airbus-cert / etwbreakerView external linksLinks
An IDA plugin to deal with Event Tracing for Windows (ETW)
☆55Jul 8, 2022Updated 3 years ago
Alternatives and similar repositories for etwbreaker
Users that are interested in etwbreaker are comparing it to the libraries listed below
Sorting:
- Tools made for my Hyper-V blog series @ https://foxhex0ne.blogspot.com/☆58Jun 21, 2020Updated 5 years ago
- XPN's RpcEnum but based on IDA instead of Ghidra☆21Aug 17, 2019Updated 6 years ago
- POC for a race condition exploit using directory junctions in Windows☆17Apr 26, 2020Updated 5 years ago
- A POC for Windows Extension Host hooking☆24Jul 13, 2019Updated 6 years ago
- ☆14Oct 5, 2019Updated 6 years ago
- Lightweight WINAPI tracing with Pin☆27Aug 22, 2019Updated 6 years ago
- enable libemu run pe file and add some good modify☆14Feb 4, 2019Updated 7 years ago
- A Fuzzer for Windows NDIS Drivers OID Handlers☆95Nov 4, 2021Updated 4 years ago
- Exploring Windows Internals.☆64Aug 18, 2020Updated 5 years ago
- A driver that supports communication between a Windows guest and HyperWin☆15Jan 6, 2021Updated 5 years ago
- IDA plugin for COM☆48Sep 30, 2022Updated 3 years ago
- win10 pgContext dynamic dump (btc version)☆110Jan 15, 2020Updated 6 years ago
- Designed to learn OS specific anti-emulation patterns by fuzzing the Windows API.☆99Jul 7, 2020Updated 5 years ago
- VMX intrinsics plugin for Hex-Rays decompiler☆73Oct 28, 2019Updated 6 years ago
- Toolkit for Hyper-V security research☆157Mar 7, 2022Updated 3 years ago
- Kernel Stack info leak at exportObjectToClient function☆42May 21, 2019Updated 6 years ago
- Hide codes/data in the kernel address space.☆188May 8, 2021Updated 4 years ago
- a frame of amd-v svm nest☆53Apr 7, 2020Updated 5 years ago
- A working version of this tutorial: https://docs.microsoft.com/en-us/windows/desktop/rpc/tutorial☆16Jun 22, 2019Updated 6 years ago
- Reverse engineering toolkit for exploit/malware analysis☆35May 10, 2020Updated 5 years ago
- ☆21Sep 6, 2018Updated 7 years ago
- Agamotto: Accelerating Kernel Driver Fuzzing with Lightweight Virtual Machine Checkpoints☆127Jun 18, 2020Updated 5 years ago
- PoC for CVE-2019-0888 - Use-After-Free in Windows ActiveX Data Objects (ADO)☆40Jul 9, 2019Updated 6 years ago
- ☆19Jun 20, 2019Updated 6 years ago
- Open Course for diving security internal☆52Nov 11, 2019Updated 6 years ago
- Windows device tree walker☆15Sep 19, 2018Updated 7 years ago
- "A Practical Recipe for Hardware Implants" presentation materials.☆13Nov 10, 2020Updated 5 years ago
- Network monitor for Linux☆13Aug 11, 2019Updated 6 years ago
- IDA plugin to explore and browse tags☆55Jul 19, 2019Updated 6 years ago
- Simple x64dbg plugin to show registers on every step.☆16Jul 27, 2019Updated 6 years ago
- Stealthy Injector that leverages a vulnerable driver and other exploits to remain undetected☆38Dec 10, 2018Updated 7 years ago
- INF Studio for easier working with driver installation files☆39Nov 11, 2023Updated 2 years ago
- A Splunk Technology Add-on to forward filtered ETW events.☆30Oct 14, 2020Updated 5 years ago
- ☆31Jul 27, 2020Updated 5 years ago
- An minifilter-based transparent encryptor on Windows.☆30Feb 27, 2017Updated 8 years ago
- Hyper-V Research is trendy now☆197May 6, 2024Updated last year
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆329May 2, 2024Updated last year
- Data Obfuscation for C/C++ Code Based on Residue Number Coding (RNC)☆24May 20, 2021Updated 4 years ago
- Windows EoP Bugs☆127Jun 9, 2020Updated 5 years ago