repnz / windbg-cheat-sheet
My personal cheat sheet for using WinDbg for kernel debugging
☆387Updated last month
Related projects ⓘ
Alternatives and complementary repositories for windbg-cheat-sheet
- A bunch of JavaScript extensions for WinDbg.☆320Updated 3 years ago
- Examples of leaking Kernel Mode information from User Mode on Windows☆581Updated 7 years ago
- My notes while studying Windows internals☆399Updated this week
- DEFCON 27 workshop - Modern Debugging with WinDbg Preview☆708Updated 2 weeks ago
- awesome windbg extensions☆313Updated 5 years ago
- XNTSV program for detailed viewing of system structures for Windows.☆446Updated this week
- Useful scripts for WinDbg using the debugger data model☆389Updated 7 months ago
- Windows NT x64 syscall fuzzer☆589Updated last year
- Time Travel Debugging IDA plugin☆553Updated 4 months ago
- Internals information about Hyper-V☆661Updated 2 months ago
- Toy scripts for playing with WinDbg JS API☆220Updated 4 months ago
- Research on Windows Kernel Executive Callback Objects☆278Updated 4 years ago
- Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks☆326Updated 3 weeks ago
- A library to develop kernel level Windows payloads for post HVCI era☆366Updated 3 years ago
- Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.☆548Updated last month
- Samples for the book Windows Kernel Programming, 2nd edition☆293Updated 3 months ago
- Defeating Patchguard universally for Windows 8, Windows 8.1 and all versions of Windows 10 regardless of HVCI.☆845Updated 4 years ago
- RpcView is a free tool to explore and decompile Microsoft RPC interfaces☆928Updated last year
- HashDB API hash lookup plugin for IDA Pro☆296Updated last month
- The Windows Kernel Programming book samples☆611Updated last year
- This is a collection of interesting codes about Windows Process creation.☆230Updated 10 months ago
- VirtualKD-Redux - A revival and modernization of VirtualKD☆820Updated 4 months ago
- A DTrace on Windows Reimplementation☆328Updated 3 weeks ago
- Quickly debug shellcode extracted during malware analysis☆565Updated last year
- Canadian Furious Beaver is a ProcMon-style tool designed only for capturing IRPs sent to any Windows driver.☆310Updated 7 months ago
- C++ STL in the Windows Kernel with C++ Exception Support☆392Updated last year
- Official x64dbg plugin for IDA Pro.☆461Updated last month
- Basic Windows Kernel Programming☆124Updated 4 years ago
- Dump of win32k POCs for bugs I've found☆370Updated 2 years ago
- ShowStopper is a tool for helping malware researchers explore and test anti-debug techniques or verify debugger plugins or other solution…☆196Updated 2 years ago