Windows kernel research tool. Looks like a debugger, but it is not a debugger. It uses a kernel driver to provide a WinDbg-like live kernel debugging experience from a TUI console.
☆71Jul 30, 2026Updated this week
Alternatives and similar repositories for kn-live-dbg
Users that are interested in kn-live-dbg are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- An IDA Pro / Hex-Rays plugin that turns noisy pseudocode into reviewable, kernel-aware cleanup artifacts☆159Jul 7, 2026Updated 3 weeks ago
- WinDbg x64 extension that disassembles live functions and uses an LLM to produce verified pseudocode.☆111Jun 22, 2026Updated last month
- Modern Win32 API monitor for Windows security, reverse engineering, debugging, and anti-cheat research.☆45Jun 28, 2026Updated last month
- ApplyCalleeType IDA Plugin 🤙 — Reborn. Single-file port to IDA Pro 9.3 with right-click menu, live prototype editor, and full SAL/MSDN p…☆77Mar 9, 2026Updated 4 months ago
- Kernforge is a project intelligence and fuzzing workbench for Windows security, anti-cheat engineering, and evidence-backed verification.☆25Jul 23, 2026Updated last week
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Windows Analysis and Research Toolkit☆674Apr 28, 2026Updated 3 months ago
- Noradrenaline is a collection of high-performance post-exploitation shared libraries designed for native execution on macOS and Linux end…☆29Jul 6, 2026Updated 3 weeks ago
- Intel 64/Windows low-level experiments☆108Jul 21, 2026Updated last week
- Usermode NT Explorer - Query kernel addresses, translate virtual to physical addresses, inspect the PFN database, and more.☆89Mar 16, 2026Updated 4 months ago
- Static analysis & exploitation-triage toolkit for Windows kernel drivers. Discover IOCTLs, Symbolic Links, and check cert , and Downlaods…☆197Apr 27, 2026Updated 3 months ago
- Semantic analysis engine for detecting vulnerability fixes in Windows kernel driver patches — 58 YAML rules, Ghidra decompilation, reacha…☆64Feb 26, 2026Updated 5 months ago
- An educational anti-cheat system for learning Windows kernel programming, process monitoring, and cheat detection techniques☆38Jul 24, 2026Updated last week
- Lua bytecode disassembler and decompiler for Lua 5.1, 5.2, 5.3, 5.4, and 5.5 binary chunks.☆24May 18, 2026Updated 2 months ago
- Demonstrate calling a kernel function and handle process creation callback against HVCI☆85Dec 21, 2022Updated 3 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Pyside6 implementation of YaraXGUI☆28May 19, 2026Updated 2 months ago
- WinMan - An Offline WIN/NT API Documentation☆30Jul 8, 2026Updated 3 weeks ago
- ☆28Jun 21, 2026Updated last month
- Windows User-Mode Shellcode Development Framework (WUMSDF)☆157Jul 15, 2026Updated 2 weeks ago
- ☆86Feb 12, 2026Updated 5 months ago
- Polymorphic PE rewriter for Windows x64 , rewrites binaries into semantically identical but byte-different variants☆200Jun 6, 2026Updated last month
- Thats it! An Open-Source Windows UEFI Rootkit☆40Jul 19, 2025Updated last year
- Multiplatform MEMORY.DMP analysis tool with a WinDbg flavor☆175Apr 20, 2026Updated 3 months ago
- Set of PoC to abuse Windows minifilters functionality☆94May 1, 2026Updated 3 months ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- C# MCP server for kernel & user-mode Windows debugging — DbgEng COM, KDNET, Frida, dbgsrv, TTD, and integrated VM control. 29 tools for L…☆36Jul 5, 2026Updated 3 weeks ago
- This repository contains the research tool presented at x33fcon 2026, along with the associated presentation slides. The content is made …☆62Jun 15, 2026Updated last month
- tests to catch some sloppy hv impls☆36Mar 16, 2026Updated 4 months ago
- binary instrumentation, analysis, and patching framework☆105Feb 20, 2026Updated 5 months ago
- first public in-process reflective PE loader for .NET NativeAOT binaries. maps a NativeAOT executable into the current process and execut…☆28Mar 28, 2026Updated 4 months ago
- usermode thread hijacking detection via working set page fault monitoring☆40Jul 17, 2026Updated 2 weeks ago
- DSCourier is a proof-of-concept that uses the WinGet Configuration COM API to apply DSC configurations through Microsoft-signed binaries.☆210Jun 25, 2026Updated last month
- An MCP to expose process monitoring and ETW tracing functionally to AI agents to assist in security work☆78May 6, 2026Updated 2 months ago
- Async port/ping scanner BOF. Supports IP/port ranges, CIDR notation and hostnames.☆18Jul 23, 2026Updated last week
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Ctrl+Scroll font zoom for all IDA views — Disassembly, Pseudocode, Hex View, Imports, Exports, Functions, Strings, and more. Compatible I…☆29Apr 15, 2026Updated 3 months ago
- PPLReaper is a Windows UNSIGNED kernel driver + userland companion tool designed to inspect and manipulate Protected Process Light (PPL) …☆24Mar 4, 2026Updated 4 months ago
- Vibe Reverse Engineer with IDA SQL: An interface for IDA in SQL via live virtual tables☆363Jul 26, 2026Updated last week
- Hooking Windows' exception dispatcher to protect process's PML4☆263Jan 24, 2025Updated last year
- ☆31Apr 2, 2026Updated 4 months ago
- Injecting code by recompiling shellcode into a ROP chain.☆144Apr 21, 2026Updated 3 months ago
- Static devirtualizer for VMProtect 3.0-3.5. Lifts virtualized code to LLVM using Remill and strips the VM layer through optimization.☆306Updated this week