n4r1b / ferrisetw
Basically a KrabsETW rip-off written in Rust
☆69Updated 9 months ago
Alternatives and similar repositories for ferrisetw:
Users that are interested in ferrisetw are comparing it to the libraries listed below
- The PE Executable Library, but for Rust!☆78Updated last year
- Rust bindings to the System Informer's (formerly known as Process Hacker) "phnt" native Windows headers☆45Updated 3 weeks ago
- Rust FFI bindings for Native API☆107Updated last year
- Structured Exception Handling (SEH) for Rust☆60Updated 7 months ago
- Local OXID Resolver (LCLOR) : Research and Tooling☆35Updated 3 years ago
- dump all available information from PDBs☆129Updated last year
- Windows Native Undocumented API for Rust Language 🔥☆38Updated 9 months ago
- A parser for the MFT (Master File Table) format☆138Updated last year
- A Rust library for parsing and writing MS Shell Links (shortcuts, *.lnk)☆29Updated last week
- intel x86(-64) code analysis library that reconstructs control flow☆103Updated 2 months ago
- Rust bindings for VirusTotal/Yara☆76Updated 2 months ago
- A binary analysis framework written in Rust.☆20Updated last year
- ☆87Updated 11 months ago
- Zydis Rust Bindings☆90Updated 10 months ago
- SCEMU The crates.io lib, x86 cpu and systems emulator focused mainly for anti-malware☆43Updated 4 months ago
- Alternative YARA scanning engine☆70Updated 2 years ago
- A PoC Windows Minifilter Driver in pure Rust (Don't use it in production)☆51Updated last year
- Examples on how to write Windows kernel drivers in Rust☆222Updated last year
- Rust bindings to Windows API☆19Updated 6 years ago
- A PoC packer written in Rust!☆68Updated 3 years ago
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆71Updated last year
- Tooling to generate metadata for Win32 APIs in the Windows Driver Kit (WDK).☆100Updated 3 months ago
- The source code for my blog post 'Writing a kernel driver with Rust.'☆135Updated 2 years ago
- CallMon is an experimental system call monitoring tool that works on Windows 10 versions 2004+ using PsAltSystemCallHandlers☆142Updated 4 years ago
- Simple windows API logger☆101Updated 5 years ago
- Windows Hypervisor Platform Rust crate☆58Updated 4 years ago
- Faster version of `symchk /om` for generating PDB manifests of offline machines☆56Updated last month
- A document tagging library☆30Updated last month
- Windows API Hooking in Rust☆48Updated 2 years ago
- Modular and extensible library for Virtual Machine Introspection☆95Updated last month