eronnen / procmon-parserLinks
Parser to process monitor file formats
☆153Updated last month
Alternatives and similar repositories for procmon-parser
Users that are interested in procmon-parser are comparing it to the libraries listed below
Sorting:
- A collection of free miscellaneous Windows tools☆140Updated 4 months ago
- CallMon is an experimental system call monitoring tool that works on Windows 10 versions 2004+ using PsAltSystemCallHandlers☆144Updated 5 years ago
- WNF Utilities 4 Newbies (WNFUN)☆97Updated 6 years ago
- Hyper-V Research is trendy now☆189Updated last year
- Parse .NET executable files.☆80Updated 2 months ago
- Toy scripts for playing with WinDbg JS API☆242Updated last year
- Official VirusTotal plugin for IDA Pro☆175Updated 2 weeks ago
- ☆68Updated 3 years ago
- Parsers for custom malware formats ("Funky malware formats")☆97Updated 3 years ago
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆315Updated last year
- ☆73Updated 2 years ago
- Extract AutoIt scripts embedded in PE binaries☆212Updated last year
- This tool is the result of a reverse engineering process of the Windows service called SysMain. Time to interact with the prefetch files …☆32Updated 5 years ago
- ShowStopper is a tool for helping malware researchers explore and test anti-debug techniques or verify debugger plugins or other solution…☆219Updated 3 years ago
- Simple windows API logger☆109Updated 6 years ago
- ☆123Updated 5 years ago
- API Logger for Windows Executables☆80Updated 5 years ago
- Hyper-V scripts☆132Updated last week
- ☆63Updated last year
- ☆164Updated 4 years ago
- ☆111Updated 2 months ago
- Metadata hash incorporating the Rich Header for robustness against packing and other malware tricks☆70Updated 4 years ago
- Two IDAPython Scripts help you to reconstruct Microsoft COM (Component Object Model) Code☆184Updated 5 years ago
- Set of antianalysis techniques found in malware☆131Updated 2 years ago
- Named pipe I/O ETW provider for Windows☆71Updated 5 years ago
- An IDA Pro extension for easier (malware) reverse engineering☆115Updated 3 years ago
- ☆139Updated 4 years ago
- ☆131Updated last year
- CFB is a ProcMon-style tool designed to assist capturing IRPs sent to Windows drivers.☆333Updated last year
- DotNext 2019 St. Petersburg Talk Demos☆39Updated 6 years ago