hfiref0x / ROCALLLinks
ReactOS x86-32 syscall fuzzer
☆58Updated 2 months ago
Alternatives and similar repositories for ROCALL
Users that are interested in ROCALL are comparing it to the libraries listed below
Sorting:
- DirectNtApi - simple method to make ntapi function call without importing or walking export table. Work under Windows 7, 8 and 10☆53Updated last year
- a binary x86win32 code obfuscator using virtual machine☆32Updated 8 years ago
- A software driver that lets you log kernel-mode debug output into a file on Windows.☆107Updated 7 years ago
- Intermediate x86 instruction representation for use in obfuscation/deobfuscation.☆54Updated 2 months ago
- ☆28Updated 10 years ago
- Virtualization detection through speculative execution PoCs and papers☆68Updated 7 years ago
- This is a simple driver with x64 inline assembly☆57Updated 5 years ago
- Driver and WinDBG scripts to dump information about all resources and lookaside lists☆67Updated 5 years ago
- reverse engineering extension plugin for windbg☆119Updated 5 years ago
- Bypass for the hardening against usage of tagWnd as a kernel read/write primitive☆32Updated 8 years ago
- AllMemPro☆46Updated 7 years ago
- Decrement Windows Kernel for fun and profit☆38Updated 7 years ago
- Windows NT port of 'Main is usually a function. So then when is it not?'☆26Updated last year
- Crash Windows 10 up to RS2 from an unprivileged process☆42Updated 7 years ago
- VMCS Auditor provides almost all of Intel's VMCS Layout checklist based on Bochs Emulator.☆31Updated 6 years ago
- ☆72Updated 11 years ago
- Windbg extension that allows you analyze Control Flow Guard map☆36Updated 3 years ago
- Windows Hypervisor Platform client☆30Updated 7 years ago
- Full reversing of the Microsoft Auxiliary Windows API Library and ported to C☆24Updated 9 months ago
- Comparison table of VMX capabilities for a bunch of processors☆13Updated 4 years ago
- Takes a Windbg dumped structure (using the 'dt' command) and formats it into a C structure☆36Updated last year
- A tool to help malware analysts tell that the sample is injecting code into other process.☆78Updated 10 years ago
- libemu shim layer and win32 environment for Unicorn Engine☆72Updated 8 years ago
- A local copy of Alex Ionescu's seemingly abandoned native-nt-toolkit project containing knowledge inherited from the ReactOS project.☆54Updated 5 years ago
- Miscellaneous Code and Docs☆82Updated 2 months ago
- clone of armadillo patched for windows☆47Updated 10 months ago
- This repository contains some tools that I have written in the past☆28Updated last year
- deprecated☆26Updated 6 years ago
- An API Monitor based on Instrumentation☆44Updated 7 years ago
- executing JS from x86 code☆27Updated 6 years ago