m417z / ntdoc
Native API online documentation, based on the System Informer (formerly Process Hacker) phnt headers
☆252Updated this week
Alternatives and similar repositories for ntdoc
Users that are interested in ntdoc are comparing it to the libraries listed below
Sorting:
- Collection of undocumented Windows API declarations.☆314Updated last month
- Single header version of System Informer's phnt library.☆217Updated last week
- Debugger Anti-Detection Benchmark☆332Updated last year
- 🗜️ A packer for Windows x86 executable files written in C and Intel x86 Assembly. The new file after packing can obstruct reverse engine…☆340Updated 6 months ago
- System call hook for Windows 10 20H1☆487Updated 3 years ago
- protector & obfuscator & code virtualizer☆524Updated this week
- Inline syscalls made easy for windows on clang☆703Updated 10 months ago
- WinVisor - A hypervisor-based emulator for Windows x64 user-mode executables using Windows Hypervisor Platform API☆567Updated 3 months ago
- A modern c++ implementation of windows heavens gate☆222Updated 4 years ago
- DLL that hooks the NtQuerySystemInformation API and hides a process name☆288Updated 2 years ago
- HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate oper…☆362Updated last year
- Windows inline hooking tool.☆268Updated 6 years ago
- Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.☆598Updated 3 months ago
- Native code virtualizer for x64 binaries☆484Updated 4 months ago
- A x64 Windows Rootkit using SSDT or Hypervisor hook☆536Updated 4 months ago
- Operating System Design Review: A systemic analysis of modern systems architecture☆312Updated 2 months ago
- Guided Hacking's official tool to practice bypassing anti-debug techniques.☆253Updated last week
- A small x64 library to load dll's into memory.☆437Updated last year
- Windows NT x64 syscall fuzzer☆605Updated last year
- An x86-64 Code Virtualizer☆258Updated 7 months ago
- Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks☆356Updated 6 months ago
- A list of excellent resources for anyone to deepen their understanding with regards to Windows Kernel Exploitation and general low level …☆143Updated 2 years ago
- COFF and Portable Executable format described using standard C++ with no dependencies.☆279Updated 3 weeks ago
- This project provides a collection of Microsoft Windows kernel structures, unions and enumerations. Most of them are not officially docum…☆203Updated 3 months ago
- Kernel-mode Paravirtualization in Ring 2, LLVM based linker, and some other things!☆337Updated 3 weeks ago
- A library to develop kernel level Windows payloads for post HVCI era☆405Updated 3 years ago
- Collection of hypervisor detections☆236Updated 7 months ago
- Demo proof of concept for shadow regions, and implementation of HyperDeceit.☆277Updated last year
- PE Viewer☆179Updated 3 months ago
- Samples for the book Windows Kernel Programming, 2nd edition☆332Updated 4 months ago