michael-fadely / usercall-hookLinks
Generate inline assembly functions to wrap your replacement functions. Supports __usercall and __userpurge
☆16Updated 2 years ago
Alternatives and similar repositories for usercall-hook
Users that are interested in usercall-hook are comparing it to the libraries listed below
Sorting:
- A dark x64dbg color theme based on IDA Consonance☆19Updated 7 years ago
- This is a simple driver with x64 inline assembly☆57Updated 5 years ago
- Takes a Windbg dumped structure (using the 'dt' command) and formats it into a C structure☆37Updated last year
- A lightweight x86/x64 VM☆18Updated 5 years ago
- UNIPE - A small framwork to execute PE files with UniCorn☆47Updated 8 years ago
- An API Monitor based on Instrumentation☆44Updated 8 years ago
- Windows 10 kernel and ntdll internal types, directly compatible with ida.☆53Updated 7 years ago
- Analyze PatchGuard☆56Updated 7 years ago
- VMProtect analysis script☆56Updated 5 years ago
- a method for undetectable breakpoints in 32-bit Windows programs☆13Updated 11 years ago
- IDA script for vmprotect Windows Api address decoder☆54Updated 4 years ago
- POC of sysenter x64 LSTAR MSR hook☆41Updated 11 years ago
- Windbg extension that allows you analyze Control Flow Guard map☆38Updated 4 years ago
- Fetch PDB symbols directly from Microsoft's symbol servers☆48Updated 3 months ago
- Windows 10 UAC bypass PoC using LaunchInfSection☆35Updated 7 years ago
- Tools made for my Hyper-V blog series @ https://foxhex0ne.blogspot.com/☆57Updated 5 years ago
- unicorn emulator for x64dbg☆34Updated 7 years ago
- it can extract functions from .dll, .exe, .sys and it be work! :)☆39Updated 6 years ago
- ☆21Updated 8 years ago
- Call 32bit NtDLL API directly from WoW64 Layer☆61Updated 5 years ago
- Lightweight x86 and x64 instructions disassembler☆35Updated 7 years ago
- virtualization obfuscator inspired by juhajong/vm-obfuscator☆60Updated 6 years ago
- Windows sandbox PoC☆32Updated 5 years ago
- IDA plugin to explore and browse tags☆55Updated 6 years ago
- DirectNtApi - simple method to make ntapi function call without importing or walking export table. Work under Windows 7, 8 and 10☆53Updated last year
- ☆37Updated 10 years ago
- XDV is disassembler or debugger that works based on the extension plugin.☆55Updated 6 years ago
- A debugger backend for IDA Pro built on top of of Intel’s PIN framework☆35Updated last year
- ☆49Updated 5 years ago
- Exploiting HEVD's WriteWhatWhereIoctlDispatch for LPE on Windows 10 TH2 through RS3 using GDI objects.☆24Updated 8 years ago