alexander-hanel / msdocsviewer
msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA.
☆151Updated last year
Alternatives and similar repositories for msdocsviewer:
Users that are interested in msdocsviewer are comparing it to the libraries listed below
- Static Binary Instrumentation tool for Windows x64 executables☆198Updated last month
- Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).☆131Updated 7 months ago
- A tool that is used to hunt vulnerabilities in x64 WDM drivers☆183Updated 3 weeks ago
- ☆145Updated last year
- The Windbg extensions to study Hyper-V on Intel and AMD processors.☆152Updated 2 weeks ago
- masm32 kernel programming, drivers, tutorials, examples, and tools (credits Four-F)☆119Updated last year
- Single header version of System Informer's phnt library.☆202Updated last week
- Bindings for Microsoft WinDBG TTD☆216Updated last year
- Post exploitation technique to turn arbitrary kernel write / increment into full read/write primitive on Windows 11 22H2☆225Updated 2 years ago
- Unofficial Common Log File System (CLFS) Documentation☆172Updated 3 years ago
- ☆198Updated last year
- Debugger Anti-Detection Benchmark☆311Updated last year
- Advanced driver monitoring utility.☆206Updated 2 years ago
- ☆142Updated last year
- An application to view and filter pool allocations from a dmp file on Windows 10 RS5+.☆136Updated 2 years ago
- Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard☆244Updated 2 years ago
- ☆73Updated 8 months ago
- Repository for the code snippets from the AllThingsIDA video channel☆101Updated 2 months ago
- WinDbg extension written in Rust to dump the CPU / memory state of a running VM☆113Updated 4 months ago
- Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks☆344Updated 4 months ago
- A DTrace on Windows Reimplementation☆341Updated last month
- APC Internals Research Code☆162Updated 4 years ago
- An intuitive query API for IDA Pro☆155Updated 2 months ago
- IOCTLpus can be used to make DeviceIoControl requests with arbitrary inputs (with functionality somewhat similar to Burp Repeater).☆88Updated 3 years ago
- Static deobfuscator for Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.☆265Updated 7 months ago
- Small tool to convert beteween the PE alignments (raw and virtual).☆87Updated 2 years ago
- ☆102Updated 2 years ago
- Rust symbol recovery tool☆44Updated last month
- Abusing exceptions for code execution.☆109Updated 2 years ago
- A Python script to download PDB files associated with a Portable Executable (PE)☆119Updated last month