avast / authenticode-parser
Authenticode-parser is a simple C library for Authenticode format parsing using OpenSSL.
☆16Updated 8 months ago
Related projects ⓘ
Alternatives and complementary repositories for authenticode-parser
- ☆17Updated 3 years ago
- Helper Script to convert a Windbg dumped structure (using the 'dt' command) into a C structure. It creates dummy structs for you if neede…☆26Updated last year
- ☆27Updated 2 years ago
- allowing um r/w through km from um ioctl ™☆12Updated 2 years ago
- Support Windows OS Reversing by searching easily for references to functions across many DLLs☆33Updated 2 years ago
- ☆21Updated 3 years ago
- A demo implementation of a well-known technique used by some malware to evade userland hooking, using my library: libpeconv.☆19Updated 6 years ago
- A ready-made template for a project based on libpeconv.☆41Updated last month
- Dumps information about all the callback objects found in a dump file and the functions registered for them☆34Updated 4 years ago
- arbitrary kernel read/write in dbutil_2_3.sys, Proof of Concept Local Privilege Escalation to nt authority/system☆53Updated 3 years ago
- A set of small utilities, helpers for PIN tracers☆31Updated last year
- ☆26Updated 3 weeks ago
- ☆32Updated 3 years ago
- Python 3 - Manipulation and conversation with different data type (Bytes operations)☆27Updated 2 years ago
- Clone running process with ZwCreateProcess☆58Updated 4 years ago
- ☆20Updated 3 years ago
- ☆22Updated last year
- Blog posts☆30Updated 4 years ago
- An IDA plugin to deal with Event Tracing for Windows (ETW)☆50Updated 2 years ago
- Extract data of TTD trace file to a minidump☆28Updated last year
- File system minifilter driver for Windows to block symbolic link attacks.☆51Updated 3 years ago
- Command like tool to print mitigation flags for running processes in a memory dump☆44Updated 4 years ago
- A Practical example of ELAM (Early Launch Anti-Malware)☆31Updated 3 years ago
- ☆19Updated 4 years ago
- ☆57Updated 2 years ago
- This is a simple driver with x64 inline assembly☆53Updated 4 years ago
- A kernel exploit leveraging NtUserHardErrorControl to elevate a thread to KernelMode and achieve arbitrary kernel R/W & more.☆28Updated 2 years ago
- SoulExtraction is a windows driver library for extracting cert information in windows drivers☆21Updated last year
- Library for using direct system calls☆35Updated 4 years ago