IDA Plugin which decodes Windows Device I/O control code into DeviceType, FunctionCode, AccessType and MethodType.
☆119Dec 1, 2023Updated 2 years ago
Alternatives and similar repositories for WinIoCtlDecoder
Users that are interested in WinIoCtlDecoder are comparing it to the libraries listed below
Sorting:
- A tool to help when dealing with Windows IOCTL codes or reversing Windows drivers.☆437Aug 22, 2018Updated 7 years ago
- DriverBuddy is an IDA Python script to assist with the reverse engineering of Windows kernel drivers.☆372Jan 8, 2020Updated 6 years ago
- Helper utility for debugging windows PE/PE+ loader.☆52Mar 15, 2015Updated 10 years ago
- wow64 syscall filter☆13Nov 12, 2014Updated 11 years ago
- windows kernel File redirection☆20Sep 21, 2014Updated 11 years ago
- Debugger extension for the Debugging Tools for Windows (WinDbg, KD, CDB, NTSD).☆69Nov 14, 2016Updated 9 years ago
- kernel exploitation helper class☆77Nov 26, 2016Updated 9 years ago
- IDAPython plugin for finding Xrefs from a function☆48Jul 14, 2016Updated 9 years ago
- A tool to help malware analysts tell that the sample is injecting code into other process.☆78Aug 12, 2015Updated 10 years ago
- ☆13Aug 12, 2015Updated 10 years ago
- hypervisor in windows device driver by intel vt☆14Aug 25, 2018Updated 7 years ago
- DiskCryptor - it's a free solution that allows you to encrypt disk partitions, including system partition.☆17Dec 7, 2011Updated 14 years ago
- A windbg extension, extracting token related contents☆41Dec 23, 2020Updated 5 years ago
- Notes my learning steps about Windows-NT☆23May 18, 2017Updated 8 years ago
- Program to monitor Windows event (keyboard, mouse event, processes, memory, cpu, ...)☆34Nov 10, 2014Updated 11 years ago
- The Windows driver and device management program for NDAS devices such as the NetDISK.☆16Jun 17, 2016Updated 9 years ago
- Name substitution plugin for IDA Pro☆146Jun 29, 2017Updated 8 years ago
- Sandbox d'analyse de malware pour Windows 7 avec un client TCP en mode noyau☆19Feb 23, 2016Updated 10 years ago
- Guest to host VM escape exploit for Parallels Desktop☆27Nov 14, 2014Updated 11 years ago
- Windows KExec☆25Apr 20, 2010Updated 15 years ago
- Python scripts for reverse engineering.☆188May 7, 2021Updated 4 years ago
- Windbg extension to find PatchGuard pages☆123Jun 24, 2014Updated 11 years ago
- Analysis PE file or Shellcode☆50Jul 28, 2016Updated 9 years ago
- ☆117Nov 11, 2012Updated 13 years ago
- more at http://www.zer0mem.sk/?p=271☆12Jun 11, 2013Updated 12 years ago
- A minifilter driver preserves all modified and deleted files.☆79Jul 17, 2015Updated 10 years ago
- IDAScript to create Symbol file which can be loaded in WinDbg via AddSyntheticSymbol☆41Jul 25, 2014Updated 11 years ago
- qb-sync is an open source tool to add some helpful glue between IDA Pro and Windbg. Its core feature is to dynamically synchronize IDA's …☆120Jul 13, 2015Updated 10 years ago
- ☆17Oct 24, 2016Updated 9 years ago
- IDASimulator is a plugin that extends IDA's conditional breakpoint support, making it easy to augment / replace complex executable code i…☆46Sep 2, 2014Updated 11 years ago
- Windows Kernel Driver - Create a driver device in TDI layer of windows kernel to capture network data packets☆36Jul 21, 2014Updated 11 years ago
- The project is a demo solution for one of the anti-rootkit techniques aimed on overcoming splicers☆34Mar 13, 2017Updated 8 years ago
- Local Kernel Debugger (LKD) is a python wrapper around dbgengine.dll☆92Aug 22, 2016Updated 9 years ago
- nyā☆70Oct 16, 2015Updated 10 years ago
- ☆14Jan 10, 2017Updated 9 years ago
- An av windows engine with file guard and compress file enumator☆12Aug 25, 2018Updated 7 years ago
- OllyCallTrace is a plugin for OllyDbg to trace the call chain of a thread.☆54Nov 4, 2011Updated 14 years ago
- Fuzz and Detect "Use After Free" vulnerability in win32k.sys ( Heap based )☆138Nov 28, 2015Updated 10 years ago
- Windows Kernel Mode PCRE☆10Feb 4, 2015Updated 11 years ago