kusano / ntfsdump
Extract files from NTFS Volume
☆32Updated 3 years ago
Alternatives and similar repositories for ntfsdump:
Users that are interested in ntfsdump are comparing it to the libraries listed below
- Dumps information about all the callback objects found in a dump file and the functions registered for them☆35Updated 4 years ago
- Blog posts☆30Updated 4 years ago
- Call 32bit NtDLL API directly from WoW64 Layer☆60Updated 4 years ago
- ☆22Updated 4 years ago
- Trace events in real time sessions☆45Updated last year
- Yet another Windows DLL injector.☆38Updated 3 years ago
- MSTSC Packet Dump Utility☆29Updated 3 years ago
- Enumerate the DLLs/Modules using NtQueryVirtualMemory☆32Updated 9 years ago
- Static library and headers for linking your software with ntdll.dll☆32Updated 5 years ago
- A ready-made template for a project based on libpeconv.☆46Updated last month
- A simple parser(library) which extracts shimcache data from windows.☆14Updated 5 years ago
- Yet another windows syscall library☆18Updated 4 years ago
- Windows Application Loader Running *.Exe files in Memory against Scrylla☆21Updated 5 years ago
- ☆15Updated 4 years ago
- Windows x64 Process Scanner to detect application compatability shims☆37Updated 6 years ago
- ☆36Updated 3 years ago
- A driver to intercept low level windows events☆62Updated 5 years ago
- ☆31Updated 4 years ago
- Demos and presentation from SECArmy Village Grayhat 2020☆37Updated 2 years ago
- A simple API monitor for Windbg☆63Updated 7 years ago
- ☆33Updated 3 years ago
- Library for Windows XML Event Log (EVTX) data types☆18Updated 6 months ago
- Windbg extension that allows you analyze Control Flow Guard map☆34Updated 3 years ago
- Capture BAT is a behavioral analysis tool of applications for the Win32 operating system family.☆32Updated 11 years ago
- Easily hook WIN32 x64 functions☆18Updated last month
- ☆18Updated 4 years ago
- A demo implementation of a well-known technique used by some malware to evade userland hooking, using my library: libpeconv.☆19Updated 6 years ago
- Headers for linking your software with ntdll.dll☆15Updated 4 years ago
- DirectNtApi - simple method to make ntapi function call without importing or walking export table. Work under Windows 7, 8 and 10☆52Updated last year
- Rekall Memory Forensic Framework☆32Updated 5 years ago