horsicq / xntsvLinks
XNTSV program for detailed viewing of system structures for Windows.
☆460Updated this week
Alternatives and similar repositories for xntsv
Users that are interested in xntsv are comparing it to the libraries listed below
Sorting:
- Debug Child Process Tool (auto attach)☆292Updated last year
- Opcode calculator / ASM calculator☆388Updated this week
- Official x64dbg plugin for IDA Pro.☆521Updated 9 months ago
- Windows NT x64 syscall fuzzer☆607Updated last year
- Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.☆605Updated 5 months ago
- Linker/Compiler/Tool detector for Windows, Linux and MacOS.☆555Updated this week
- Strings plugin for x64dbg☆232Updated this week
- My personal cheat sheet for using WinDbg for kernel debugging☆424Updated 2 months ago
- syser debugger x32/x64 ring3 with source level debugging/watch view/struct view☆285Updated 3 months ago
- A collection of x64dbg scripts. Feel free to submit a pull request to add your script.☆526Updated last year
- Process Monitor X v2☆616Updated last year
- Defeating Patchguard universally for Windows 8, Windows 8.1 and all versions of Windows 10 regardless of HVCI.☆881Updated 5 years ago
- Time Travel Debugging IDA plugin☆587Updated last year
- Canadian Furious Beaver is a ProcMon-style tool designed only for capturing IRPs sent to any Windows driver.☆322Updated last year
- A VMP to VTIL lifter.☆437Updated 4 years ago
- Labeless is a multipurpose IDA Pro plugin system for labels/comments synchronization with a debugger backend, with complex memory dumping…☆553Updated 5 months ago
- Extract Windows Defender database from vdm files and unpack it☆443Updated last week
- A library to develop kernel level Windows payloads for post HVCI era☆413Updated 4 years ago
- A library to load, manipulate, dump PE files. See also: https://github.com/hasherezade/libpeconv_tpl☆1,237Updated last month
- PDBRipper is a utility for extract an information from PDB-files.☆840Updated this week
- IFL - Interactive Functions List (plugin for IDA Pro)☆462Updated 4 months ago
- RpcView is a free tool to explore and decompile Microsoft RPC interfaces☆983Updated last year
- Persistent IAT hooking application - based on bearparser☆259Updated 2 years ago
- A DTrace on Windows Reimplementation☆348Updated 4 months ago
- Detours with just single dependency - NTDLL☆645Updated 2 years ago
- Portable Executable parsing library (from PE-bear)☆655Updated 2 months ago
- Dynamic unpacker based on PE-sieve☆736Updated last month
- Unicorn PE is an unicorn based instrumentation project designed to emulate code execution for windows PE files.☆849Updated last year
- Examples of leaking Kernel Mode information from User Mode on Windows☆605Updated 7 years ago
- WinDBG Anti-RootKit Extension☆633Updated 4 years ago