yardenshafir / WinDbg_Scripts
Useful scripts for WinDbg using the debugger data model
☆408Updated last year
Alternatives and similar repositories for WinDbg_Scripts:
Users that are interested in WinDbg_Scripts are comparing it to the libraries listed below
- My personal cheat sheet for using WinDbg for kernel debugging☆410Updated 5 months ago
- A DTrace on Windows Reimplementation☆342Updated last month
- A bunch of JavaScript extensions for WinDbg.☆331Updated 4 months ago
- An application to view and filter pool allocations from a dmp file on Windows 10 RS5+.☆136Updated 2 years ago
- Time Travel Debugging IDA plugin☆577Updated 9 months ago
- Toy scripts for playing with WinDbg JS API☆226Updated 8 months ago
- Advanced driver monitoring utility.☆207Updated 2 years ago
- My notes while studying Windows internals☆418Updated 3 months ago
- A library to develop kernel level Windows payloads for post HVCI era☆395Updated 3 years ago
- XNTSV program for detailed viewing of system structures for Windows.☆457Updated this week
- Static Binary Instrumentation tool for Windows x64 executables☆198Updated last month
- Samples for the book Windows Kernel Programming, 2nd edition☆327Updated 3 months ago
- This is a repo for small, useful scripts and extensions☆244Updated last year
- Extract Windows Defender database from vdm files and unpack it☆437Updated 5 years ago
- Exploring RPC interfaces on Windows☆320Updated last year
- Bindings for Microsoft WinDBG TTD☆218Updated last year
- msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA.☆151Updated last year
- Examples of leaking Kernel Mode information from User Mode on Windows☆595Updated 7 years ago
- View ETW Provider manifest☆466Updated 5 months ago
- Web-based tool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across different versions of the …☆335Updated this week
- DEFCON 27 workshop - Modern Debugging with WinDbg Preview☆719Updated 5 months ago
- Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks☆347Updated 5 months ago
- Internals information about Hyper-V☆689Updated 2 months ago
- Dump of win32k POCs for bugs I've found☆371Updated 3 years ago
- Operating System Design Review: A systemic analysis of modern systems architecture☆306Updated last month
- APC Internals Research Code☆162Updated 4 years ago
- Research on Windows Kernel Executive Callback Objects☆285Updated 5 years ago
- Enumerating and removing kernel callbacks using signed vulnerable drivers☆556Updated 2 years ago
- Post exploitation technique to turn arbitrary kernel write / increment into full read/write primitive on Windows 11 22H2☆225Updated 2 years ago
- Canadian Furious Beaver is a ProcMon-style tool designed only for capturing IRPs sent to any Windows driver.☆317Updated last year