themeldingwars / Be.HexEditor
A modified fork of Be.HexEditor for use in debug tools
☆15Updated 2 years ago
Related projects: ⓘ
- Parse Microsoft shim databases☆28Updated 2 weeks ago
- Library to process OLE compound file format. This is a work in progress and was initially written for jumplist parsing (for which it does…☆18Updated 2 weeks ago
- Dump certificates from PE files in different formats☆36Updated 8 months ago
- .NET wrapper for dbghelp.dll☆21Updated 5 years ago
- Example/starter code for custom Windows application compatibility shims☆29Updated 3 years ago
- ☆26Updated last year
- ☆19Updated this week
- An efficient tool for search files, directories, and alternate data streams directly from NTFS image files.☆19Updated 7 months ago
- Lnk file parser☆78Updated 2 weeks ago
- AlphaFS is a .NET library providing more complete Win32 file system functionality to the .NET platform than the standard System.IO classe…☆10Updated 3 years ago
- ☆59Updated 2 months ago
- C# wrapper around the Yara pattern matching library☆34Updated 2 years ago
- Extension blocks as found in ShellBags and other places in the Registry☆23Updated 2 weeks ago
- WPF helper library☆14Updated 5 years ago
- ☆21Updated 7 years ago
- An example pattern in C# for using WMI to monitor process creation and termination events.☆51Updated 6 years ago
- $MFT parser (from live systems or a copy of the $MFT) and raw file copy utility☆36Updated 2 months ago
- Analyzers for Portable Executable anomalies and other malware behavior.☆32Updated 3 months ago
- INF Studio for easier working with driver installation files☆36Updated 10 months ago
- Windows x64 Process Scanner to detect application compatability shims☆37Updated 5 years ago
- x64dbg Plugin SDK For x86 Assembler☆21Updated 6 years ago
- Code samples that serve as references for Windows API functions☆11Updated 3 months ago
- extract and parse WEVT_TEMPLATEs from PE files☆17Updated 8 months ago
- ☆39Updated 10 months ago
- ☆38Updated last year
- Mount VSCs with ease!☆14Updated last year
- Automatic/Custom Destinations & LNK (MS-SHLLINK) Browser☆30Updated 6 months ago
- Provides a way which you can load a .NET dll/exe from disk, modify/inject IL, and then run the assembly all in memory without modifying t…☆29Updated 7 years ago
- IDAPython scripts☆15Updated 7 years ago
- A repo that contains a recursive dump from the ROOT key of every Windows Registry hive (using KAPE) from a vanilla (clean) install of eve…☆44Updated last year