hasherezade / libpeconv_and_detours_tpl
A template for projects using both libPeConv and MS Detours
☆13Updated last year
Alternatives and similar repositories for libpeconv_and_detours_tpl:
Users that are interested in libpeconv_and_detours_tpl are comparing it to the libraries listed below
- Windows x64 Process Scanner to detect application compatability shims☆36Updated 6 years ago
- Subtract one PE file from another!☆19Updated 3 years ago
- Example for PagedOut!☆24Updated 5 years ago
- A set of small utilities, helpers for PIN tracers☆31Updated last year
- ☆18Updated 3 years ago
- WinXPSP2.Cermalus on stereoids, supporting all 32 bits Windows version. Windows Kernel Virus stuff for noobs☆17Updated last year
- Code Integrity Violation Spotter☆17Updated 7 months ago
- Helper Script to convert a Windbg dumped structure (using the 'dt' command) into a C structure. It creates dummy structs for you if neede…☆26Updated last year
- Static library and headers for linking your software with ntdll.dll☆31Updated 5 years ago
- Windows kernel PDB data parsed into YAML☆34Updated 2 months ago
- ☆27Updated 2 years ago
- Dumps information about all the callback objects found in a dump file and the functions registered for them☆35Updated 4 years ago
- ☆23Updated 4 years ago
- Collection of structures, prototype and examples for Microsoft Macro Assembler (MASM) x64.☆16Updated 4 years ago
- Extract data of TTD trace file to a minidump☆28Updated last year
- Resources from my journey into Windows binary exploitation☆22Updated 6 years ago
- Clone running process with ZwCreateProcess☆58Updated 4 years ago
- ☆31Updated 4 years ago
- A ready-made template for a project based on libpeconv.☆43Updated 2 months ago
- ☆18Updated 5 years ago
- Support Windows OS Reversing by searching easily for references to functions across many DLLs☆34Updated 3 years ago
- automates exploits using ROP chains, using ntdll-scraper☆16Updated 2 years ago
- A PoC to demo modifying cmdline of the child process dynamically. It might be useful against process log tracing, AV or EDR.☆38Updated 4 years ago
- An example of how to use Microsoft Windows Warbird technology☆27Updated last year
- ☆21Updated 6 years ago
- Tiny driver patch to allow kernel callbacks to work on Win10 21h1☆34Updated 2 years ago