vadimkotov / winapi-jsonLinks
Windows API functions in JSON for your automation needs
☆27Updated 4 years ago
Alternatives and similar repositories for winapi-json
Users that are interested in winapi-json are comparing it to the libraries listed below
Sorting:
- BluePill: Neutralizing Anti-Analysis Behavior in Malware Dissection (Black Hat Europe 2019, IEEE TIFS 2020)☆125Updated 3 years ago
- IDA Plugin which decodes Windows Device I/O control code into DeviceType, FunctionCode, AccessType and MethodType.☆112Updated last year
- This x64dbg plugin adds several commands for dumping PE header information by address.☆63Updated 8 years ago
- A command tree based on commands and extensions for Windows Kernel Debugging.☆109Updated 5 years ago
- Persistent IAT hooking application - based on bearparser☆258Updated 2 years ago
- Hyper-V Research is trendy now☆182Updated last year
- Metadata hash incorporating the Rich Header for robustness against packing and other malware tricks☆67Updated 4 years ago
- Analyses in IDA/Hex-Rays☆84Updated 2 years ago
- Library that allows you to run 64bit code on a Wow64 32bit process☆147Updated 8 years ago
- Simple windows API logger☆108Updated 5 years ago
- Set of antianalysis techniques found in malware☆131Updated 2 years ago
- Automatically rebuild Import Address Table for dumped PE file. With python bindings!☆120Updated 6 years ago
- A local copy of Alex Ionescu's seemingly abandoned native-nt-toolkit project containing knowledge inherited from the ReactOS project.☆54Updated 5 years ago
- The history of Windows Internals via symbols.☆180Updated 3 years ago
- ☆131Updated 10 months ago
- ☆117Updated 12 years ago
- My repository to upload drivers from different books and all the information related to windows internals.☆157Updated 6 years ago
- Simple project that demonstrates how an ETW consumer can be created just by using NTDLL☆145Updated 6 years ago
- Print compiler information stored in Rich Header of PE executables.☆138Updated last week
- Recon 2015 Presentation from Alex Ionescu☆243Updated 9 years ago
- A branch-monitor-based solution for process monitoring.☆133Updated 5 years ago
- ☆150Updated last week
- Elevation of privilege detector based on HyperPlatform☆122Updated 8 years ago
- MemoryRanger protects kernel data and code by running drivers and hosting data in isolated kernel enclaves using VT-x and EPT features. M…☆229Updated 5 years ago
- Windbg extension to find PatchGuard pages☆121Updated 11 years ago
- ☆120Updated 4 years ago
- [ARCHIVED] mov rax, ${Thalium/IceBox}; jmp rax;☆74Updated 6 years ago
- ☆108Updated 6 years ago
- Static unpacker for FinSpy VM☆102Updated 4 years ago
- reverse engineering extension plugin for windbg☆116Updated 5 years ago