eronnen / procmon-parserLinks
Parser to process monitor file formats
☆154Updated 2 months ago
Alternatives and similar repositories for procmon-parser
Users that are interested in procmon-parser are comparing it to the libraries listed below
Sorting:
- WNF Utilities 4 Newbies (WNFUN)☆98Updated 7 years ago
- Official VirusTotal plugin for IDA Pro☆176Updated 2 weeks ago
- CallMon is an experimental system call monitoring tool that works on Windows 10 versions 2004+ using PsAltSystemCallHandlers☆144Updated 5 years ago
- Parse .NET executable files.☆81Updated 3 months ago
- Toy scripts for playing with WinDbg JS API☆242Updated last year
- Hyper-V Research is trendy now☆190Updated last year
- A collection of free miscellaneous Windows tools☆140Updated 4 months ago
- capemon: CAPE's monitor☆142Updated last week
- GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.☆118Updated 2 years ago
- Parsers for custom malware formats ("Funky malware formats")☆98Updated 3 years ago
- Simple windows API logger☆109Updated 6 years ago
- Metadata hash incorporating the Rich Header for robustness against packing and other malware tricks☆70Updated 4 years ago
- ☆73Updated 2 years ago
- Named pipe I/O ETW provider for Windows☆71Updated 5 years ago
- ☆124Updated 5 years ago
- IDA Pro plugin for recognizing known hashes of API function names☆82Updated 3 years ago
- Two IDAPython Scripts help you to reconstruct Microsoft COM (Component Object Model) Code☆184Updated 5 years ago
- ☆111Updated 3 months ago
- Extract AutoIt scripts embedded in PE binaries☆215Updated last year
- ShowStopper is a tool for helping malware researchers explore and test anti-debug techniques or verify debugger plugins or other solution…☆219Updated 3 years ago
- ☆164Updated 4 years ago
- API Logger for Windows Executables☆80Updated 5 years ago
- ☆140Updated 4 years ago
- ☆68Updated 3 years ago
- Go Lang Portable Executable Parser☆39Updated 4 years ago
- This tool is the result of a reverse engineering process of the Windows service called SysMain. Time to interact with the prefetch files …☆32Updated 5 years ago
- Native Python3 bindings for @horsicq's Detect-It-Easy☆76Updated 7 months ago
- ☆148Updated 2 years ago
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆323Updated last year
- WIP Emotet Control Flow Unflattening using miasm and radare2☆23Updated 2 years ago