My personal cheat sheet for using WinDbg for kernel debugging
☆473Apr 17, 2025Updated last year
Alternatives and similar repositories for windbg-cheat-sheet
Users that are interested in windbg-cheat-sheet are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Useful scripts for WinDbg using the debugger data model☆436Mar 27, 2024Updated 2 years ago
- DEFCON 27 workshop - Modern Debugging with WinDbg Preview☆748Nov 1, 2024Updated last year
- APC Internals Research Code☆174Jun 28, 2020Updated 6 years ago
- A bunch of JavaScript extensions for WinDbg.☆368Nov 28, 2024Updated last year
- Internals information about Hyper-V☆746Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Sample extensions, scripts, and API uses for WinDbg.☆821Jun 30, 2026Updated last month
- Windows Object Explorer 64-bit☆1,965Updated this week
- ☆22Jul 10, 2020Updated 6 years ago
- Reverse engineered source code of the autochk rootkit☆213Nov 1, 2019Updated 6 years ago
- Techniques based on named pipes for pool overflow exploitation targeting the most recent (and oldest) Windows versions demonstrated on CV…☆264Sep 1, 2022Updated 3 years ago
- A library to develop kernel level Windows payloads for post HVCI era☆525May 18, 2021Updated 5 years ago
- Research on Windows Kernel Executive Callback Objects☆315Feb 22, 2020Updated 6 years ago
- Examples of leaking Kernel Mode information from User Mode on Windows☆646Jul 7, 2017Updated 9 years ago
- awesome windbg extensions☆366Mar 27, 2019Updated 7 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Windows NT x64 syscall fuzzer☆641Apr 2, 2026Updated 4 months ago
- This is a repo for small, useful scripts and extensions☆262Jun 1, 2023Updated 3 years ago
- Native API header files for the System Informer project.☆1,460Mar 26, 2026Updated 4 months ago
- Toy scripts for playing with WinDbg JS API☆244Jul 8, 2024Updated 2 years ago
- State-of-the-art native debugging tools☆3,987Updated this week
- proof-of-concept Windows Driver for injecting DLL into user-mode processes using APC☆1,295May 1, 2024Updated 2 years ago
- My notes while studying Windows internals☆491Jul 6, 2026Updated last month
- Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.☆677Jan 28, 2025Updated last year
- A driver that hooks C: volume using symbolic link callback to track all FS access to the volume☆108Apr 24, 2020Updated 6 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- An application to view and filter pool allocations from a dmp file on Windows 10 RS5+.☆153Mar 2, 2023Updated 3 years ago
- A Windows kernel dump C++ parser library with Python 3 bindings.☆212Oct 5, 2025Updated 10 months ago
- Windows 10 System Programming book samples☆457Oct 19, 2025Updated 9 months ago
- An index of Windows binaries, including download links for executables such as exe, dll and sys files☆860Updated this week
- UEFI bootkit for driver manual mapping☆600Jan 1, 2024Updated 2 years ago
- A Pin Tool for tracing API calls etc☆1,685Jun 2, 2026Updated 2 months ago
- PoC exploiting Aligned Chunk Confusion on Windows kernel Segment Heap☆211Jul 2, 2020Updated 6 years ago
- Dump of win32k POCs for bugs I've found☆379Mar 6, 2022Updated 4 years ago
- hvpp is a lightweight Intel x64/VT-x hypervisor written in C++ focused primarily on virtualization of already running operating system☆1,340Mar 15, 2021Updated 5 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- ☆19Jan 12, 2020Updated 6 years ago
- Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks☆435Jul 10, 2026Updated last month
- Process Monitor X v2☆663Jul 4, 2026Updated last month
- Static Binary Instrumentation tool for Windows x64 executables☆206Sep 29, 2025Updated 10 months ago
- Windows kernel hacking framework, driver template, hypervisor and API written on C++☆1,819Nov 12, 2023Updated 2 years ago
- Intel / AMD CPU Internals☆1,207Jun 24, 2026Updated last month
- HackSys Extreme Vulnerable Driver (HEVD) - Windows & Linux☆3,065Feb 24, 2025Updated last year