microsoft / ntosebpfext
eBPF-For-Windows extension to provide access to Windows kernel functionality
☆22Updated last week
Alternatives and similar repositories for ntosebpfext:
Users that are interested in ntosebpfext are comparing it to the libraries listed below
- INF Studio for easier working with driver installation files☆36Updated last year
- WinDbg installer/updater☆39Updated last year
- Rust version of the objdir tool☆12Updated 11 months ago
- ☆80Updated last month
- Windows Hypervisor Platform Rust crate☆57Updated 4 years ago
- Show Window Stations, Desktops and top level windows☆15Updated last year
- This repository contains the demo material built on top of ebpf-for-windows platform.☆38Updated 5 months ago
- View handles and object for each object type☆61Updated 5 years ago
- Different tools for Microsoft Hyper-V researching☆47Updated 8 months ago
- Portable Executable parsing library, used by PEExplorer. Also available as a nuget package☆36Updated 7 years ago
- Networking related test tools for Windows. Relevant for anyone who is interested in Windows networking.☆26Updated last week
- Download pdbs from symbol servers and cache locally, parse symbol paths from env vars☆22Updated 2 months ago
- A thin introspection hypervisor framework that allows for low level resource manipulation.☆13Updated last year
- Hyper-V VMBusPipe Reversing☆19Updated 3 years ago
- Driver demonstrating how to register a DPC to asynchronously wait on an object☆48Updated 4 years ago
- The lightweight library for Hyper-V guest interfaces.☆23Updated 3 months ago
- Experiments involving the Windows Hypervisor Platform☆23Updated 4 years ago
- Utility functions for building Windows kernel drivers in Rust☆21Updated 3 years ago
- A console debugger using DbgX and Terminal.Gui☆29Updated 2 years ago
- Crates for Microsoft Hypervisor ioctls and bindings☆32Updated this week
- VM firmware pkg for Project Mu☆37Updated 3 weeks ago
- Runtime smm module loader☆32Updated 2 years ago
- The common parts of the Sysinternals Sysmon tool shared between the Windows and Linux versions.☆61Updated last month
- A skeleton WinRT component that can serve as a substitute for the Region Policy Evaluator in Windows.☆12Updated last year
- extract and parse WEVT_TEMPLATEs from PE files☆18Updated last year
- ☆40Updated 3 years ago
- Rust unsafe bindings for Vid API (Hyper-V)☆19Updated 5 years ago
- IDA Database Parser for Rust☆25Updated 5 months ago
- Integration of Syntia program synthesis tool into the radare2 reverse engineering framework.☆20Updated 4 years ago
- Event Tracing for Windows tools and samples☆22Updated last month