Native API online documentation, based on the System Informer (formerly Process Hacker) phnt headers
☆478Oct 9, 2026Updated this week
Alternatives and similar repositories for ntdoc
Users that are interested in ntdoc are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Native API header files for the System Informer project.☆1,485Mar 26, 2026Updated 6 months ago
- Windows Object Explorer 64-bit☆1,983Updated this week
- Undocumented MSVC☆50Nov 10, 2025Updated 10 months ago
- Reverse engineering winapi function loadlibrary.☆249Apr 17, 2023Updated 3 years ago
- Windows NT Syscall tables☆1,480Sep 4, 2026Updated last month
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Implementing an early exception handler for hooking and threadless process injection without relying on VEH or SEH☆139Aug 31, 2025Updated last year
- PDB file inspection tool☆138Nov 21, 2025Updated 10 months ago
- Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.☆679Jan 28, 2025Updated last year
- Anti-Rootkit/Anti-Cheat Driver to uncover unbacked or hidden kernel code.☆353Mar 12, 2026Updated 6 months ago
- Collection of undocumented Windows API declarations.☆372Sep 19, 2026Updated 3 weeks ago
- Process Injection using Thread Name☆310Apr 18, 2025Updated last year
- An example of how to use Microsoft Windows Warbird technology☆97Apr 23, 2023Updated 3 years ago
- A library to load, manipulate, dump PE files. See also: https://github.com/hasherezade/libpeconv_tpl☆1,393Apr 18, 2026Updated 5 months ago
- Injecting code by recompiling shellcode into a ROP chain.☆148Apr 21, 2026Updated 5 months ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Metamorphic cross-compilation of C++ & C-code to PIC, BOF & EXE.☆650Feb 2, 2026Updated 8 months ago
- Windows System Call Tables (NT/2000/XP/2003/Vista/7/8/10/11)☆2,649Dec 30, 2025Updated 9 months ago
- PE Viewer☆236Updated this week
- Single header version of System Informer's phnt library.☆252Mar 27, 2026Updated 6 months ago
- Ryūjin Protector - Is a Intel Arch - BIN2BIN - PE Obfuscation/Protection/DRM tool☆349Nov 20, 2025Updated 10 months ago
- Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).☆170Aug 23, 2024Updated 2 years ago
- "Service-less" driver loading☆191Nov 28, 2024Updated last year
- Kernel Driver Utility☆2,762Sep 29, 2026Updated last week
- State-of-the-art virtual machine detection☆1,438Updated this week
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Process Monitor X v2☆662Jul 4, 2026Updated 3 months ago
- Research on obfuscated licensing APIs / CLIP service in the Windows kernel☆144Aug 23, 2022Updated 4 years ago
- A tool that is used to hunt vulnerabilities in x64 WDM drivers☆473Jun 18, 2026Updated 3 months ago
- A x86_64 software emulator☆168Aug 25, 2025Updated last year
- Windows Anti-Rootkit Tool☆576Jul 25, 2026Updated 2 months ago
- My personal cheat sheet for using WinDbg for kernel debugging☆475Apr 17, 2025Updated last year
- An index of Windows binaries, including download links for executables such as exe, dll and sys files☆890Updated this week
- Hooking Windows' exception dispatcher to protect process's PML4☆273Jan 24, 2025Updated last year
- Windows Explorer application written in assembly☆15Jun 15, 2023Updated 3 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- proof-of-concept Windows Driver for injecting DLL into user-mode processes using APC☆1,297May 1, 2024Updated 2 years ago
- x64 PE bin2bin obfuscator which doesn't add a section to the binary☆346Aug 18, 2026Updated last month
- 🪅 Windows & Linux userspace emulator☆3,659Updated this week
- LLVM fork with explicit compatibility with MSVC 2022 features.☆438Oct 3, 2026Updated last week
- WinVisor - A hypervisor-based emulator for Windows x64 user-mode executables using Windows Hypervisor Platform API☆670Jan 23, 2025Updated last year
- Windows rootkit for Intel x64 with 25+ features, demonstrating rootkit techniques compatible with all Windows 10 and Windows 11 versions.☆2,520Sep 26, 2026Updated last week
- RunPE implementation with multiple evasive techniques (2)☆286Sep 25, 2025Updated last year