gamozolabs / mempeekView external linksLinks
A command line tool that resembles a debugger as well as Cheat Engine, to search for values in memory
☆223May 28, 2022Updated 3 years ago
Alternatives and similar repositories for mempeek
Users that are interested in mempeek are comparing it to the libraries listed below
Sorting:
- A code parser for C-Style header files that lets you to parse function's prototypes and data types used in their parameters.☆94Apr 17, 2022Updated 3 years ago
- A /proc/mem IDA loader to snapshot a running process☆168Jun 29, 2025Updated 7 months ago
- kernel driver used to monitor the activity of BadlionAnticheat.sys by patching its IAT☆33Jul 9, 2021Updated 4 years ago
- Reverse engineered API for Microsoft's Time Travel Debugger☆36Apr 18, 2024Updated last year
- High-performance QEMU memory and instruction tracing☆552Jul 26, 2024Updated last year
- Time Travel Debugging IDA plugin☆593Jun 27, 2024Updated last year
- Static analysis tool based on clang, which detects source-to-binary information leaks in C and C++ projects☆86Oct 2, 2022Updated 3 years ago
- Highly advanced Linux anti-exploitation and anti-tamper binary protector for ELF.☆159Sep 3, 2022Updated 3 years ago
- A simple password-based PE encryptor for Windows 32-bit executables.☆51Jan 9, 2025Updated last year
- Virtual Tagger Plugin is a Cutter plugin that significantly improves handling and analysis of vtables and virtual functions☆16Mar 23, 2023Updated 2 years ago
- A DTrace on Windows Reimplementation☆369Feb 3, 2026Updated last week
- Web-based tool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across different versions of the …☆354Feb 5, 2026Updated last week
- Advanced driver monitoring utility.☆218Jul 13, 2022Updated 3 years ago
- x86/x64 Ring 0/-2 System Freezer/Debugger☆120May 21, 2025Updated 8 months ago
- ☆31Jan 12, 2022Updated 4 years ago
- Detours implementation (x64/x86) which used only ntdll import☆90Oct 14, 2025Updated 3 months ago
- Snapshot-based coverage-guided windows kernel fuzzer☆322Dec 16, 2021Updated 4 years ago
- Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard☆265Aug 31, 2022Updated 3 years ago
- C/C++ Runtime library for system file (Windows Kernel Driver) - Supports Microsoft STL☆194Aug 27, 2022Updated 3 years ago
- ☆85Oct 15, 2022Updated 3 years ago
- Header only wrapper around Hex-Rays API in C++20.☆168Dec 25, 2024Updated last year
- Hygieia, a vulnerable driver traces scanner written in C++ as an x64 Windows kernel driver.☆150Feb 12, 2022Updated 4 years ago
- Binary Ninja plugin for exploring Structured Exception Handlers☆82Jun 6, 2024Updated last year
- Slides and Material for "SymbolicExecutionDemystified" Presentation @ Insomni'Hack 2022☆100Mar 26, 2022Updated 3 years ago
- Cross-platform tool that allows browsing and extracting C and C++ type declarations from PDB files.☆358Feb 9, 2025Updated last year
- HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate oper…☆376Jun 3, 2023Updated 2 years ago
- A blazing fast™ multithreaded ROP Gadget finder. ropper / ropgadget alternative (currently x86 only)☆542Jun 4, 2025Updated 8 months ago
- Bindings for Microsoft WinDBG TTD☆234Aug 5, 2023Updated 2 years ago
- ☆12Jun 22, 2022Updated 3 years ago
- ☆16Feb 1, 2026Updated last week
- ☆118Aug 7, 2022Updated 3 years ago
- An easy-to-use library for emulating memory dumps. Useful for malware analysis (config extraction, unpacking) and dynamic analysis in gen…☆854Feb 2, 2024Updated 2 years ago
- A WinDbg extension to trace COM interactions☆131Aug 14, 2025Updated 5 months ago
- Type 2 Hypervisor for security research supported by AMD-V hardware assisted virtualization☆41Jan 9, 2023Updated 3 years ago
- ☆72Feb 28, 2023Updated 2 years ago
- Workshop Material on VM-based Deobfuscation☆196Oct 20, 2021Updated 4 years ago
- A native hypervisor designed for the Windows operating system☆125Mar 6, 2021Updated 4 years ago
- A command line Windows API tracing tool for Golang binaries.☆159Dec 4, 2023Updated 2 years ago
- CFB is a ProcMon-style tool designed to assist capturing IRPs sent to Windows drivers.☆333Mar 26, 2024Updated last year