kusano / ntfsdump
Extract files from NTFS Volume
☆32Updated 3 years ago
Related projects ⓘ
Alternatives and complementary repositories for ntfsdump
- A ready-made template for a project based on libpeconv.☆41Updated last month
- Blog posts☆30Updated 4 years ago
- Not Another Code Injection Toolkit☆16Updated 3 years ago
- MSTSC Packet Dump Utility☆27Updated 2 years ago
- Demos and presentation from SECArmy Village Grayhat 2020☆36Updated last year
- Rekall Memory Forensic Framework☆29Updated 5 years ago
- C Header Only Library for Virii☆9Updated 4 years ago
- A small library helping to parse commandline parameters (for C/C++)☆53Updated last year
- Headers for linking your software with ntdll.dll☆15Updated 4 years ago
- An example pattern in C# for using WMI to monitor process creation and termination events.☆51Updated 6 years ago
- Dumps information about all the callback objects found in a dump file and the functions registered for them☆34Updated 4 years ago
- collection of links related to using and improving windbg☆19Updated 6 years ago
- An IDA plugin to deal with Event Tracing for Windows (ETW)☆50Updated 2 years ago
- ☆49Updated 4 years ago
- Windows x64 Process Scanner to detect application compatability shims☆36Updated 6 years ago
- DotNext 2019 St. Petersburg Talk Demos☆36Updated 5 years ago
- Uses WMI Event Win32_ModuleLoadTrace to monitor module loading. Provides filters, and detailed data. Has an option to monitor for CLR Inj…☆39Updated 5 years ago
- ☆35Updated 5 years ago
- Bare template for a Kernel Mode Driver☆51Updated 4 years ago
- Data and structures regarding the research done on WdFilter☆13Updated 4 years ago
- Windows Inline function hooking library targeted at MSVC☆26Updated 8 years ago
- Code Injection technique written in cpp language☆31Updated 6 years ago
- A demo implementation of a well-known technique used by some malware to evade userland hooking, using my library: libpeconv.☆19Updated 6 years ago
- A collection of shellcode hashes☆17Updated 6 years ago
- This is a simple tool to dump all the reparse points on an NTFS volume.☆31Updated 4 years ago