microsoft / Detours
Detours is a software package for monitoring and instrumenting API calls on Windows. It is distributed in source code form.
☆5,141Updated last month
Related projects: ⓘ
- The Minimalistic x86/x64 API Hooking Library for Windows☆4,286Updated last month
- EasyHook - The reinvention of Windows API Hooking☆3,005Updated 7 months ago
- Library to load a DLL from memory.☆2,782Updated 8 months ago
- Windows memory hacking library☆4,780Updated 7 months ago
- Windows Implementation Library☆2,568Updated 3 weeks ago
- This repo contains samples that demonstrate the API used in Windows classic desktop applications.☆5,003Updated last week
- Advanced usermode anti-anti-debugger. Forked from https://bitbucket.org/NtQuery/scyllahide☆3,397Updated 3 months ago
- Blazing fast and correct x86/x64 disassembler, assembler, decoder, encoder for Rust, .NET, Java, Python, Lua☆2,882Updated this week
- This repo contains driver samples prepared for use with Microsoft Visual Studio and the Windows Driver Kit (WDK). It contains both Univer…☆6,877Updated last week
- C++20, x86/x64 Hooking Libary v2.0☆1,585Updated last month
- WinDivert: Windows Packet Divert☆2,449Updated last year
- Program for determining types of files for Windows, Linux and MacOS.☆7,292Updated this week
- Hook system calls, context switches, page faults and more.☆2,373Updated last year
- Windows tool for dumping malware PE files from memory back to disk for analysis.☆1,624Updated 2 weeks ago
- A free, powerful, multi-purpose tool that helps you monitor system resources, debug software and detect malware. Brought to you by Winsid…☆10,816Updated this week
- A rewrite of the old legacy software "depends.exe" in C# for Windows devs to troubleshoot dll load dependencies issues.☆8,896Updated 4 months ago
- DIE engine☆2,304Updated this week
- An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.☆44,322Updated last week
- Windows System Call Tables (NT/2000/XP/2003/Vista/7/8/10/11)☆2,111Updated last month
- A list of IDA Plugins☆3,499Updated 3 months ago
- Information from Microsoft about the PDB format. We'll try to keep this up to date. Just trying to help the CLANG/LLVM community get ont…☆1,840Updated last year
- Windows Object Explorer 64-bit☆1,619Updated 2 months ago
- .NET deobfuscator and unpacker.☆6,900Updated 4 years ago
- Capstone disassembly/disassembler framework for ARM, ARM64 (ARMv8), Alpha, BPF, Ethereum VM, HPPA, LoongArch, M68K, M680X, Mips, MOS65XX,…☆7,349Updated this week
- Hiding kernel-driver for x86/x64.☆2,077Updated 8 months ago
- A Windows API hooking library☆723Updated 3 years ago
- A free but powerful Windows kernel research tool.☆2,380Updated 3 months ago
- Public mirror for win32-pr☆1,080Updated this week
- Fast and lightweight x86/x86-64 disassembler and code generation library☆3,375Updated last month
- More than a ReClass port to the .NET platform.☆1,804Updated 4 months ago