A branch-monitor-based solution for process monitoring.
☆138Feb 9, 2020Updated 6 years ago
Alternatives and similar repositories for BranchMonitoringProject
Users that are interested in BranchMonitoringProject are comparing it to the libraries listed below
Sorting:
- This driver implements the Intel Processor Trace functionality in Intel Skylake architecture for Microsoft Windows☆466Apr 17, 2018Updated 7 years ago
- reverse engineering extension plugin for windbg☆122Sep 30, 2019Updated 6 years ago
- libemu shim layer and win32 environment for Unicorn Engine☆73Apr 14, 2017Updated 8 years ago
- ☆30May 23, 2017Updated 8 years ago
- Demo List cm/ps/ob/minifilter callback And Patch/Bypass it☆29Dec 5, 2017Updated 8 years ago
- modify binary Portable Executable to hook its export functions☆67Jan 13, 2019Updated 7 years ago
- ☆36Oct 29, 2020Updated 5 years ago
- Shareds for kernel developement☆29Dec 23, 2013Updated 12 years ago
- Detects if a Kernel mode debugger is active by reading the value of KUSER_SHARED_DATA.KdDebuggerEnabled. It is a high level and portable …☆23Sep 18, 2017Updated 8 years ago
- PoC of BOOST-ed _EPROCESS.VadRoot iterating☆27May 21, 2014Updated 11 years ago
- Hypervisor-based debugger☆191Dec 2, 2020Updated 5 years ago
- An aggregate of tools used in the core of vmp_dbg plus other parsing utils to parse vmp bc.☆16Oct 18, 2016Updated 9 years ago
- ATrace is a tool for tracing execution of binaries on Windows.☆240Nov 19, 2025Updated 4 months ago
- more at http://www.zer0mem.sk/?p=271☆12Jun 11, 2013Updated 12 years ago
- kernel pool windbg extension☆83Jul 23, 2015Updated 10 years ago
- The Windows Library for Intel Process Trace (WinIPT) is a project that leverages the new Intel Processor Trace functionality exposed by W…☆406Apr 27, 2023Updated 2 years ago
- Implementation of a thin hypervisor☆43May 20, 2016Updated 9 years ago
- Minimalistic VT-x hypervisor with hooks☆935Oct 18, 2019Updated 6 years ago
- Xenpwn is a toolkit for memory access tracing using hardware-assisted virtualization☆145Jul 22, 2016Updated 9 years ago
- ☆14May 9, 2017Updated 8 years ago
- Augmenting Static Analysis Using Pintool: Ablation☆39Aug 4, 2016Updated 9 years ago
- Figuring out the cause of a handle downgrade☆24Dec 13, 2022Updated 3 years ago
- kHypervisor is a lightweight bluepill-like nested VMM for Windows, it provides and emulating a basic function of Intel VT-x☆446Nov 29, 2021Updated 4 years ago
- IDAScript to create Symbol file which can be loaded in WinDbg via AddSyntheticSymbol☆41Jul 25, 2014Updated 11 years ago
- win32/x64 obfuscate framework☆33Apr 16, 2019Updated 6 years ago
- deprecated☆27Mar 20, 2019Updated 7 years ago
- Vulnerability Data Tracer - Published at Phrack 67 Article☆15Dec 12, 2014Updated 11 years ago
- ☆11Mar 11, 2015Updated 11 years ago
- ☆22Mar 23, 2016Updated 9 years ago
- IDA Plugin which decodes Windows Device I/O control code into DeviceType, FunctionCode, AccessType and MethodType.☆120Dec 1, 2023Updated 2 years ago
- Path based Dynamic Analysis☆118Mar 25, 2017Updated 8 years ago
- ☆14Jan 10, 2017Updated 9 years ago
- This is a VmProtect integrated debugger, that will essentially allow you to disasm and debug vmp partially virtualized functions at the v…☆47Oct 18, 2016Updated 9 years ago
- Loading unsigned code into kernel in Windows 10 (64) with help of VMware Workstation Pro/Player design flaw☆141Apr 4, 2017Updated 8 years ago
- Nosy Newt is a simple concolic execution tool for exploring the input space of a binary executable program based in Triton☆62Aug 5, 2017Updated 8 years ago
- Dynamic trace toolkit for Windows☆52Jun 25, 2025Updated 8 months ago
- Demos presented on Hackerfest 2015☆14Nov 9, 2015Updated 10 years ago
- Universal Trace Debugger Engine. Currently, only support windbg on Windows, but the long term goal is to also support GDB or LLDB☆13Dec 30, 2013Updated 12 years ago
- A tool to help when dealing with Windows IOCTL codes or reversing Windows drivers.☆437Aug 22, 2018Updated 7 years ago