anhkgg / awesome-windbg-extensions
awesome windbg extensions
☆321Updated 5 years ago
Alternatives and similar repositories for awesome-windbg-extensions:
Users that are interested in awesome-windbg-extensions are comparing it to the libraries listed below
- My personal cheat sheet for using WinDbg for kernel debugging☆395Updated 3 months ago
- A bunch of JavaScript extensions for WinDbg.☆325Updated last month
- Sample extensions, scripts, and API uses for WinDbg.☆735Updated 5 months ago
- DEFCON 27 workshop - Modern Debugging with WinDbg Preview☆712Updated 2 months ago
- Source code for File Test - Interactive File System Test Tool☆269Updated 2 weeks ago
- Toy scripts for playing with WinDbg JS API☆221Updated 6 months ago
- Process Monitor X v2☆594Updated 11 months ago
- XNTSV program for detailed viewing of system structures for Windows.☆448Updated this week
- Research on Windows Kernel Executive Callback Objects☆282Updated 4 years ago
- Extended Process Monitor-like tool based on Event Tracing for Windows☆464Updated 5 years ago
- Monitor activity of any driver☆329Updated 4 years ago
- Detours with just single dependency - NTDLL☆617Updated 2 years ago
- This is a repo for small, useful scripts and extensions☆242Updated last year
- Examples of leaking Kernel Mode information from User Mode on Windows☆585Updated 7 years ago
- The goal of the tool is to monitor requests received by selected device objects or kernel drivers. The tool is quite similar to IrpTracke…☆368Updated 3 weeks ago
- WinDBG Anti-RootKit Extension☆623Updated 4 years ago
- Useful scripts for WinDbg using the debugger data model☆392Updated 9 months ago
- 0CCh Windbg extension: include some useful commands☆110Updated last year
- Windows NT x64 syscall fuzzer☆596Updated last year
- PDB Downloader - An easier way to download Microsoft's public symbols for Libraries and Executables.☆294Updated 8 years ago
- The Windows Library for Intel Process Trace (WinIPT) is a project that leverages the new Intel Processor Trace functionality exposed by W…☆374Updated last year
- Syscall Monitor is a system monitor program (like Sysinternal's Process Monitor) using Intel VT-X/EPT for Windows7+☆726Updated 7 years ago
- This is a collection of interesting codes about Windows Process creation.☆232Updated last year
- My notes while studying Windows internals☆407Updated last month
- pdbex is a utility for reconstructing structures and unions from the PDB into compilable C headers☆833Updated 4 months ago
- VirtualKD-Redux - A revival and modernization of VirtualKD☆848Updated 6 months ago
- This driver implements the Intel Processor Trace functionality in Intel Skylake architecture for Microsoft Windows☆433Updated 6 years ago
- Debug Child Process Tool (auto attach)☆277Updated last year
- View ETW Provider manifest☆447Updated 2 months ago
- Canadian Furious Beaver is a ProcMon-style tool designed only for capturing IRPs sent to any Windows driver.☆312Updated 9 months ago