m417z / ntdoc
Native API online documentation, based on the System Informer (formerly Process Hacker) phnt headers
☆163Updated last week
Related projects ⓘ
Alternatives and complementary repositories for ntdoc
- Single header version of System Informer's phnt library.☆186Updated this week
- Debugger Anti-Detection Benchmark☆291Updated 11 months ago
- Bootkit for Windows Sandbox to disable DSE/PatchGuard.☆261Updated last month
- msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA.☆148Updated 10 months ago
- Collection of undocumented Windows API declarations.☆291Updated 3 weeks ago
- A DTrace on Windows Reimplementation☆328Updated 3 weeks ago
- Demo proof of concept for shadow regions, and implementation of HyperDeceit.☆267Updated last year
- Collection of hypervisor detections☆189Updated last month
- Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard☆237Updated 2 years ago
- PE Viewer☆152Updated 3 weeks ago
- Advanced driver monitoring utility.☆201Updated 2 years ago
- ntdll.h - compatible with MSVC 6.0, Intel C++ Compiler and MinGW. Serves as a complete replacement for Windows.h☆130Updated 5 years ago
- The Windows Research Kernel (WRK)☆174Updated 8 years ago
- HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate oper…☆360Updated last year
- A list of excellent resources for anyone to deepen their understanding with regards to Windows Kernel Exploitation and general low level …☆123Updated 2 years ago
- Recon 2023 slides and code☆79Updated last year
- A library to develop kernel level Windows payloads for post HVCI era☆366Updated 3 years ago
- Small tool to convert beteween the PE alignments (raw and virtual).☆81Updated last year
- Explore Kernel Objects on Windows☆200Updated 10 months ago
- Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks☆326Updated 3 weeks ago
- The Windbg extension that implements commands helpful to study Hyper-V on Intel processors.☆130Updated last month
- Side-by-side comparison of the Windows and Linux (GNU) Loaders☆288Updated 2 months ago
- Signtool for expired certificates☆455Updated last year
- Kernel-mode Paravirtualization in Ring 2, LLVM based linker, and some other things!☆260Updated 3 weeks ago
- Comparing, discussing, and bypassing various techniques for suspending and freezing processes on Windows.☆114Updated 3 years ago
- Native code virtualizer for x64 binaries☆403Updated this week
- Windows inline hooking tool.☆226Updated 6 years ago
- Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).☆115Updated 2 months ago
- masm32 kernel programming, drivers, tutorials, examples, and tools (credits Four-F)☆115Updated last year
- x64 Windows kernel code execution via user-mode, arbitrary syscall, vulnerable IOCTLs demonstration☆226Updated 2 years ago