trailofbits / cfg-showcaseLinks
Sample programs that illustrate how to use Control Flow Guard, VS2015's control flow integrity implementation
☆52Updated 8 years ago
Alternatives and similar repositories for cfg-showcase
Users that are interested in cfg-showcase are comparing it to the libraries listed below
Sorting:
- kernel pool windbg extension☆84Updated 10 years ago
- windbg plugin for win32k debugging☆75Updated 6 years ago
- Windbg2ida lets you dump each step in Windbg then shows these steps in IDA☆74Updated last year
- Driver and WinDBG scripts to dump information about all resources and lookaside lists☆65Updated 5 years ago
- A branch-monitor-based solution for process monitoring.☆135Updated 5 years ago
- AllMemPro☆46Updated 7 years ago
- Elevation of privilege detector based on HyperPlatform☆123Updated 8 years ago
- Static unpacker for FinSpy VM☆103Updated 4 years ago
- A little WinDbg extension to help dump the state of Win32k Type Isolation structures.☆38Updated 7 years ago
- Python bindings for the Microsoft Hypervisor Platform APIs.☆80Updated 6 years ago
- A windbg extension, extracting token related contents☆41Updated 4 years ago
- Adding exceptions to Microsoft's Control Flow Guard (CFG)☆57Updated 9 years ago
- A fast execution trace symbolizer for Windows.☆129Updated last year
- libemu shim layer and win32 environment for Unicorn Engine☆73Updated 8 years ago
- Takes a Windbg dumped structure (using the 'dt' command) and formats it into a C structure☆36Updated last year
- VMCS Auditor provides almost all of Intel's VMCS Layout checklist based on Bochs Emulator.☆32Updated 6 years ago
- reverse engineering extension plugin for windbg☆119Updated 6 years ago
- Windows 10 kernel and ntdll internal types, directly compatible with ida.☆53Updated 7 years ago
- VMX intrinsics plugin for Hex-Rays decompiler☆72Updated 6 years ago
- IDA plugin to explore and browse tags☆56Updated 6 years ago
- Code-Reuse Exploits detection using Intel Processor Trace☆28Updated 7 years ago
- ☆34Updated 4 years ago
- clone of armadillo patched for windows☆48Updated last year
- ☆49Updated 5 years ago
- IDA Plugin which decodes Windows Device I/O control code into DeviceType, FunctionCode, AccessType and MethodType.☆118Updated last year
- Bypass for the hardening against usage of tagWnd as a kernel read/write primitive☆32Updated 8 years ago
- Course sample for SMT-Based Binary Program Analysis training class☆32Updated 7 years ago
- [ARCHIVED] mov rax, ${Thalium/IceBox}; jmp rax;☆76Updated 6 years ago
- ☆11Updated 5 years ago
- Tools made for my Hyper-V blog series @ https://foxhex0ne.blogspot.com/☆57Updated 5 years ago