PhrozenIO / PsyloDbg
User-friendly Microsoft Windows Debugger for Malware Analysts.
☆188Updated last year
Related projects ⓘ
Alternatives and complementary repositories for PsyloDbg
- Microsoft Windows DLL Export Browser (Enumerate Exports, COM Methods and Properties) with Advanced Search Features.☆179Updated 4 months ago
- Comparing, discussing, and bypassing various techniques for suspending and freezing processes on Windows.☆114Updated 2 years ago
- Repository to publish your evasion techniques and contribute to the project☆134Updated 3 weeks ago
- Advanced driver monitoring utility.☆201Updated 2 years ago
- masm32 kernel programming, drivers, tutorials, examples, and tools (credits Four-F)☆115Updated last year
- GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.☆113Updated last year
- A dynamic unpacking tool☆128Updated last year
- Tools and technical write-ups describing attacking techniques that rely on concealing code execution on Windows☆197Updated 2 years ago
- Source code of exploiting windows API for red teaming series☆147Updated 2 years ago
- A list of excellent resources for anyone to deepen their understanding with regards to Windows Kernel Exploitation and general low level …☆121Updated 2 years ago
- Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.☆220Updated last year
- My notes while studying Windows exploitation☆184Updated last year
- a PE Loader and Windows API tracer. Useful in malware analysis.☆137Updated 2 years ago
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆109Updated 3 months ago
- Recon 2023 slides and code☆78Updated last year
- ☆104Updated this week
- MalUnpack companion driver☆92Updated 4 months ago
- Admin to Kernel code execution using the KSecDD driver☆237Updated 6 months ago
- A attempt at replicating BLACKLOTUS capabilities, whilst not acting as a direct mimic.☆85Updated last year
- Patching "signtool.exe" to accept expired certificates for code-signing.☆268Updated 3 months ago
- MSI Dump - a tool that analyzes malicious MSI installation packages, extracts files, streams, binary data and incorporates YARA scanner.☆193Updated last year
- A generic UEFI bootkit used to achieve initial usermode execution. It works with modifications.☆396Updated last year
- Tools and PoCs for Windows syscall investigation.☆354Updated 6 months ago
- ☆94Updated 2 years ago
- collection of apis used in malware development☆221Updated 2 years ago
- Bootkit for Windows Sandbox to disable DSE/PatchGuard.☆258Updated 3 weeks ago
- Killing your preferred antimalware by abusing native symbolic links and NT paths.☆351Updated 2 years ago
- Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard☆236Updated 2 years ago
- Important notes and topics on my journey towards mastering Windows Internals☆339Updated 6 months ago