tpn / windows-nt-file-system-internals-book
Source code on the 1.44MB 3.5 floppy accompanying the Windows NT File System Internals book.
☆15Updated 5 years ago
Related projects ⓘ
Alternatives and complementary repositories for windows-nt-file-system-internals-book
- An experimental dynamic malware unpacker based on Intel Pin and PE-sieve☆57Updated 2 months ago
- ☆41Updated last week
- ☆18Updated 5 years ago
- Code Integrity Violation Spotter☆17Updated 4 months ago
- A set of small utilities, helpers for PIN tracers☆31Updated last year
- DirectNtApi - simple method to make ntapi function call without importing or walking export table. Work under Windows 7, 8 and 10☆52Updated 7 months ago
- Helper Script to convert a Windbg dumped structure (using the 'dt' command) into a C structure. It creates dummy structs for you if neede…☆26Updated last year
- An API Monitor based on Instrumentation☆42Updated 6 years ago
- Runtime smm module loader☆30Updated last year
- Helper scripts for windows debugging with symbols for Bochs and IDA Pro (PDB files). Very handy for user mode <--> kernel mode☆19Updated last year
- Simple command line version of Sysinternals WinObj. Currently just lists object names and types given an object manager directory.☆19Updated last year
- Headers for linking your software with ntdll.dll☆15Updated 4 years ago
- ☆20Updated 3 years ago
- allowing um r/w through km from um ioctl ™☆12Updated 2 years ago
- ☆8Updated last week
- Support Windows OS Reversing by searching easily for references to functions across many DLLs☆33Updated 2 years ago
- Shows different icons for 64 and 32-bit DLLs. Register with RegSvr32 to install☆32Updated 2 years ago
- Windbg extension that allows you analyze Control Flow Guard map☆36Updated 3 years ago
- Simple error lookup for Win32 and NTSTATUS errors☆17Updated 5 years ago
- Static library and headers for linking your software with ntdll.dll☆30Updated 4 years ago
- EDR PoC WIP LLC☆10Updated 9 months ago
- ☆17Updated 5 years ago
- Windows NT port of 'Main is usually a function. So then when is it not?'☆24Updated 7 months ago
- NDC Oslo 2019 slides and demos☆32Updated 3 years ago
- Simple utility to watch directory change notifications on a given path☆16Updated 7 years ago
- An example of how to use Microsoft Windows Warbird technology☆25Updated last year
- Dump PDB Symbols including support for Bochs Debugging Format (with wine support)☆14Updated last year
- Various WinDbg extensions and scripts☆31Updated 6 years ago