ergrelet / windiff
Web-based tool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across different versions of the OS.
☆332Updated this week
Alternatives and similar repositories for windiff:
Users that are interested in windiff are comparing it to the libraries listed below
- msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA.☆151Updated last year
- A DTrace on Windows Reimplementation☆341Updated last month
- Static Binary Instrumentation tool for Windows x64 executables☆198Updated last month
- Operating System Design Review: A systemic analysis of modern systems architecture☆305Updated 3 weeks ago
- SHAREM is a shellcode analysis framework, capable of emulating more than 20,000 WinAPIs and virutally all Windows syscalls. It also conta…☆387Updated this week
- ☆198Updated last year
- WinDbg extension written in Rust to dump the CPU / memory state of a running VM☆115Updated 4 months ago
- A simple ptrace-less shared library injector for x64 Linux☆251Updated 2 years ago
- Cross-platform tool that allows browsing and extracting C and C++ type declarations from PDB files.☆308Updated last month
- Advanced driver monitoring utility.☆206Updated 2 years ago
- x86 malware emulator☆215Updated last week
- Post exploitation technique to turn arbitrary kernel write / increment into full read/write primitive on Windows 11 22H2☆225Updated 2 years ago
- A small x64 library to load dll's into memory.☆435Updated last year
- Useful scripts for WinDbg using the debugger data model☆407Updated 11 months ago
- Single header version of System Informer's phnt library.☆203Updated this week
- LLVM plugin to transparently apply stack spoofing and indirect syscalls to Windows x64 native calls at compile time.☆273Updated last year
- Recon 2023 slides and code☆79Updated last year
- Time Travel Debugging IDA plugin☆572Updated 8 months ago
- A command line Windows API tracing tool for Golang binaries.☆156Updated last year
- A Cross-Platform C++ parser library for Windows user minidumps with Python 3 bindings.☆200Updated 4 months ago
- Process Injection using Thread Name☆249Updated 6 months ago
- A C++ tool to unstrip Rust/Go binaries (ELF and PE)☆312Updated last month
- Yet another variant of Process Hollowing☆384Updated last month
- ☆142Updated last year
- FLARE Team's Binary Navigator☆236Updated last week
- The Windbg extensions to study Hyper-V on Intel and AMD processors.☆152Updated 2 weeks ago
- ☆111Updated last month
- Bindings for Microsoft WinDBG TTD☆216Updated last year
- Vulnerable driver research tool, result and exploit PoCs☆189Updated last year