hfiref0x / ROCALLLinks
ReactOS x86-32 syscall fuzzer
☆55Updated last month
Alternatives and similar repositories for ROCALL
Users that are interested in ROCALL are comparing it to the libraries listed below
Sorting:
- a binary x86win32 code obfuscator using virtual machine☆32Updated 8 years ago
- Decrement Windows Kernel for fun and profit☆38Updated 7 years ago
- DirectNtApi - simple method to make ntapi function call without importing or walking export table. Work under Windows 7, 8 and 10☆53Updated last year
- Virtualization detection through speculative execution PoCs and papers☆70Updated 7 years ago
- VMCS Auditor provides almost all of Intel's VMCS Layout checklist based on Bochs Emulator.☆32Updated 6 years ago
- This is a simple driver with x64 inline assembly☆57Updated 5 years ago
- Bootkits Revisited☆40Updated 11 years ago
- libemu shim layer and win32 environment for Unicorn Engine☆72Updated 8 years ago
- Bypass for the hardening against usage of tagWnd as a kernel read/write primitive☆29Updated 8 years ago
- Windows NT port of 'Main is usually a function. So then when is it not?'☆25Updated last year
- Intermediate x86 instruction representation for use in obfuscation/deobfuscation.☆53Updated last month
- Windbg extension that allows you analyze Control Flow Guard map☆36Updated 3 years ago
- Windows 10 UAC bypass PoC using LaunchInfSection☆34Updated 7 years ago
- reverse engineering extension plugin for windbg☆116Updated 5 years ago
- Adding exceptions to Microsoft's Control Flow Guard (CFG)☆58Updated 9 years ago
- ☆34Updated 7 years ago
- Driver and WinDBG scripts to dump information about all resources and lookaside lists☆68Updated 5 years ago
- Decompiler for Code Virtualizer 1.3.8 (Oreans)☆81Updated 12 years ago
- An API Monitor based on Instrumentation☆43Updated 7 years ago
- Plugins for IDA Pro and Hex-Rays☆46Updated 7 years ago
- deprecated☆26Updated 6 years ago
- A software driver that lets you log kernel-mode debug output into a file on Windows.☆107Updated 7 years ago
- Windows API listing in JSON format - generated from SDK headers + SDK API documentation☆66Updated 5 years ago
- AllMemPro☆45Updated 7 years ago
- A session-0 capable dll injection utility☆76Updated 7 years ago
- clone of armadillo patched for windows☆47Updated 9 months ago
- ☆72Updated 11 years ago
- A windbg extension, extracting token related contents☆41Updated 4 years ago
- A tool to help malware analysts tell that the sample is injecting code into other process.☆78Updated 9 years ago
- Takes a Windbg dumped structure (using the 'dt' command) and formats it into a C structure☆36Updated last year