corelan / windbglib
Public repository for windbglib, a wrapper around pykd.pyd (for Windbg), used by mona.py
☆326Updated 2 years ago
Alternatives and similar repositories for windbglib:
Users that are interested in windbglib are comparing it to the libraries listed below
- Cross Platform Kernel Fuzzer Framework☆449Updated 6 years ago
- ☆231Updated 7 years ago
- Papers, blogposts, tutorials etc for learning about Windows kernel exploitation, internals and (r|b)ootkits☆389Updated 5 years ago
- A tool to help when dealing with Windows IOCTL codes or reversing Windows drivers.☆428Updated 6 years ago
- Automatically exported from code.google.com/p/ioctlfuzzer☆159Updated 9 years ago
- Windows Kernel Drivers fuzzer☆337Updated 7 years ago
- PEDA-like debugger UI for WinDbg☆202Updated 11 months ago
- Checksec, but for Windows: static detection of security mitigations in executables☆579Updated 2 months ago
- Tools for instrumenting Windows Defender's mpengine.dll☆293Updated 6 years ago
- Detect, analyze and uniquely identify crashes in Windows applications☆502Updated 3 weeks ago
- Exploiting challenges in Linux and Windows☆122Updated 5 years ago
- Pocs for Antivirus Software‘s Kernel Vulnerabilities☆263Updated 7 years ago
- A Bochs-based instrumentation project designed to log kernel memory references, to identify "double fetches" and other OS vulnerabilities☆334Updated 5 years ago
- A Bochs-based instrumentation performing kernel memory taint tracking to detect disclosure of uninitialized memory to ring 3☆301Updated 6 years ago
- Fork of mona.py with x64dbg support☆102Updated 2 years ago
- idahunt is a framework to analyze binaries with IDA Pro and hunt for things in IDA Pro☆384Updated last year
- Patching ROP-encoded shellcodes into PEs☆184Updated 7 years ago
- DriverBuddy is an IDA Python script to assist with the reverse engineering of Windows kernel drivers.☆359Updated 5 years ago
- Examples of leaking Kernel Mode information from User Mode on Windows☆595Updated 7 years ago
- ☆380Updated last year
- Quickly debug shellcode extracted during malware analysis☆590Updated last year
- DC25 5A1F - Demystifying Windows Kernel Exploitation by Abusing GDI Objects☆145Updated 7 years ago
- Windows RPC Python fuzzer☆160Updated 7 years ago
- Incident Response & Digital Forensics Debugging Extension☆375Updated 6 years ago
- ☆767Updated 2 years ago
- Content from presentation at BHUSA 2017☆180Updated 7 years ago
- A small, null-free Windows shellcode that executes calc.exe (x86/x64, all OS/SPs)☆405Updated 9 months ago
- Collection of VC++ example applications to demonstrate Win10 userland heap behavior (BEA & FEA)☆84Updated 8 years ago
- IDA Pro plugin to assist with complex graphs☆314Updated last year
- ROPium is a tool that helps you building ROP exploits by finding and chaining gadgets together☆385Updated 2 years ago