kobykahane / NpEtw
Named pipe I/O ETW provider for Windows
☆66Updated 4 years ago
Related projects ⓘ
Alternatives and complementary repositories for NpEtw
- A command tree based on commands and extensions for Windows Kernel Debugging.☆105Updated 4 years ago
- Simple project that demonstrates how an ETW consumer can be created just by using NTDLL☆134Updated 5 years ago
- Hyper-V Research is trendy now☆171Updated 6 months ago
- WinDbg debugger extension library providing various tools to analyse, dump and fix (restore) Microsoft Portable Executable files for both…☆81Updated 2 months ago
- Hyper-V Research is trendy now☆150Updated 3 weeks ago
- The history of Windows Internals via symbols.☆177Updated 3 years ago
- Elevation of privilege detector based on HyperPlatform☆117Updated 7 years ago
- CallMon is an experimental system call monitoring tool that works on Windows 10 versions 2004+ using PsAltSystemCallHandlers☆129Updated 4 years ago
- A software driver that lets you log kernel-mode debug output into a file on Windows.☆96Updated 6 years ago
- Windows Drivers☆95Updated 5 years ago
- Driver and WinDBG scripts to dump information about all resources and lookaside lists☆66Updated 4 years ago
- A simple API monitor for Windbg☆62Updated 7 years ago
- Toy scripts for playing with WinDbg JS API☆218Updated 4 months ago
- 0CCh Windbg extension: include some useful commands☆109Updated last year
- Two IDAPython Scripts help you to reconstruct Microsoft COM (Component Object Model) Code☆178Updated 4 years ago
- Windbg extension to find PatchGuard pages☆117Updated 10 years ago
- Driver Initial Reconnaissance Tool☆119Updated 4 years ago
- An application to view and filter pool allocations from a dmp file on Windows 10 RS5+.☆124Updated last year
- Windbg2ida lets you dump each step in Windbg then shows these steps in IDA☆73Updated 4 months ago
- Log ALPC activity☆80Updated last year
- ☆120Updated last month
- Mario & Luigi - Tools for sniffing Windows Named Pipes communication☆129Updated 7 years ago
- DotNext 2019 St. Petersburg Talk Demos☆36Updated 5 years ago
- WNF Utilities 4 Newbies (WNFUN)☆91Updated 5 years ago
- Parsers for custom malware formats ("Funky malware formats")☆92Updated 2 years ago
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆266Updated 6 months ago
- A collection of free miscellaneous Windows tools☆122Updated 2 months ago
- Some research on AltSystemCallHandlers functionality in Windows 10 20H1 18999☆204Updated 5 years ago
- [ARCHIVED] mov rax, ${Thalium/IceBox}; jmp rax;☆71Updated 5 years ago