microsoft / ntosebpfextLinks
eBPF-For-Windows extension to provide access to Windows kernel functionality
☆26Updated last week
Alternatives and similar repositories for ntosebpfext
Users that are interested in ntosebpfext are comparing it to the libraries listed below
Sorting:
- INF Studio for easier working with driver installation files☆38Updated last year
- Download pdbs from symbol servers and cache locally, parse symbol paths from env vars☆22Updated 2 months ago
- Tools and documents for working with Microsoft PDB files, in Rust☆24Updated 3 weeks ago
- Rust version of the objdir tool☆13Updated last year
- WinDbg installer/updater☆41Updated last year
- ☆83Updated 2 weeks ago
- A thin introspection hypervisor framework that allows for low level resource manipulation.☆13Updated last year
- Runtime smm module loader☆33Updated 2 years ago
- View handles and object for each object type☆64Updated 5 years ago
- Windows Hypervisor Platform Rust crate☆59Updated 4 years ago
- Different tools for Microsoft Hyper-V researching☆57Updated 11 months ago
- Rust unsafe bindings for Vid API (Hyper-V)☆20Updated 3 months ago
- Show Window Stations, Desktops and top level windows☆15Updated last year
- This repository contains the demo material built on top of ebpf-for-windows platform.☆43Updated 8 months ago
- Helper scripts for windows debugging with symbols for Bochs and IDA Pro (PDB files). Very handy for user mode <--> kernel mode☆19Updated last year
- Windows Minidump loader for Ghidra☆29Updated 2 years ago
- Windows system repair tool☆20Updated 4 years ago
- Driver demonstrating how to register a DPC to asynchronously wait on an object☆49Updated 4 years ago
- ETrace is a syscall tracing utility powered by eBPF☆25Updated 2 years ago
- Event Tracing for Windows tools and samples☆25Updated 4 months ago
- Collection of Windows Driver Utils☆11Updated last year
- Native Rust bindings for @horsicq's Detect-It-Easy☆15Updated 4 months ago
- Plugin for x64dbg to disable parallel loading of dependencies☆19Updated 2 years ago
- Portable Executable parsing library, used by PEExplorer. Also available as a nuget package☆36Updated 7 years ago
- ☆40Updated 3 years ago
- Experiments involving the Windows Hypervisor Platform☆23Updated 4 years ago
- .NET wrapper for dbghelp.dll☆21Updated 5 years ago
- IDA Database Parser for Rust☆25Updated 8 months ago
- Networking related test tools for Windows. Relevant for anyone who is interested in Windows networking.☆29Updated 2 weeks ago
- Hyper-V VMBusPipe Reversing☆19Updated 4 years ago