trailofbits / uthenticodeLinks
A cross-platform library for verifying Authenticode signatures
☆156Updated last month
Alternatives and similar repositories for uthenticode
Users that are interested in uthenticode are comparing it to the libraries listed below
Sorting:
- ☆131Updated last year
- Named pipe I/O ETW provider for Windows☆71Updated 5 years ago
- The history of Windows Internals via symbols.☆180Updated 3 years ago
- API monitoring via return-hijacking thunks; works without information about target function prototypes.☆118Updated 5 years ago
- Simple project that demonstrates how an ETW consumer can be created just by using NTDLL☆143Updated 6 years ago
- Hyper-V Research is trendy now☆189Updated last year
- IntroVirt is an guest introspection library for KVM☆56Updated last year
- Hyper-V Research is trendy now☆174Updated last month
- An implementation of a Microsoft Symbol Proxy server using Python☆38Updated 4 years ago
- Translates WinDbg "dt" structure dump to a C structure☆132Updated 9 years ago
- Automatically generate AV byte signatures from sets of similar binaries.☆282Updated 10 months ago
- Parser for Microsoft Program Database (PDB) files☆76Updated 5 years ago
- Module to generate and verify Authenticode signatures☆84Updated last week
- Automatically exported from code.google.com/p/virtdbg☆99Updated 10 years ago
- PICO processes toolbox, playground for PICO processes research☆74Updated 7 years ago
- ☆174Updated last year
- Hypervisor based tool for monitoring system register accesses.☆147Updated 7 years ago
- Simple driver to register all available process, thread, image, Registry, and Object callbacks☆124Updated 8 years ago
- A collection of empty MSVC projects, compiled using various versions and configurations of Visual Studio.☆33Updated last year
- An example sandbox using AppContainer (Windows 8+)☆140Updated 5 years ago
- An analysis of the Warbird virtual-machine protection for the CI!g_pStore☆257Updated 7 years ago
- capemon: CAPE's monitor☆129Updated last week
- WinDbg debugger extension library providing various tools to analyse, dump and fix (restore) Microsoft Portable Executable files for both…☆84Updated last year
- A Windows kernel dump C++ parser library with Python 3 bindings.☆206Updated 2 weeks ago
- Print compiler information stored in Rich Header of PE executables.☆140Updated last week
- Elevation of privilege detector based on HyperPlatform☆122Updated 8 years ago
- CallMon is an experimental system call monitoring tool that works on Windows 10 versions 2004+ using PsAltSystemCallHandlers☆144Updated 5 years ago
- Fetch PDB symbols directly from Microsoft's symbol servers☆42Updated 3 years ago
- Hyper-V scripts☆130Updated this week
- Lightweight type-1 hypervisor offering a foundation for building advanced security-focused functionality.☆276Updated 9 months ago