corelan / windbglib
Public repository for windbglib, a wrapper around pykd.pyd (for Windbg), used by mona.py
☆326Updated 2 years ago
Alternatives and similar repositories for windbglib:
Users that are interested in windbglib are comparing it to the libraries listed below
- ☆233Updated 7 years ago
- Windows Kernel Drivers fuzzer☆340Updated 8 years ago
- Papers, blogposts, tutorials etc for learning about Windows kernel exploitation, internals and (r|b)ootkits☆393Updated 5 years ago
- Cross Platform Kernel Fuzzer Framework☆450Updated 6 years ago
- Patching ROP-encoded shellcodes into PEs☆184Updated 7 years ago
- Checksec, but for Windows: static detection of security mitigations in executables☆582Updated 3 months ago
- Pocs for Antivirus Software‘s Kernel Vulnerabilities☆263Updated 7 years ago
- Tools for instrumenting Windows Defender's mpengine.dll☆294Updated 6 years ago
- Examples of leaking Kernel Mode information from User Mode on Windows☆597Updated 7 years ago
- A Bochs-based instrumentation project designed to log kernel memory references, to identify "double fetches" and other OS vulnerabilities☆334Updated 5 years ago
- A small, null-free Windows shellcode that executes calc.exe (x86/x64, all OS/SPs)☆412Updated 10 months ago
- Automatically exported from code.google.com/p/ioctlfuzzer☆160Updated 9 years ago
- A Bochs-based instrumentation performing kernel memory taint tracking to detect disclosure of uninitialized memory to ring 3☆302Updated 6 years ago
- A tool to help when dealing with Windows IOCTL codes or reversing Windows drivers.☆432Updated 6 years ago
- Detect, analyze and uniquely identify crashes in Windows applications☆503Updated last month
- Fork of mona.py with x64dbg support☆102Updated 2 years ago
- windows syscall table from xp ~ 10 rs4☆353Updated 6 years ago
- ☆779Updated 2 years ago
- Search for code cave in all binaries☆277Updated 9 months ago
- Exploiting challenges in Linux and Windows☆122Updated 5 years ago
- A tool to detect and crash Cuckoo Sandbox☆293Updated 8 months ago
- An extensible framework for easily writing compiler optimized position independent x86 / x64 shellcode for windows platforms.☆514Updated 5 years ago
- DriverBuddy is an IDA Python script to assist with the reverse engineering of Windows kernel drivers.☆359Updated 5 years ago
- idahunt is a framework to analyze binaries with IDA Pro and hunt for things in IDA Pro☆384Updated last year
- Dump of win32k POCs for bugs I've found☆372Updated 3 years ago
- A pintool in order to unpack malware☆231Updated 8 years ago
- PowerLoaderEx - Advanced Code Injection Technique for x32 / x64☆364Updated 7 years ago
- DC25 5A1F - Demystifying Windows Kernel Exploitation by Abusing GDI Objects☆145Updated 7 years ago
- Have fun with the LowFragmentationHeap☆237Updated 4 years ago
- PEDA-like debugger UI for WinDbg☆203Updated last year