Uses ghidra to find all ETW write metadata for each API in a PE file
☆32Jul 26, 2024Updated 2 years ago
Alternatives and similar repositories for API-To-ETW
Users that are interested in API-To-ETW are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Windows driver template, using C++20 & cmake & GithubActions☆25Aug 9, 2024Updated 2 years ago
- Tool that gathers a customizable set of ETW telemetry and generates user-defined detections☆56Jan 28, 2026Updated 7 months ago
- Binary Ninja MLIL to LLVM IR lifter☆16May 8, 2021Updated 5 years ago
- Collect Windows telemetry for Maldev☆504Aug 14, 2026Updated 2 weeks ago
- A simple provider to analyse what gets passed into Microsoft's Anti-Malware Scan Interface☆17Jan 10, 2020Updated 6 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Monitors ETW for security relevant syscalls maintaining the set called by each unique process☆90May 17, 2023Updated 3 years ago
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆337Aug 15, 2026Updated 2 weeks ago
- Simple DLL and client app that work together to hook all the functions in WinHvPlatform.dll in order to provide logging and introspection…☆21Dec 1, 2021Updated 4 years ago
- Advanced call stack manipulation techniques for evading EDR/XDR on Windows ARM64 systems☆24Aug 22, 2025Updated last year
- ☆52Jun 6, 2025Updated last year
- 大部分常见windows内核文件合集 感谢以下网站给出的版本号参考☆16Mar 4, 2026Updated 5 months ago
- Demonstrates consuming from a SecurityTrace ETW session by consuming from the Threat-Intelligence ETW provider without a driver or PPL pr…☆83Jan 19, 2026Updated 7 months ago
- ☆29Nov 22, 2023Updated 2 years ago
- Walks the CFG bitmap to find previously executable but currently hidden shellcode regions☆142May 17, 2023Updated 3 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- A Windows Kernel Driver Emulator base on Unicorn, Kernel Memory Dump and some of native environment☆193Updated this week
- Rust library for lifting raw binary data to LLVM IR☆65Jul 8, 2026Updated last month
- 可在非测试模式下符号化读取内核内存。Kernel memory can be read symbolically in non test mode。☆108Sep 1, 2022Updated 3 years ago
- ☆30May 16, 2024Updated 2 years ago
- ☆17Jan 9, 2023Updated 3 years ago
- Black Signature Driver☆26Oct 20, 2023Updated 2 years ago
- ☆25May 26, 2021Updated 5 years ago
- about how to make a anti-virus engine☆115May 22, 2025Updated last year
- Static analysis & exploitation-triage toolkit for Windows kernel drivers. Discover IOCTLs, Symbolic Links, and check cert , and Downlaods…☆200Apr 27, 2026Updated 4 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- 正确解析 _HEAP_VS_***符号 ,支持在最新win11 24h2 运行,替换windbg自带的!pool命令☆17Nov 30, 2024Updated last year
- Anti-Rootkit Tool for Windows☆16Mar 24, 2025Updated last year
- WinDbg-ext-MCP bridges your favorite LLM client (like Cursor, Claude, or VS Code) with WinDbg, enabling real-time, AI assisted kernel deb…☆118Sep 10, 2025Updated 11 months ago
- A x86_64 software emulator☆165Aug 25, 2025Updated last year
- Custom KiSystemStartup, can be used to modificate kernel before boot.☆52Apr 7, 2022Updated 4 years ago
- Jupyter Kernel for Ghidra's Jython☆28Apr 13, 2022Updated 4 years ago
- My research into the Windows UCPD☆17Jul 28, 2026Updated last month
- DSE & PG bypass via BYOVD attack☆83Jul 12, 2025Updated last year
- PoC memory injection detection agent based on ETW, for offensive and defensive research purposes☆300Apr 10, 2021Updated 5 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- ☆20Feb 22, 2021Updated 5 years ago
- A Proof-of-Concept implementation of Reflective DLL Injection (RDI) specifically for Windows on ARM64. Demonstrates PEB access via the x1…☆38May 30, 2025Updated last year
- Totsugekitai DeBugger☆21May 19, 2024Updated 2 years ago
- Easily hook WIN32 x64 functions☆18Feb 19, 2025Updated last year
- ☆267Jun 7, 2025Updated last year
- Uses Threat-Intelligence ETW events to identify shellcode regions being hidden by fluctuating memory protections☆186May 17, 2023Updated 3 years ago
- Windows OS Internals Curriculum Resource Kit ACADEMIC☆19Nov 4, 2017Updated 8 years ago