silverf0x / RpcView
RpcView is a free tool to explore and decompile Microsoft RPC interfaces
☆947Updated last year
Alternatives and similar repositories for RpcView:
Users that are interested in RpcView are comparing it to the libraries listed below
- A library to load, manipulate, dump PE files. See also: https://github.com/hasherezade/libpeconv_tpl☆1,133Updated last month
- Examples of leaking Kernel Mode information from User Mode on Windows☆585Updated 7 years ago
- Obfuscate specific windows apis with different apis☆987Updated 3 years ago
- proof-of-concept Windows Driver for injecting DLL into user-mode processes using APC☆1,188Updated 8 months ago
- Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode☆2,183Updated last year
- Pinjectra is a C/C++ OOP-like library that implements Process Injection techniques (with focus on Windows 10 64-bit)☆800Updated 2 years ago
- Protected Processes Light Killer☆905Updated last year
- ☆802Updated 5 years ago
- Windows NT Syscall tables☆1,228Updated 2 months ago
- Quickly debug shellcode extracted during malware analysis☆575Updated last year
- Portable Executable parsing library (from PE-bear)☆650Updated 4 months ago
- WinDBG Anti-RootKit Extension☆623Updated 4 years ago
- A Pin Tool for tracing API calls etc☆1,363Updated 2 weeks ago
- Native API header files for the System Informer project.☆1,090Updated 4 months ago
- XNTSV program for detailed viewing of system structures for Windows.☆448Updated this week
- Extract Windows Defender database from vdm files and unpack it☆433Updated 4 years ago
- Windows Object Explorer 64-bit☆1,678Updated 3 weeks ago
- ☆765Updated 2 years ago
- DEFCON 27 workshop - Modern Debugging with WinDbg Preview☆712Updated 2 months ago
- VirtualKD-Redux - A revival and modernization of VirtualKD☆848Updated 6 months ago
- Shellcode Compiler☆1,082Updated 4 months ago
- Driver loader for bypassing Windows x64 Driver Signature Enforcement☆1,078Updated 5 years ago
- Windows NT x64 syscall fuzzer☆596Updated last year
- My implementation of enSilo's Process Doppelganging (PE injection technique)☆585Updated 2 years ago
- An extensible framework for easily writing compiler optimized position independent x86 / x64 shellcode for windows platforms.☆501Updated 5 years ago
- Process Herpaderping proof of concept, tool, and technical deep dive. Process Herpaderping bypasses security products by obscuring the in…☆1,113Updated last year
- Syscall Monitor is a system monitor program (like Sysinternal's Process Monitor) using Intel VT-X/EPT for Windows7+☆726Updated 7 years ago
- Process Monitor X v2☆594Updated 11 months ago
- My personal cheat sheet for using WinDbg for kernel debugging☆395Updated 3 months ago