zed-0xff / pedump
dump windows PE files using ruby
☆314Updated last week
Alternatives and similar repositories for pedump:
Users that are interested in pedump are comparing it to the libraries listed below
- C++ application that uses memory and code hooks to detect packers☆270Updated 7 years ago
- SmartDec decompiler☆401Updated 3 years ago
- Python code to parse Microsoft PDB files☆321Updated 7 months ago
- Persistent IAT hooking application - based on bearparser☆253Updated 2 years ago
- windows syscall table from xp ~ 10 rs4☆353Updated 6 years ago
- Portable Executable parsing library (from PE-bear)☆655Updated 7 months ago
- Labeless is a multipurpose IDA Pro plugin system for labels/comments synchronization with a debugger backend, with complex memory dumping…☆543Updated 2 months ago
- Incident Response & Digital Forensics Debugging Extension☆377Updated 6 years ago
- Drltrace is a library calls tracer for Windows and Linux applications.☆396Updated 4 years ago
- ATrace is a tool for tracing execution of binaries on Windows.☆237Updated 8 years ago
- Windows registry file format specification☆335Updated 6 years ago
- This is the main repository for metasm, a free assembler / disassembler / compiler written in ruby☆467Updated 5 months ago
- A pintool in order to unpack malware☆231Updated 8 years ago
- Source from VMDE paper, adapted to 2015☆181Updated 7 years ago
- Open source library that implements translator and tools for REIL (Reverse Engineering Intermediate Language)☆503Updated 3 years ago
- Virtualbox, VirtualMachine, Cuckoo, Anubis, ThreatExpert, Sandboxie, QEMU, Analysis Tools Detection Tools☆450Updated 6 years ago
- YaCo is an Hex-Rays IDA plugin. When enabled, multiple users can work simultaneously on the same binary. Any modification done by any use…☆318Updated 5 years ago
- IDA Pro script to add some useful runtime info to static analysis☆526Updated 2 years ago
- Consonance, a dark color scheme for IDA.☆263Updated 12 years ago
- Pure Python parser and analyzer for IDA Pro database files (.idb).☆472Updated 3 years ago
- DriverBuddy is an IDA Python script to assist with the reverse engineering of Windows kernel drivers.☆358Updated 5 years ago
- ☆960Updated last month
- A patch analysis tool☆362Updated 4 years ago
- Dynamic IDA Enrichment☆471Updated 3 years ago
- capstone based disassembler for extracting to binnavi☆227Updated 8 years ago
- Reverse engineering tool for automatic structure recovering and memory use analysis based on DynamoRIO and Capstone☆319Updated 5 years ago
- The ultimate hooking library☆263Updated 4 years ago
- A tool to detect and crash Cuckoo Sandbox☆292Updated 8 months ago
- flare-dbg is a project meant to aid malware reverse engineers in rapidly developing debugger scripts.☆150Updated 7 years ago
- Toolkit for enriching and speeding up static malware analysis☆167Updated 3 years ago