hugsy / defcon_27_windbg_workshop
DEFCON 27 workshop - Modern Debugging with WinDbg Preview
☆715Updated 4 months ago
Alternatives and similar repositories for defcon_27_windbg_workshop:
Users that are interested in defcon_27_windbg_workshop are comparing it to the libraries listed below
- My personal cheat sheet for using WinDbg for kernel debugging☆404Updated 4 months ago
- Pinjectra is a C/C++ OOP-like library that implements Process Injection techniques (with focus on Windows 10 64-bit)☆802Updated 2 years ago
- Examples of leaking Kernel Mode information from User Mode on Windows☆594Updated 7 years ago
- A bunch of JavaScript extensions for WinDbg.☆328Updated 3 months ago
- RpcView is a free tool to explore and decompile Microsoft RPC interfaces☆954Updated last year
- Dump of win32k POCs for bugs I've found☆370Updated 2 years ago
- Internals information about Hyper-V☆685Updated 2 months ago
- Quickly debug shellcode extracted during malware analysis☆586Updated last year
- Scripts and cheatsheets for IDAPython☆661Updated last year
- ☆766Updated 2 years ago
- Checksec, but for Windows: static detection of security mitigations in executables☆577Updated last month
- Time Travel Debugging IDA plugin☆567Updated 8 months ago
- Useful scripts for WinDbg using the debugger data model☆402Updated 11 months ago
- awesome windbg extensions☆324Updated 5 years ago
- collect for learning cases☆576Updated 8 months ago
- A Pin Tool for tracing API calls etc☆1,385Updated last month
- Windows Kernel Drivers fuzzer☆336Updated 7 years ago
- Papers, blogposts, tutorials etc for learning about Windows kernel exploitation, internals and (r|b)ootkits☆388Updated 5 years ago
- Automatic and platform-independent unpacker for Windows binaries based on emulation☆680Updated 5 months ago
- A small, null-free Windows shellcode that executes calc.exe (x86/x64, all OS/SPs)☆405Updated 9 months ago
- ☆182Updated 7 years ago
- My implementation of enSilo's Process Doppelganging (PE injection technique)☆596Updated 2 years ago
- ☆803Updated 5 years ago
- Supporting Data Archives for Ghidra☆262Updated 4 years ago
- My notes while studying Windows internals☆411Updated 2 months ago
- Canadian Furious Beaver is a ProcMon-style tool designed only for capturing IRPs sent to any Windows driver.☆316Updated 11 months ago
- Karta - source code assisted fast binary matching plugin for IDA☆871Updated last year
- DriverBuddy is an IDA Python script to assist with the reverse engineering of Windows kernel drivers.☆359Updated 5 years ago
- Incident Response & Digital Forensics Debugging Extension☆375Updated 6 years ago
- Extract Windows Defender database from vdm files and unpack it☆435Updated 5 years ago