Native API online documentation, based on the System Informer (formerly Process Hacker) phnt headers
☆451Jul 26, 2026Updated this week
Alternatives and similar repositories for ntdoc
Users that are interested in ntdoc are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Native API header files for the System Informer project.☆1,449Mar 26, 2026Updated 4 months ago
- Windows Object Explorer 64-bit☆1,959Updated this week
- Windows NT Syscall tables☆1,449Jul 4, 2026Updated 3 weeks ago
- Reverse engineering winapi function loadlibrary.☆251Apr 17, 2023Updated 3 years ago
- Undocumented MSVC☆49Nov 10, 2025Updated 8 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- PDB file inspection tool☆137Nov 21, 2025Updated 8 months ago
- Anti-Rootkit/Anti-Cheat Driver to uncover unbacked or hidden kernel code.☆341Mar 12, 2026Updated 4 months ago
- Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.☆677Jan 28, 2025Updated last year
- Process Injection using Thread Name☆311Apr 18, 2025Updated last year
- An example of how to use Microsoft Windows Warbird technology☆96Apr 23, 2023Updated 3 years ago
- A library to load, manipulate, dump PE files. See also: https://github.com/hasherezade/libpeconv_tpl☆1,375Apr 18, 2026Updated 3 months ago
- Collection of undocumented Windows API declarations.☆363Updated this week
- Implementing an early exception handler for hooking and threadless process injection without relying on VEH or SEH☆140Aug 31, 2025Updated 10 months ago
- Windows System Call Tables (NT/2000/XP/2003/Vista/7/8/10/11)☆2,617Dec 30, 2025Updated 6 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Metamorphic cross-compilation of C++ & C-code to PIC, BOF & EXE.☆640Feb 2, 2026Updated 5 months ago
- PE Viewer☆232Jun 11, 2026Updated last month
- Single header version of System Informer's phnt library.☆249Mar 27, 2026Updated 4 months ago
- Ryūjin Protector - Is a Intel Arch - BIN2BIN - PE Obfuscation/Protection/DRM tool☆336Nov 20, 2025Updated 8 months ago
- Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).☆172Aug 23, 2024Updated last year
- "Service-less" driver loading☆189Nov 28, 2024Updated last year
- Process Monitor X v2☆660Jul 4, 2026Updated 3 weeks ago
- Research on obfuscated licensing APIs / CLIP service in the Windows kernel☆145Aug 23, 2022Updated 3 years ago
- Kernel Driver Utility☆2,673Jul 22, 2026Updated last week
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Injecting code by recompiling shellcode into a ROP chain.☆144Apr 21, 2026Updated 3 months ago
- A tool that is used to hunt vulnerabilities in x64 WDM drivers☆469Jun 18, 2026Updated last month
- Windows Anti-Rootkit Tool☆566Updated this week
- Advanced VM detection library and tool☆1,320Updated this week
- My personal cheat sheet for using WinDbg for kernel debugging☆474Apr 17, 2025Updated last year
- An index of Windows binaries, including download links for executables such as exe, dll and sys files☆855Updated this week
- Hooking Windows' exception dispatcher to protect process's PML4☆261Jan 24, 2025Updated last year
- Windows Explorer application written in assembly☆15Jun 15, 2023Updated 3 years ago
- proof-of-concept Windows Driver for injecting DLL into user-mode processes using APC☆1,292May 1, 2024Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Windows rootkit for Intel x64 with 25+ features, demonstrating rootkit techniques compatible with all Windows 10 and Windows 11 versions.☆2,443Jun 26, 2026Updated last month
- RunPE implementation with multiple evasive techniques (2)☆284Sep 25, 2025Updated 10 months ago
- A x86_64 software emulator☆163Aug 25, 2025Updated 11 months ago
- Collection of various malicious functionality to aid in malware development☆1,920Feb 28, 2024Updated 2 years ago
- Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.☆245Sep 26, 2023Updated 2 years ago
- Usermode exploit to bypass any AC using a 0day shatter attack.☆384Nov 26, 2025Updated 8 months ago
- 🪅 Windows & Linux userspace emulator☆3,437Updated this week