Monitor activity of any driver
☆352Nov 2, 2020Updated 5 years ago
Alternatives and similar repositories for DriverMon
Users that are interested in DriverMon are comparing it to the libraries listed below
Sorting:
- WinDBG Anti-RootKit Extension☆646Jul 29, 2020Updated 5 years ago
- A tool to help when dealing with Windows IOCTL codes or reversing Windows drivers.☆437Aug 22, 2018Updated 7 years ago
- The goal of the tool is to monitor requests received by selected device objects or kernel drivers. The tool is quite similar to IrpTracke…☆411Dec 27, 2024Updated last year
- Portable Executable Explorer☆161Mar 14, 2021Updated 5 years ago
- All reasonably stable tools☆1,402Feb 27, 2026Updated 3 weeks ago
- View handles and object for each object type☆65Sep 1, 2019Updated 6 years ago
- Simple driver to register all available process, thread, image, Registry, and Object callbacks☆124Oct 5, 2017Updated 8 years ago
- Syscall Monitor is a system monitor program (like Sysinternal's Process Monitor) using Intel VT-X/EPT for Windows7+☆748Jun 26, 2017Updated 8 years ago
- ☆16Nov 10, 2015Updated 10 years ago
- Driver and WinDBG scripts to dump information about all resources and lookaside lists☆66Apr 4, 2020Updated 5 years ago
- Hypervisor-based debugger☆191Dec 2, 2020Updated 5 years ago
- ☆34Sep 22, 2017Updated 8 years ago
- Windows Object Explorer 64-bit☆1,893Mar 9, 2026Updated last week
- Process Monitor X v2☆651Jan 22, 2024Updated 2 years ago
- Windows System Explorer☆878Nov 29, 2025Updated 3 months ago
- Papers, blogposts, tutorials etc for learning about Windows kernel exploitation, internals and (r|b)ootkits☆415Jan 2, 2020Updated 6 years ago
- ☆408Mar 1, 2017Updated 9 years ago
- Extended Process Monitor-like tool based on Event Tracing for Windows☆474Nov 29, 2019Updated 6 years ago
- A sample project for using Capstone from a driver in Visual Studio 2015☆36May 4, 2016Updated 9 years ago
- AllMemPro☆46Jan 15, 2018Updated 8 years ago
- This driver implements the Intel Processor Trace functionality in Intel Skylake architecture for Microsoft Windows☆466Apr 17, 2018Updated 7 years ago
- Elevation of privilege detector based on HyperPlatform☆123Mar 5, 2017Updated 9 years ago
- Notes my learning steps about Windows-NT☆23May 18, 2017Updated 8 years ago
- Monitoring and controlling kernel API calls with stealth hook using EPT☆1,362Jan 22, 2022Updated 4 years ago
- usermode standalone kernel interface☆111Jul 9, 2018Updated 7 years ago
- Hypervisor based tool for monitoring system register accesses.☆154Sep 13, 2018Updated 7 years ago
- Шаблон полнофункционального драйвера и обёртки над ядерным API☆113Aug 28, 2016Updated 9 years ago
- Blog posts☆29Aug 7, 2020Updated 5 years ago
- A tool to help malware analysts tell that the sample is injecting code into other process.☆78Aug 12, 2015Updated 10 years ago
- Hide Driver By MiProcessLoaderEntry☆294May 17, 2019Updated 6 years ago
- A driver that hooks C: volume using symbolic link callback to track all FS access to the volume☆109Apr 24, 2020Updated 5 years ago
- Set of tools to analyze Windows sandboxes for exposed attack surface.☆2,276Nov 6, 2025Updated 4 months ago
- reverse engineering extension plugin for windbg☆122Sep 30, 2019Updated 6 years ago
- Simple project that demonstrates how an ETW consumer can be created just by using NTDLL☆146Feb 23, 2019Updated 7 years ago
- A windbg extension, extracting token related contents☆41Dec 23, 2020Updated 5 years ago
- A command tree based on commands and extensions for Windows Kernel Debugging.☆112Jul 10, 2020Updated 5 years ago
- ☆20Jul 9, 2019Updated 6 years ago
- PdbView shows the contents of PDB files☆94Aug 23, 2018Updated 7 years ago
- Bypass for the hardening against usage of tagWnd as a kernel read/write primitive☆32Mar 22, 2017Updated 8 years ago