NtQuery / DebugDetector
☆26Updated 10 years ago
Related projects: ⓘ
- Helper script for Windows kernel debugging with IDA Pro on VMware + GDB stub☆76Updated 12 years ago
- ☆27Updated 6 years ago
- *DEPRECATED* Advanced skinning plugin for IDA Pro, ported to x64dbg☆31Updated 7 years ago
- Helper utility for debugging windows PE/PE+ loader.☆49Updated 9 years ago
- ☆112Updated 11 years ago
- Open and generic Anti-Anti Reversing Framework. Works in 32 and 64 bits.☆63Updated 11 years ago
- x64dbg conditional branches logger [Plugin]☆67Updated 7 years ago
- IDAScript to create Symbol file which can be loaded in WinDbg via AddSyntheticSymbol☆40Updated 10 years ago
- Windows 10 kernel and ntdll internal types, directly compatible with ida.☆50Updated 5 years ago
- Identifying Virtual Table Functions using VTBL IDA Pro Plugin + Deviare Hooking Engine☆90Updated 11 years ago
- Bypassing code hooks detection in modern anti-rootkits via building faked PTE entries.☆72Updated 13 years ago
- Import debugging traces from WinDBG into IDA. Color the graph, fill in the value of all the operands, etc.☆25Updated 11 years ago
- IDA Pro MSDN Helper☆39Updated 8 years ago
- Adding exceptions to Microsoft's Control Flow Guard (CFG)☆58Updated 8 years ago
- This IDAPython script tags subroutines according to their use of imported functions☆69Updated 3 years ago
- ☆16Updated 6 years ago
- Intercept arbitrary functions at run-time, without knowing their typedefs☆86Updated 7 years ago
- Windbg extension to find PatchGuard pages☆116Updated 10 years ago
- Analyze and attack windows applications using dll hijacking vulnerabilities☆54Updated 4 years ago
- IDA Plugin which decodes Windows Device I/O control code into DeviceType, FunctionCode, AccessType and MethodType.☆106Updated 9 months ago
- modify binary Portable Executable to hook its export functions☆62Updated 5 years ago
- libemu shim layer and win32 environment for Unicorn Engine☆71Updated 7 years ago
- ☆58Updated this week
- Analyze PatchGuard☆53Updated 6 years ago
- IDA script for vmprotect Windows Api address decoder☆51Updated 3 years ago
- Retrieve pointers to undocumented kernel functions and offsets to members within undocumented structures to use in your driver by using t…☆52Updated 5 years ago
- Windows kernel vulnerability in win32k.sys Driver☆34Updated 8 years ago
- This is a VmProtect integrated debugger, that will essentially allow you to disasm and debug vmp partially virtualized functions at the v…☆45Updated 7 years ago
- Simple proof of concept code for injecting libraries on 64bit processes from a 32bit process☆91Updated 5 years ago
- 微软7月布丁增加内存延迟释放机制☆11Updated 10 years ago