m417z / ntdocLinks
Native API online documentation, based on the System Informer (formerly Process Hacker) phnt headers
☆261Updated 2 weeks ago
Alternatives and similar repositories for ntdoc
Users that are interested in ntdoc are comparing it to the libraries listed below
Sorting:
- Collection of undocumented Windows API declarations.☆314Updated this week
- Single header version of System Informer's phnt library.☆221Updated last week
- Debugger Anti-Detection Benchmark☆333Updated last year
- HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate oper…☆364Updated 2 years ago
- Native code virtualizer for x64 binaries☆483Updated 5 months ago
- Guided Hacking's official tool to practice bypassing anti-debug techniques.☆277Updated 3 weeks ago
- An x86-64 Code Virtualizer☆262Updated 8 months ago
- protector & obfuscator & code virtualizer☆530Updated this week
- Demo proof of concept for shadow regions, and implementation of HyperDeceit.☆279Updated 2 years ago
- System call hook for Windows 10 20H1☆493Updated 3 years ago
- x64 Windows kernel code execution via user-mode, arbitrary syscall, vulnerable IOCTLs demonstration☆322Updated 2 years ago
- Collection of hypervisor detections☆236Updated 8 months ago
- LLVM fork with explicit compatibility with MSVC 2022 features.☆299Updated 2 months ago
- COFF and Portable Executable format described using standard C++ with no dependencies.☆284Updated last month
- Bootkit for Windows Sandbox to disable DSE/PatchGuard.☆280Updated 7 months ago
- DLL that hooks the NtQuerySystemInformation API and hides a process name☆288Updated 2 years ago
- A DTrace on Windows Reimplementation☆348Updated 4 months ago
- Samples for the book Windows Kernel Programming, 2nd edition☆338Updated 5 months ago
- Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.☆599Updated 4 months ago
- A x64 Windows Rootkit using SSDT or Hypervisor hook☆537Updated 5 months ago
- Kernel-mode Paravirtualization in Ring 2, LLVM based linker, and some other things!☆347Updated last month
- Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks☆361Updated 7 months ago
- Deobfuscation via optimization with usage of LLVM IR and parsing assembly.☆594Updated 2 weeks ago
- PE Viewer☆181Updated 4 months ago
- My notes while studying Windows internals☆427Updated 5 months ago
- PE bin2bin obfuscator☆704Updated last month
- 🗜️ A packer for Windows x86 executable files written in C and Intel x86 Assembly. The new file after packing can obstruct reverse engine…☆343Updated 7 months ago
- A small x64 library to load dll's into memory.☆441Updated last year
- A modern c++ implementation of windows heavens gate☆224Updated 4 years ago
- Static deobfuscator for Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.☆282Updated 10 months ago