Native API online documentation, based on the System Informer (formerly Process Hacker) phnt headers
☆464Jul 26, 2026Updated 3 weeks ago
Alternatives and similar repositories for ntdoc
Users that are interested in ntdoc are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Native API header files for the System Informer project.☆1,463Mar 26, 2026Updated 4 months ago
- Windows Object Explorer 64-bit☆1,967Updated this week
- Windows NT Syscall tables☆1,455Jul 4, 2026Updated last month
- Reverse engineering winapi function loadlibrary.☆252Apr 17, 2023Updated 3 years ago
- Undocumented MSVC☆50Nov 10, 2025Updated 9 months ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- PDB file inspection tool☆138Nov 21, 2025Updated 8 months ago
- Anti-Rootkit/Anti-Cheat Driver to uncover unbacked or hidden kernel code.☆346Mar 12, 2026Updated 5 months ago
- Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.☆679Jan 28, 2025Updated last year
- Process Injection using Thread Name☆312Apr 18, 2025Updated last year
- An example of how to use Microsoft Windows Warbird technology☆97Apr 23, 2023Updated 3 years ago
- A library to load, manipulate, dump PE files. See also: https://github.com/hasherezade/libpeconv_tpl☆1,382Apr 18, 2026Updated 4 months ago
- Collection of undocumented Windows API declarations.☆365Jul 25, 2026Updated 3 weeks ago
- Implementing an early exception handler for hooking and threadless process injection without relying on VEH or SEH☆141Aug 31, 2025Updated 11 months ago
- Windows System Call Tables (NT/2000/XP/2003/Vista/7/8/10/11)☆2,628Dec 30, 2025Updated 7 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Metamorphic cross-compilation of C++ & C-code to PIC, BOF & EXE.☆641Feb 2, 2026Updated 6 months ago
- PE Viewer☆233Jun 11, 2026Updated 2 months ago
- Single header version of System Informer's phnt library.☆251Mar 27, 2026Updated 4 months ago
- Ryūjin Protector - Is a Intel Arch - BIN2BIN - PE Obfuscation/Protection/DRM tool☆341Nov 20, 2025Updated 8 months ago
- Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).☆171Aug 23, 2024Updated last year
- "Service-less" driver loading☆191Nov 28, 2024Updated last year
- Process Monitor X v2☆662Jul 4, 2026Updated last month
- Research on obfuscated licensing APIs / CLIP service in the Windows kernel☆146Aug 23, 2022Updated 3 years ago
- Kernel Driver Utility☆2,693Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Injecting code by recompiling shellcode into a ROP chain.☆145Apr 21, 2026Updated 3 months ago
- A tool that is used to hunt vulnerabilities in x64 WDM drivers☆470Jun 18, 2026Updated 2 months ago
- Windows Anti-Rootkit Tool☆568Jul 25, 2026Updated 3 weeks ago
- Advanced VM detection library and tool☆1,352Updated this week
- My personal cheat sheet for using WinDbg for kernel debugging☆473Apr 17, 2025Updated last year
- An index of Windows binaries, including download links for executables such as exe, dll and sys files☆863Updated this week
- Hooking Windows' exception dispatcher to protect process's PML4☆268Jan 24, 2025Updated last year
- Windows Explorer application written in assembly☆15Jun 15, 2023Updated 3 years ago
- proof-of-concept Windows Driver for injecting DLL into user-mode processes using APC☆1,295May 1, 2024Updated 2 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Windows rootkit for Intel x64 with 25+ features, demonstrating rootkit techniques compatible with all Windows 10 and Windows 11 versions.☆2,463Jun 26, 2026Updated last month
- RunPE implementation with multiple evasive techniques (2)☆286Sep 25, 2025Updated 10 months ago
- A x86_64 software emulator☆163Aug 25, 2025Updated 11 months ago
- Collection of various malicious functionality to aid in malware development☆1,931Feb 28, 2024Updated 2 years ago
- Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.☆244Sep 26, 2023Updated 2 years ago
- Usermode exploit to bypass any AC using a 0day shatter attack.☆388Nov 26, 2025Updated 8 months ago
- 🪅 Windows & Linux userspace emulator☆3,513Updated this week