imugee / pegasusView external linksLinks
reverse engineering extension plugin for windbg
☆120Sep 30, 2019Updated 6 years ago
Alternatives and similar repositories for pegasus
Users that are interested in pegasus are comparing it to the libraries listed below
Sorting:
- libemu shim layer and win32 environment for Unicorn Engine☆73Apr 14, 2017Updated 8 years ago
- A branch-monitor-based solution for process monitoring.☆136Feb 9, 2020Updated 6 years ago
- PoC of BOOST-ed _EPROCESS.VadRoot iterating☆27May 21, 2014Updated 11 years ago
- XDV is disassembler or debugger that works based on the extension plugin.☆55Sep 3, 2019Updated 6 years ago
- Just another tool to download specify Symbol (.pdb) files☆39Sep 4, 2019Updated 6 years ago
- Translates WinDbg "dt" structure dump to a C structure☆134Oct 16, 2016Updated 9 years ago
- HAXM hypervisor client☆18Nov 30, 2018Updated 7 years ago
- Internet Explorer Exploit with CFG bypass for Windows 10☆59Jan 11, 2017Updated 9 years ago
- Agent installed on node to launch IDA,Bindiff,... and send results to the server ( AutoDiffWeb )☆10Mar 25, 2016Updated 9 years ago
- ☆30May 23, 2017Updated 8 years ago
- Reverse engineered API for Microsoft's Time Travel Debugger☆36Apr 18, 2024Updated last year
- RVDbg is a debugger/exception handler for Windows processes and has the capability to circumvent anti-debugging techniques. (Cleaner, doc…☆72Sep 5, 2020Updated 5 years ago
- Dynamic binary analysis via platform emulation☆12Aug 10, 2018Updated 7 years ago
- RunPE dump - I wrote this to have better control over the analysis of malwares. I can stop and analysis malware when it uses some of the …☆10Jul 1, 2015Updated 10 years ago
- ☆13Jul 11, 2017Updated 8 years ago
- an efficient yet easy to use network packet builder and parser☆11Jul 3, 2017Updated 8 years ago
- IDAScript to create Symbol file which can be loaded in WinDbg via AddSyntheticSymbol☆41Jul 25, 2014Updated 11 years ago
- This driver implements the Intel Processor Trace functionality in Intel Skylake architecture for Microsoft Windows☆463Apr 17, 2018Updated 7 years ago
- usermode standalone kernel interface☆111Jul 9, 2018Updated 7 years ago
- Lightweight WINAPI tracing with Pin☆27Aug 22, 2019Updated 6 years ago
- Debugger extension for the Debugging Tools for Windows (WinDbg, KD, CDB, NTSD).☆69Nov 14, 2016Updated 9 years ago
- A hypervisor hiding user-mode memory using EPT☆107Jan 28, 2018Updated 8 years ago
- This is a pintool that can analyze target dynamically and output code blocks and "key frames".☆14Mar 26, 2015Updated 10 years ago
- ☆12Feb 19, 2017Updated 8 years ago
- Plugin for x64dbg to break on unresolved APIs.☆12Oct 4, 2017Updated 8 years ago
- Hyper-V Research is trendy now☆197May 6, 2024Updated last year
- A command tree based on commands and extensions for Windows Kernel Debugging.☆111Jul 10, 2020Updated 5 years ago
- Create and use macros in IDA's CLIs☆65Dec 26, 2025Updated last month
- WinDBG Anti-RootKit Extension☆645Jul 29, 2020Updated 5 years ago
- ☆27Apr 4, 2019Updated 6 years ago
- kernel pool windbg extension☆83Jul 23, 2015Updated 10 years ago
- After Process monitor, execute Themida☆15Aug 23, 2017Updated 8 years ago
- Communication via callback☆73Oct 9, 2019Updated 6 years ago
- A sample project for using Capstone from a driver in Visual Studio 2015☆36May 4, 2016Updated 9 years ago
- PEDA-like debugger UI for WinDbg☆206Mar 29, 2024Updated last year
- more at http://www.zer0mem.sk/?p=271☆12Jun 11, 2013Updated 12 years ago
- Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard☆265Aug 31, 2022Updated 3 years ago
- [ARCHIVED] mov rax, ${Thalium/IceBox}; jmp rax;☆76Jun 8, 2019Updated 6 years ago
- a binary x86win32 code obfuscator using virtual machine☆31Jan 8, 2017Updated 9 years ago