I was challenged by a friend to list all the processes and drivers in a system using more "unusual" methods. By doing this I learned quite a lot about the windows internals. To be specific I learned a lot about the undocumented structures and functions in the NTAPI.
☆14Jul 12, 2016Updated 10 years ago
Alternatives and similar repositories for UndocumentedNTAPI
Users that are interested in UndocumentedNTAPI are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Intraceptor intercept Windows NT API calls and redirect them to a kernel driver to bypass process/threads handle protections.☆29May 18, 2022Updated 4 years ago
- eject_idb is a last ditch effort to flush and save your IDB when IDA hangs or a plugin causes an exception, etc.☆42Aug 18, 2026Updated last month
- Exploit PoC for CVE's and non CVE's alike☆21Jul 24, 2020Updated 6 years ago
- DirectNtApi - simple method to make ntapi function call without importing or walking export table. Work under Windows 7, 8 and 10☆53Mar 12, 2024Updated 2 years ago
- ntdll.h - compatible with MSVC 6.0, Intel C++ Compiler and MinGW. Serves as a complete replacement for Windows.h☆152May 24, 2026Updated 3 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Two PoC of accessing process virtual memory via NT Kernel☆21Jun 25, 2021Updated 5 years ago
- Leveraging Platform Trust Technology (PTT) to defeat Driver Signing Enforcement (DSE) to run Kernel Drivers (KMDF) with Secure Boot Enabl…☆19Aug 22, 2022Updated 4 years ago
- WinDbg Symbols Caching Proxy.☆19Updated this week
- XOrCryptEx lightweight C Utility/Algorithm☆13Mar 3, 2022Updated 4 years ago
- Chrome Extensions Dataset☆12Updated this week
- C & Shellcode Playground..☆10Dec 2, 2017Updated 8 years ago
- A fully compatible replacement of Windows NT NtCreateLowBoxToken syscall - precisely restored from reverse engineering☆45Jun 10, 2025Updated last year
- search for a driver/dll module that has a wanted section bigger than the size of your image☆21Aug 14, 2021Updated 5 years ago
- Test/benchmark of using 32-bit pointers in 64-bit code on Windows. Not an actual ABI, only inspired by Linux's x32 ABI.☆13Jun 7, 2019Updated 7 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Incident Response Collections☆11Jul 24, 2018Updated 8 years ago
- Simple tool to perform AStyle formatting in a git repository.☆15Apr 16, 2026Updated 5 months ago
- DUQU MALWARE SOURCE + BINARY + More coming☆14Feb 6, 2023Updated 3 years ago
- FAUCET is an OpenFlow controller for multi table OpenFlow 1.3 switches, that implements layer 2 switching, VLANs, ACLs, and layer 3 IPv4 …☆14Nov 18, 2019Updated 6 years ago
- ntoskrnl .data hooks for UM-KM communication☆53May 26, 2024Updated 2 years ago
- Zerokit shared code☆18Mar 28, 2019Updated 7 years ago
- fyyre.l2-fashion.de .. old site☆17Aug 15, 2026Updated last month
- Binary Deobfuscation Series☆21Nov 20, 2019Updated 6 years ago
- ☆10Sep 11, 2026Updated last week
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- ☆133Oct 2, 2024Updated last year
- ☆26Oct 18, 2023Updated 2 years ago
- Source code on the 1.44MB 3.5 floppy accompanying the Windows NT File System Internals book.☆20Jul 31, 2019Updated 7 years ago
- an iSCSI demo driver for Windows☆12Sep 21, 2015Updated 10 years ago
- Demonstrate the new FileDispositionInfoEx behavior☆15Nov 6, 2017Updated 8 years ago
- ☆14Apr 16, 2022Updated 4 years ago
- Extended library for using direct system calls on windows☆17Feb 6, 2022Updated 4 years ago
- RunPE dump - I wrote this to have better control over the analysis of malwares. I can stop and analysis malware when it uses some of the …☆10Jul 1, 2015Updated 11 years ago
- MSDN data annotation for radare2☆13Jul 2, 2024Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Windows Research Kernel☆41May 16, 2026Updated 4 months ago
- Malware WinXPSP2.Cermalus Windows Kernel Virus☆14Aug 11, 2023Updated 3 years ago
- FreeType compiled in WASM with emscripten☆14Jun 24, 2022Updated 4 years ago
- fanny.bmp cleaned MALWARE - ONLY FOR ACADEMICAL RESEARCH AND EDUCATIONAL PURPOSES! (incl Metasploit detection Module)☆49Jul 9, 2025Updated last year
- WizardsToolkit is a secure C library offering cross-platform cryptography, hashing, authentication, and data integrity tools. It supports…☆16Sep 12, 2026Updated last week
- ☆27Jun 29, 2023Updated 3 years ago
- A simple DLL injection protection driver.☆12Dec 21, 2020Updated 5 years ago