WalkingCat / ExpDiffLinks
Diff tool for comparing export tables in PE images
☆24Updated 5 years ago
Alternatives and similar repositories for ExpDiff
Users that are interested in ExpDiff are comparing it to the libraries listed below
Sorting:
- Event Tracing for Windows Custom Events☆21Updated 10 years ago
- An alternative tool to Sysinternals WinObj tool (nicer icons!)☆37Updated 7 years ago
- Diff tool for comparing symbols in PDB files☆84Updated 5 years ago
- Notes my learning steps about Windows-NT☆23Updated 8 years ago
- ☆21Updated 8 years ago
- The internal Windows structures hack to create the in-process private ETW session☆13Updated 8 years ago
- NTrace -- a function boundary tracing tool for Windows user and kernel mode☆22Updated 12 years ago
- The project is a demo solution for one of the anti-rootkit techniques aimed on overcoming splicers☆35Updated 8 years ago
- Windows KExec☆25Updated 15 years ago
- Plugins for Scylla☆20Updated 14 years ago
- Demonstrate the new FileDispositionInfoEx behavior☆14Updated 8 years ago
- ☆15Updated 9 years ago
- Hyper-V sockets☆29Updated 8 years ago
- User-mode program parsing logs created by HyperPlatform☆18Updated 9 years ago
- Class implementation of PowerLoader injection technique☆32Updated 9 years ago
- Windows hidden thread suspend POC with code injection☆12Updated 8 years ago
- PE Infector/Cryptor source code☆16Updated 8 years ago
- Windows NT port of 'Main is usually a function. So then when is it not?'☆27Updated last year
- Listens for Firewall rule match events generated by Microsoft Hyper-V Virtual Filter Protocol (VFP) extension.☆31Updated 4 years ago
- Simple command line version of Sysinternals WinObj. Currently just lists object names and types given an object manager directory.☆21Updated 2 years ago
- Windows kernel-mode callbacks tutorial driver☆47Updated 9 years ago
- Portable Executable parsing library, used by PEExplorer. Also available as a nuget package☆36Updated 7 years ago
- This repository contains some tools that I have written in the past☆28Updated 2 years ago
- xLCB plugin for x64dbg☆20Updated 9 years ago
- use crystalCPUID to identify vt-x & amd-v☆17Updated 10 years ago
- Managed wrappers around the Windows API and some Native API☆35Updated 7 years ago
- Obtain remote process cookies by performing a brute-force attack on ntdll.RtlDecodePointer using known pointer encodings.☆22Updated 8 years ago
- Low-level MS Windows registry files analysis tools☆20Updated 9 years ago
- windows kernel File redirection☆20Updated 11 years ago
- Full reversing of the Microsoft Auxiliary Windows API Library and ported to C☆24Updated last year