rogerorr / NtTrace
An strace-like program for the Windows 'native' API
☆196Updated 2 months ago
Related projects ⓘ
Alternatives and complementary repositories for NtTrace
- C++ Exceptions in Windows Drivers☆198Updated 3 years ago
- Detours with just single dependency - NTDLL☆612Updated 2 years ago
- The history of Windows Internals via symbols.☆177Updated 3 years ago
- A Windows PE format file loader☆137Updated 6 years ago
- A header-only C++ library for accessing files in COFF binary format. (Including Windows PE/PE+ formats)☆188Updated this week
- PDB Downloader - An easier way to download Microsoft's public symbols for Libraries and Executables.☆291Updated 8 years ago
- A modern c++ implementation of windows heavens gate☆194Updated 4 years ago
- C++ STL in the Windows Kernel with C++ Exception Support☆392Updated last year
- 0CCh Windbg extension: include some useful commands☆109Updated last year
- Cross-platform tool that allows browsing and extracting C and C++ type declarations from PDB files.☆294Updated 2 months ago
- CMake module for building drivers with Windows Development Kit (WDK)☆255Updated 2 months ago
- A bunch of parsers for PE and PDB formats in C++☆226Updated 6 months ago
- open source process monitor☆254Updated 11 months ago
- A Windows kernel dump C++ parser library with Python 3 bindings.☆193Updated 4 months ago
- COFF and Portable Executable format described using standard C++ with no dependencies.☆255Updated 7 months ago
- A bunch of JavaScript extensions for WinDbg.☆320Updated 3 years ago
- ☆151Updated last month
- The ultimate hooking library☆253Updated 3 years ago
- PICO processes toolbox, playground for PICO processes research☆68Updated 7 years ago
- Print compiler information stored in Rich Header of PE executables.☆125Updated this week
- A wrapper library around native windows sytem APIs☆421Updated 3 years ago
- ☆120Updated last month
- My personal cheat sheet for using WinDbg for kernel debugging☆387Updated last month
- A Windows API hooking library☆190Updated 2 years ago
- An example of a client and server using Windows' ALPC functions to send and receive data.☆89Updated 4 years ago
- Windows NT x64 syscall fuzzer☆589Updated last year
- API monitoring via return-hijacking thunks; works without information about target function prototypes.☆113Updated 4 years ago
- ntdll.h - compatible with MSVC 6.0, Intel C++ Compiler and MinGW. Serves as a complete replacement for Windows.h☆130Updated 5 years ago
- An IDA Plugin that help analyzing module that use COM☆198Updated last year
- Persistent IAT hooking application - based on bearparser☆247Updated 2 years ago