eronnen / procmon-parser
Parser to process monitor file formats
☆123Updated last year
Related projects ⓘ
Alternatives and complementary repositories for procmon-parser
- Hyper-V Research is trendy now☆171Updated 6 months ago
- Named pipe I/O ETW provider for Windows☆66Updated 4 years ago
- Toy scripts for playing with WinDbg JS API☆218Updated 4 months ago
- Simple windows API logger☆98Updated 5 years ago
- Parsers for custom malware formats ("Funky malware formats")☆92Updated 2 years ago
- ☆100Updated 11 months ago
- IDA python plugin to scan binary with Yara rules☆171Updated 9 months ago
- ☆68Updated 2 years ago
- Bindings for Microsoft WinDBG TTD☆211Updated last year
- CallMon is an experimental system call monitoring tool that works on Windows 10 versions 2004+ using PsAltSystemCallHandlers☆129Updated 4 years ago
- Two IDAPython Scripts help you to reconstruct Microsoft COM (Component Object Model) Code☆178Updated 4 years ago
- ☆107Updated 4 years ago
- GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.☆113Updated last year
- A Windows kernel dump C++ parser library with Python 3 bindings.☆193Updated 3 months ago
- A DTrace on Windows Reimplementation☆328Updated 2 weeks ago
- An IDA Pro extension for easier (malware) reverse engineering☆110Updated 2 years ago
- Hyper-V Research is trendy now☆150Updated 3 weeks ago
- Robust Automated Malware Unpacker☆84Updated last year
- Set of antianalysis techniques found in malware☆129Updated last year
- WNF Utilities 4 Newbies (WNFUN)☆91Updated 5 years ago
- A collection of free miscellaneous Windows tools☆122Updated 2 months ago
- Hyper-V scripts☆112Updated 11 months ago
- (unofficial) Hyper-V® Development Kit☆215Updated 8 months ago
- The history of Windows Internals via symbols.☆177Updated 3 years ago
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆266Updated 6 months ago
- This project aims at simplifying Windows API import recovery on arbitrary memory dumps☆241Updated last year
- Parse .NET executable files.☆74Updated 3 weeks ago
- An application to view and filter pool allocations from a dmp file on Windows 10 RS5+.☆124Updated last year
- The content of this repository aims to assist efforts on analysing inner working principles, functionalities, and properties of the Micro…☆150Updated 4 years ago
- IDA Pro plugin for recognizing known hashes of API function names☆81Updated 2 years ago