alex-ilgayev / windbg-kernel-debug-cheat-sheetLinks
Helpful WinDBG command for kernel debugging
☆23Updated 4 years ago
Alternatives and similar repositories for windbg-kernel-debug-cheat-sheet
Users that are interested in windbg-kernel-debug-cheat-sheet are comparing it to the libraries listed below
Sorting:
- IOCTLpus can be used to make DeviceIoControl requests with arbitrary inputs (with functionality somewhat similar to Burp Repeater).☆89Updated 3 years ago
- Writeups for CTF challenges☆31Updated last year
- ☆31Updated 3 years ago
- ☆74Updated 11 months ago
- Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).☆143Updated 10 months ago
- ☆90Updated last year
- The Windbg extensions to study Hyper-V on Intel and AMD processors.☆153Updated 3 months ago
- Unofficial Common Log File System (CLFS) Documentation☆179Updated 3 years ago
- ☆145Updated 2 years ago
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆116Updated 11 months ago
- ☆70Updated 2 years ago
- A tool that is used to hunt vulnerabilities in x64 WDM drivers☆203Updated 2 months ago
- A collection of tools, source code, and papers researching Windows' implementation of CET.☆84Updated 4 years ago
- Hyper-V related resources☆31Updated last year
- Python bindings for the Icicle emulator.☆35Updated 2 months ago
- Small tool to convert beteween the PE alignments (raw and virtual).☆90Updated 2 years ago
- ☆145Updated last year
- Implementation of an export address table protection mitigation, like Export Address Filtering (EAF)☆105Updated 2 years ago
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆73Updated last year
- WinDbg extension written in Rust to dump the CPU / memory state of a running VM☆117Updated last month
- ☆50Updated 4 months ago
- Windows KASLR bypass using prefetch side-channel☆102Updated last year
- Post exploitation technique to turn arbitrary kernel write / increment into full read/write primitive on Windows 11 22H2☆228Updated 2 years ago
- UnpacMe IDA Byte Search☆28Updated last year
- msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA.☆152Updated last year
- GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.☆116Updated 2 years ago
- A fast execution trace symbolizer for Windows that runs on all major platforms and doesn't depend on any Microsoft libraries.☆94Updated 8 months ago
- Static Binary Instrumentation tool for Windows x64 executables☆206Updated last month
- Helper idapython code for reversing kmdf drivers☆72Updated 2 years ago
- APC Internals Research Code☆166Updated 4 years ago