leeqwind / PESignAnalyzer
This program can retrieve signature information from PE files which signed by one or more certificates on Windows. Supporting multi-signed (nested) infomation and certificate-chain.
☆99Updated 2 years ago
Alternatives and similar repositories for PESignAnalyzer:
Users that are interested in PESignAnalyzer are comparing it to the libraries listed below
- An example of a client and server using Windows' ALPC functions to send and receive data.☆90Updated 4 years ago
- Windows Kernel Template Library☆108Updated 2 years ago
- Simple driver to register all available process, thread, image, Registry, and Object callbacks☆117Updated 7 years ago
- Simple project that demonstrates how an ETW consumer can be created just by using NTDLL☆139Updated 5 years ago
- Using C++ STL on Windows kernle development☆88Updated 5 years ago
- Advance LPC☆60Updated 7 years ago
- Intel Virtualization Technology demo☆65Updated 8 years ago
- Collect different versions of Crucial modules.☆128Updated 6 months ago
- An Ark tool project,run on Win7 x86/x64☆111Updated 7 years ago
- hook msr by amd svm☆119Updated 5 years ago
- ☆64Updated 6 years ago
- ☆123Updated 4 years ago
- Analyze Windows x64 Kernel Memory Layout☆123Updated 4 years ago
- Use ci.dll API for validating Authenticode signature of files☆136Updated 2 years ago
- Windows Driver Kit Extesion Header (Undoc)☆133Updated 3 years ago
- WinDbg debugger extension library providing various tools to analyse, dump and fix (restore) Microsoft Portable Executable files for both…☆82Updated 4 months ago
- A driver that hooks C: volume using symbolic link callback to track all FS access to the volume☆103Updated 4 years ago
- Authenticode Hash Calculator for PE32/PE32+ files☆108Updated 10 months ago
- ☆171Updated 4 years ago
- A software driver that lets you log kernel-mode debug output into a file on Windows.☆98Updated 6 years ago
- File system minifilter driver for Windows to block symbolic link attacks.☆50Updated 4 years ago
- A minifilter driver preserves all modified and deleted files.☆80Updated 9 years ago
- This is a sample that shows how to leverage SetThreadContext for DLL injection☆81Updated 7 years ago
- Translates WinDbg "dt" structure dump to a C structure☆127Updated 8 years ago
- Automatically exported from code.google.com/p/wskudp☆43Updated 8 years ago
- Collect various versions of ntoskrnl files☆49Updated last year
- Windows Kernel Driver with C++ runtime☆169Updated 4 years ago
- Modern C++ wrapper for Windows PE signature verification mechanism☆28Updated 5 years ago
- D☆40Updated 3 years ago
- The Kernel-Mode Winsock library, supporting TCP, UDP and Unix sockets (DGRAM and STREAM).☆239Updated 9 months ago