ergrelet / windiff
Web-based tool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across different versions of the OS.
☆331Updated this week
Alternatives and similar repositories for windiff:
Users that are interested in windiff are comparing it to the libraries listed below
- A DTrace on Windows Reimplementation☆338Updated last week
- msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA.☆148Updated last year
- Operating System Design Review: A systemic analysis of modern systems architecture☆302Updated this week
- Static Binary Instrumentation tool for Windows x64 executables☆196Updated last week
- A Cross-Platform C++ parser library for Windows user minidumps with Python 3 bindings.☆200Updated 2 months ago
- Exploring RPC interfaces on Windows☆315Updated last year
- Vulnerable driver research tool, result and exploit PoCs☆184Updated last year
- ☆192Updated last year
- Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard☆243Updated 2 years ago
- masm32 kernel programming, drivers, tutorials, examples, and tools (credits Four-F)☆118Updated last year
- WinDbg extension written in Rust to dump the CPU / memory state of a running VM☆113Updated 3 months ago
- LLVM plugin to transparently apply stack spoofing and indirect syscalls to Windows x64 native calls at compile time.☆267Updated last year
- A small x64 library to load dll's into memory.☆429Updated last year
- SHAREM is a shellcode analysis framework, capable of emulating more than 20,000 WinAPIs and virutally all Windows syscalls. It also conta…☆366Updated 3 months ago
- A tool that is used to hunt vulnerabilities in x64 WDM drivers☆172Updated last year
- x86 malware emulator☆207Updated 3 weeks ago
- FLARE Team's Binary Navigator☆218Updated 3 weeks ago
- Advanced driver monitoring utility.☆203Updated 2 years ago
- Unofficial Common Log File System (CLFS) Documentation☆169Updated 3 years ago
- Patching "signtool.exe" to accept expired certificates for code-signing.☆273Updated 6 months ago
- Generate a proxy dll for arbitrary dll☆165Updated 3 months ago
- Bootkit for Windows Sandbox to disable DSE/PatchGuard.☆269Updated 4 months ago
- The Definitive Guide To Process Cloning on Windows☆457Updated last year
- Debugger Anti-Detection Benchmark☆305Updated last year
- Time Travel Debugging IDA plugin☆561Updated 7 months ago
- PoCs for Kernelmode rootkit techniques research.☆352Updated 3 weeks ago
- baton drop (CVE-2022-21894): Secure Boot Security Feature Bypass Vulnerability☆315Updated last year
- Cross-platform tool that allows browsing and extracting C and C++ type declarations from PDB files.☆304Updated last week
- For when DLLMain is the only way☆365Updated 3 months ago