VoidSec / DriverBuddyReloaded
Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks
☆344Updated 5 months ago
Alternatives and similar repositories for DriverBuddyReloaded:
Users that are interested in DriverBuddyReloaded are comparing it to the libraries listed below
- Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.☆584Updated last month
- Debugger Anti-Detection Benchmark☆323Updated last year
- Static deobfuscator for Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.☆265Updated 7 months ago
- A library to develop kernel level Windows payloads for post HVCI era☆396Updated 3 years ago
- This project provides a collection of Microsoft Windows kernel structures, unions and enumerations. Most of them are not officially docum…☆194Updated last month
- IDA Pro plugin to make bitfield accesses easier to grep☆232Updated last month
- Research on Windows Kernel Executive Callback Objects☆285Updated 5 years ago
- Analyze patches in a process☆251Updated 3 years ago
- msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA.☆151Updated last year
- Browse Page Tables on Windows (Page Table Viewer)☆196Updated 2 years ago
- ☆198Updated last year
- A tool that is used to hunt vulnerabilities in x64 WDM drivers☆183Updated last month
- Advanced driver monitoring utility.☆207Updated 2 years ago
- A collection of themes based on pastel colors, created for reverse engineers☆141Updated last month
- Shell extension for opening executables in IDA☆186Updated 2 years ago
- A collection of various vulnerable (mostly physical memory exposing) drivers.☆363Updated 2 years ago
- Universal x86/x64 VMProtect 2.0-3.X Import fixer☆5Updated 3 years ago
- Demo proof of concept for shadow regions, and implementation of HyperDeceit.☆276Updated last year
- Native code virtualizer for x64 binaries☆471Updated 3 months ago
- Deobfuscation via optimization with usage of LLVM IR and parsing assembly.☆541Updated this week
- A VMP to VTIL lifter.☆433Updated 3 years ago
- Load your driver like win32k.sys☆251Updated 2 years ago
- Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard☆244Updated 2 years ago
- ☆402Updated 2 months ago
- Time Travel Debugging IDA plugin☆572Updated 8 months ago
- Some research on AltSystemCallHandlers functionality in Windows 10 20H1 18999☆209Updated 5 years ago
- Bootkit for Windows Sandbox to disable DSE/PatchGuard.☆274Updated 5 months ago
- IDA Pro plugin to manage classes☆318Updated 6 months ago
- This is a collection of interesting codes about Windows Process creation.☆232Updated last year
- Bindings for Microsoft WinDBG TTD☆216Updated last year