hakril / PythonForWindows
A codebase aimed to make interaction with Windows and native execution easier
☆620Updated 3 weeks ago
Alternatives and similar repositories for PythonForWindows:
Users that are interested in PythonForWindows are comparing it to the libraries listed below
- WinAppDbg Debugger☆455Updated last year
- Automating x64dbg using Python, Snapshots:☆1,478Updated last year
- RpcView is a free tool to explore and decompile Microsoft RPC interfaces☆961Updated last year
- windows syscall table from xp ~ 10 rs4☆353Updated 6 years ago
- DriverBuddy is an IDA Python script to assist with the reverse engineering of Windows kernel drivers.☆358Updated 5 years ago
- Pinjectra is a C/C++ OOP-like library that implements Process Injection techniques (with focus on Windows 10 64-bit)☆806Updated 3 years ago
- Examples of leaking Kernel Mode information from User Mode on Windows☆595Updated 7 years ago
- Portable Executable parsing library (from PE-bear)☆655Updated 7 months ago
- Syscall Monitor is a system monitor program (like Sysinternal's Process Monitor) using Intel VT-X/EPT for Windows7+☆736Updated 7 years ago
- Labeless is a multipurpose IDA Pro plugin system for labels/comments synchronization with a debugger backend, with complex memory dumping…☆543Updated 2 months ago
- WinDBG Anti-RootKit Extension☆626Updated 4 years ago
- Official x64dbg plugin for IDA Pro.☆489Updated 6 months ago
- A library to load, manipulate, dump PE files. See also: https://github.com/hasherezade/libpeconv_tpl☆1,189Updated 3 weeks ago
- Papers, blogposts, tutorials etc for learning about Windows kernel exploitation, internals and (r|b)ootkits☆391Updated 5 years ago
- PowerLoaderEx - Advanced Code Injection Technique for x32 / x64☆363Updated 7 years ago
- A basic Direct Kernel Object Manipulation rootkit that removes a process from the EPROCESS list, hiding it from the Task Manager☆665Updated 6 years ago
- proof-of-concept Windows Driver for injecting DLL into user-mode processes using APC☆1,206Updated 10 months ago
- An extensible framework for easily writing compiler optimized position independent x86 / x64 shellcode for windows platforms.☆508Updated 5 years ago
- pdbex is a utility for reconstructing structures and unions from the PDB into compilable C headers☆848Updated 7 months ago
- Incident Response & Digital Forensics Debugging Extension☆377Updated 6 years ago
- DEFCON 27 workshop - Modern Debugging with WinDbg Preview☆719Updated 4 months ago
- Automatic and platform-independent unpacker for Windows binaries based on emulation☆685Updated 6 months ago
- Quickly debug shellcode extracted during malware analysis☆595Updated last year
- Driver loader for bypassing Windows x64 Driver Signature Enforcement☆1,111Updated 5 years ago
- Runtime Process Manipulation☆231Updated 4 months ago
- Obfuscate specific windows apis with different apis☆997Updated 4 years ago
- makin - reveal anti-debugging and anti-VM tricks [This project is not maintained anymore]☆738Updated 6 years ago
- A bunch of JavaScript extensions for WinDbg.☆331Updated 4 months ago
- Windows NT Syscall tables☆1,255Updated last month
- ☆807Updated 5 years ago