ernw / Windows-Insight
The content of this repository aims to assist efforts on analysing inner working principles, functionalities, and properties of the Microsoft Windows operating system. This repository stores relevant documentation as well as executable files needed for conducting analysis studies.
☆151Updated 4 years ago
Alternatives and similar repositories for Windows-Insight:
Users that are interested in Windows-Insight are comparing it to the libraries listed below
- Mario & Luigi - Tools for sniffing Windows Named Pipes communication☆129Updated 8 years ago
- Documentation and supporting script sample for Windows Exploit Guard☆156Updated 3 years ago
- ☆67Updated 2 years ago
- Driver Initial Reconnaissance Tool☆122Updated 5 years ago
- ☆108Updated 4 years ago
- FLARE Kernel Shellcode Loader☆176Updated 5 years ago
- Pure Python parser for Application Compatibility Shim Databases (.sdb files)☆108Updated 4 years ago
- ☆213Updated 6 years ago
- Hyper-V Research is trendy now☆178Updated 10 months ago
- ☆232Updated 7 years ago
- Parsers for custom malware formats ("Funky malware formats")☆95Updated 3 years ago
- Scripts for disassembling VBScript p-code in the memory to aid in exploits analysis☆84Updated 2 years ago
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆288Updated 10 months ago
- Two IDAPython Scripts help you to reconstruct Microsoft COM (Component Object Model) Code☆181Updated 4 years ago
- PoC for persisting .NET payloads in Windows Notification Facility (WNF) state names using low-level Windows Kernel API calls.☆149Updated 5 years ago
- PowerKrabsEtw is a PowerShell interface for doing real-time ETW tracing.☆103Updated 4 years ago
- A command tree based on commands and extensions for Windows Kernel Debugging.☆107Updated 4 years ago
- WNF Utilities 4 Newbies (WNFUN)☆94Updated 6 years ago
- Ruxcon2016 POC Code☆137Updated 8 years ago
- A reference Device Guard code integrity policy consisting of FilePublisher deny rules for published Device Guard configuration bypasses☆115Updated 7 years ago
- Tool to view and create Microsoft shim database files (SDB).☆113Updated 7 years ago
- SysmonX - An Augmented Drop-In Replacement of Sysmon☆214Updated 5 years ago
- Reflective Polymorphism☆104Updated 6 years ago
- Trace ScriptBlock execution for powershell v2☆40Updated 5 years ago
- Another Repo of Malware. Enjoy. <3☆60Updated 6 years ago
- Advanced Portable Executable File Analyzer And Disassembler 32 & 64 Bit☆99Updated 5 years ago
- Just a normal flask web app to understand win32api with code snippets and references.☆72Updated 5 years ago
- Various Yara signatures (possibly to be included in a release later).☆86Updated 5 years ago
- Named pipe I/O ETW provider for Windows☆69Updated 4 years ago
- Windows Drivers☆97Updated 5 years ago