilable C headers☆847Updated 6 months ago
- Debug Child Process Tool (auto attach)☆283Updated last year
- kHypervisor is a lightweight bluepill-like nested VMM for Windows, it provides and emulating a basic function of Intel VT-x☆424Updated 3 years ago
- Mirror of users section of rootkit.com☆291Updated 8 years ago
- The Windows Library for Intel Process Trace (WinIPT) is a project that leverages the new Intel Processor Trace functionality exposed by W…☆377Updated last year
- x64dbg plugin to set breakpoints automatically to Win32/64 APIs☆174Updated 7 years ago
- Minimalistic VT-x hypervisor with hooks☆848Updated 5 years ago
- Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.☆581Updated last month
- Turn off PatchGuard in real time for win7 (7600) ~ later☆1,004Updated 2 years ago
- Monitoring and controlling kernel API calls with stealth hook using EPT☆1,224Updated 3 years ago
- Universal PatchGuard and Driver Signature Enforcement Disable☆838Updated 5 years ago
- proof-of-concept Windows Driver for injecting DLL into user-mode processes using APC☆1,201Updated 10 months ago