skelsec / minidump
Python library to parse and read Microsoft minidump file format
☆286Updated 4 months ago
Alternatives and similar repositories for minidump
Users that are interested in minidump are comparing it to the libraries listed below
Sorting:
- Extract Windows Defender database from vdm files and unpack it☆440Updated 5 years ago
- Exploring RPC interfaces on Windows☆321Updated last year
- RpcView is a free tool to explore and decompile Microsoft RPC interfaces☆967Updated last year
- Quickly debug shellcode extracted during malware analysis☆605Updated last year
- Expriments☆455Updated 7 months ago
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆297Updated last year
- My implementation of enSilo's Process Doppelganging (PE injection technique)☆609Updated 2 years ago
- Universal Unhooking☆321Updated 6 years ago
- Dump of win32k POCs for bugs I've found☆373Updated 3 years ago
- Tools for instrumenting Windows Defender's mpengine.dll☆295Updated 6 years ago
- Sysmon-Like research tool for ETW☆352Updated 2 years ago
- Adaptive DLL hijacking / dynamic export forwarding☆753Updated 4 years ago
- A more stealthy variant of "DLL hollowing"☆348Updated last year
- This respository is a collection of C# class libraries which implement RPC clients for various versions of the Windows Operating System f…☆277Updated 5 years ago
- A way to delete a locked file, or current running executable, on disk.☆524Updated 9 months ago
- View ETW Provider manifest☆482Updated 6 months ago
- Enumerating and removing kernel callbacks using signed vulnerable drivers☆560Updated 2 years ago
- Useful scripts for WinDbg using the debugger data model☆411Updated last year
- Idapython script to carve binary for internal RPC structures☆233Updated last year
- Windows Kernel Drivers fuzzer☆342Updated 8 years ago
- Pinjectra is a C/C++ OOP-like library that implements Process Injection techniques (with focus on Windows 10 64-bit)☆811Updated 3 years ago
- Enumerate and disable common sources of telemetry used by AV/EDR.☆794Updated 4 years ago
- FLARE Kernel Shellcode Loader☆177Updated 6 years ago
- A small, null-free Windows shellcode that executes calc.exe (x86/x64, all OS/SPs)☆415Updated 11 months ago
- A DTrace on Windows Reimplementation☆344Updated 3 months ago
- A Cross-Platform C++ parser library for Windows user minidumps with Python 3 bindings.☆203Updated 5 months ago
- Find patterns of vulnerabilities on Windows in order to find 0-day and write exploits of 1-days. We use Microsoft security updates in ord…☆184Updated 3 years ago
- Canadian Furious Beaver is a ProcMon-style tool designed only for capturing IRPs sent to any Windows driver.☆318Updated last year
- ☆814Updated 5 years ago
- ☆297Updated 4 years ago