zodiacon / TotalPE2
PE Viewer
☆175Updated 3 months ago
Alternatives and similar repositories for TotalPE2:
Users that are interested in TotalPE2 are comparing it to the libraries listed below
- Single header version of System Informer's phnt library.☆210Updated last week
- Explore Kernel Objects on Windows☆213Updated 2 weeks ago
- Yet another PE Viewer☆139Updated 2 years ago
- Advanced driver monitoring utility.☆207Updated 2 years ago
- A bunch of parsers for PE and PDB formats in C++☆240Updated 11 months ago
- Comparing, discussing, and bypassing various techniques for suspending and freezing processes on Windows.☆123Updated 3 years ago
- An example of a client and server using Windows' ALPC functions to send and receive data.☆95Updated 3 months ago
- Collection of undocumented Windows API declarations.☆310Updated 2 weeks ago
- ntdll.h - compatible with MSVC 6.0, Intel C++ Compiler and MinGW. Serves as a complete replacement for Windows.h☆136Updated 5 years ago
- Browse Page Tables on Windows (Page Table Viewer)☆197Updated 3 years ago
- Debugger Anti-Detection Benchmark☆328Updated last year
- Samples for the book Windows Kernel Programming, 2nd edition☆331Updated 4 months ago
- Elevate a process to be a protected process☆149Updated 5 years ago
- Global user-mode hooking framework, based on AppInit_DLLs. The goal is to allow you to rapidly develop hooks to inject in an arbitrary pr…☆169Updated 3 years ago
- C++ Exceptions in Windows Drivers☆207Updated 4 years ago
- Bootkit for Windows Sandbox to disable DSE/PatchGuard.☆277Updated 6 months ago
- A global injection and hooking example☆136Updated last year
- Authenticode Hash Calculator for PE32/PE32+ files☆111Updated last year
- Run Processes as PPL with ELAM☆160Updated 3 years ago
- Ghetto user mode emulation of Windows kernel drivers.☆134Updated 6 months ago
- Hooking Windows' exception dispatcher to protect process's PML4☆165Updated 2 months ago
- API Set resolver for Windows☆130Updated 7 months ago
- Use ci.dll API for validating Authenticode signature of files☆138Updated 3 years ago
- Samples from my book Windows Native API programming☆61Updated 2 weeks ago
- Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard☆244Updated 2 years ago
- APC Internals Research Code☆165Updated 4 years ago
- This project migrated to https://github.com/backengineering/llvm-msvc☆82Updated last year
- x64 Windows kernel code execution via user-mode, arbitrary syscall, vulnerable IOCTLs demonstration☆312Updated 2 years ago
- Use ntdll/ntoskrnl to implement Kernel32, Advapi32 and other APIs. It includes user-mode and kernel-mode.☆77Updated last month
- Some Code Samples for Windows based Inter-Process-Communication (IPC)☆171Updated last year