yardenshafir / WinDbg_Scripts
Useful scripts for WinDbg using the debugger data model
☆389Updated 7 months ago
Related projects ⓘ
Alternatives and complementary repositories for WinDbg_Scripts
- My personal cheat sheet for using WinDbg for kernel debugging☆388Updated last month
- A DTrace on Windows Reimplementation☆328Updated 3 weeks ago
- Time Travel Debugging IDA plugin☆553Updated 4 months ago
- Toy scripts for playing with WinDbg JS API☆220Updated 4 months ago
- Side-by-side comparison of the Windows and Linux (GNU) Loaders☆290Updated 2 months ago
- A bunch of JavaScript extensions for WinDbg.☆320Updated 3 years ago
- My notes while studying Windows internals☆400Updated this week
- View ETW Provider manifest☆433Updated 3 weeks ago
- Exploring RPC interfaces on Windows☆284Updated 9 months ago
- Internals information about Hyper-V☆661Updated 2 months ago
- A library to develop kernel level Windows payloads for post HVCI era☆366Updated 3 years ago
- Canadian Furious Beaver is a ProcMon-style tool designed only for capturing IRPs sent to any Windows driver.☆310Updated 7 months ago
- An application to view and filter pool allocations from a dmp file on Windows 10 RS5+.☆124Updated last year
- msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA.☆148Updated 10 months ago
- Quickly debug shellcode extracted during malware analysis☆565Updated last year
- Static Binary Instrumentation tool for Windows x64 executables☆180Updated 3 weeks ago
- Samples for the book Windows Kernel Programming, 2nd edition☆294Updated this week
- This is a repo for small, useful scripts and extensions☆241Updated last year
- Expriments☆444Updated last month
- awesome windbg extensions☆314Updated 5 years ago
- Bindings for Microsoft WinDBG TTD☆213Updated last year
- XNTSV program for detailed viewing of system structures for Windows.☆446Updated this week
- Extract Windows Defender database from vdm files and unpack it☆425Updated 4 years ago
- HashDB API hash lookup plugin for IDA Pro☆296Updated last month
- Some Code Samples for Windows based Inter-Process-Communication (IPC)☆161Updated 8 months ago
- DEFCON 27 workshop - Modern Debugging with WinDbg Preview☆709Updated 3 weeks ago
- Examples of leaking Kernel Mode information from User Mode on Windows☆581Updated 7 years ago
- Unofficial Common Log File System (CLFS) Documentation☆164Updated 3 years ago
- Research on Windows Kernel Executive Callback Objects☆278Updated 4 years ago
- SHAREM is a shellcode analysis framework, capable of emulating more than 20,000 WinAPIs and virutally all Windows syscalls. It also conta…☆343Updated 3 weeks ago