utshina / noahxLinks
Noah for Windows
☆25Updated 4 years ago
Alternatives and similar repositories for noahx
Users that are interested in noahx are comparing it to the libraries listed below
Sorting:
- Driver demonstrating how to register a DPC to asynchronously wait on an object☆49Updated 4 years ago
- Driver and WinDBG scripts to dump information about all resources and lookaside lists☆68Updated 5 years ago
- A research project about Windows notify routines.☆37Updated 5 years ago
- Parser for Microsoft Program Database (PDB) files☆76Updated 5 years ago
- VMCS Auditor provides almost all of Intel's VMCS Layout checklist based on Bochs Emulator.☆32Updated 6 years ago
- POC of sysenter x64 LSTAR MSR hook☆40Updated 11 years ago
- The sample DXE runtime driver demonstrating how to program DMA remapping.☆60Updated last year
- Simple Protected Mode Kernel for i386☆15Updated 5 years ago
- Extended Length Disassembler Engine for x86-64 (1337 bytes in size)☆52Updated 6 years ago
- Kernel mode driver for writing to physical disk with SL_FORCE_DIRECT_WRITE☆24Updated 10 years ago
- Windows 10 PE image loader (LDR) NTDLL component toolbox☆49Updated 5 years ago
- Windows_OS_Internals_Curriculum_Resource_Kit-ACADEMIC☆25Updated 6 years ago
- Crash Windows 10 up to RS2 from an unprivileged process☆41Updated 7 years ago
- This repository contains some tools that I have written in the past☆28Updated last year
- Virtualization detection through speculative execution PoCs and papers☆70Updated 7 years ago
- This is a simple driver with x64 inline assembly☆57Updated 5 years ago
- VrtuleTree is a tool that displays information about driver and device objects present in the system and relations between them. Its func…☆60Updated 4 years ago
- A collection of tools, source code, and papers researching Windows' implementation of CET.☆84Updated 4 years ago
- DirectNtApi - simple method to make ntapi function call without importing or walking export table. Work under Windows 7, 8 and 10☆53Updated last year
- penter hook example and driver time recorder☆31Updated 7 years ago
- HelloAmdHvPkg is a type-1 research hypervisor for AMD processors.☆96Updated 5 years ago
- Automatically exported from code.google.com/p/virtdbg☆98Updated 10 years ago
- Intermediate x86 instruction representation for use in obfuscation/deobfuscation.☆53Updated last month
- ☆40Updated 4 years ago
- Analyze PatchGuard☆59Updated 6 years ago
- Figuring out the cause of a handle downgrade☆24Updated 2 years ago
- Various WinDbg extensions and scripts☆32Updated 6 years ago
- A local copy of Alex Ionescu's seemingly abandoned native-nt-toolkit project containing knowledge inherited from the ReactOS project.☆54Updated 5 years ago
- Standalone program to download PDB Symbol files for debugging without WDK☆79Updated 6 years ago
- This is the first software system, which can detect a stealthy hypervisor and calculate several nested ones even under countermeasures.☆86Updated 10 years ago