Windows Filtering Platform Explorer
☆335Aug 28, 2025Updated 6 months ago
Alternatives and similar repositories for WFPExplorer
Users that are interested in WFPExplorer are comparing it to the libraries listed below
Sorting:
- ☆27Jul 13, 2025Updated 8 months ago
- ☆58Feb 27, 2026Updated 3 weeks ago
- View Windows System in action☆46Aug 3, 2025Updated 7 months ago
- Process Monitor X v2☆651Jan 22, 2024Updated 2 years ago
- Explore Kernel Objects on Windows☆244Apr 4, 2025Updated 11 months ago
- INF Studio for easier working with driver installation files☆39Nov 11, 2023Updated 2 years ago
- PE Viewer☆212Jan 24, 2026Updated last month
- Debug Print viewer (user and kernel)☆72Feb 7, 2024Updated 2 years ago
- All reasonably stable tools☆1,402Feb 27, 2026Updated 3 weeks ago
- Work with eBPF on Windows☆44Feb 26, 2025Updated last year
- Remote Thread Detection with a Kernel Driver☆34Jan 14, 2025Updated last year
- BITS Transfers Manager☆46May 18, 2025Updated 10 months ago
- Code to make it easier to write an NDIS network driver on Windows☆93Oct 1, 2023Updated 2 years ago
- Enhanced version of the classic Spy++ tool☆223Feb 26, 2026Updated 3 weeks ago
- Windows Object Explorer 64-bit☆1,893Mar 9, 2026Updated last week
- Sysmon-Like research tool for ETW☆387Nov 15, 2022Updated 3 years ago
- Samples for the book Windows Kernel Programming, 2nd edition☆372Aug 2, 2025Updated 7 months ago
- List the ETW provider(s) in the registration table of a process.☆80Sep 20, 2023Updated 2 years ago
- View ETW Provider manifest☆576Nov 1, 2024Updated last year
- Windows System Explorer☆878Nov 29, 2025Updated 3 months ago
- Sample for Creating a new kernel object type and supporting API☆28Sep 7, 2024Updated last year
- RpcView is a free tool to explore and decompile Microsoft RPC interfaces☆1,049Sep 24, 2023Updated 2 years ago
- An example driver for Windows that shows how to set-up some basic components of the Windows Filtering Platform☆205Jul 6, 2022Updated 3 years ago
- Some Code Samples for Windows based Inter-Process-Communication (IPC)☆211Feb 29, 2024Updated 2 years ago
- Bootkit for Windows Sandbox to disable DSE/PatchGuard.☆321Oct 13, 2024Updated last year
- RPC Monitor tool based on Event Tracing for Windows☆388Aug 19, 2024Updated last year
- Run any executable as SYSTEM account (no service required)☆142May 11, 2024Updated last year
- Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.☆244Sep 26, 2023Updated 2 years ago
- Files for http://blog.deniable.org/posts/windows-callbacks/☆83Feb 26, 2022Updated 4 years ago
- Uses Threat-Intelligence ETW events to identify shellcode regions being hidden by fluctuating memory protections☆172May 17, 2023Updated 2 years ago
- Windows Anti-Rootkit Tool☆547Dec 31, 2025Updated 2 months ago
- Simple project that demonstrates how an ETW consumer can be created just by using NTDLL☆146Feb 23, 2019Updated 7 years ago
- ☆40May 10, 2025Updated 10 months ago
- Controlling Windows PP(L)s☆381Jun 9, 2023Updated 2 years ago
- PoC memory injection detection agent based on ETW, for offensive and defensive research purposes☆301Apr 10, 2021Updated 4 years ago
- Walks the CFG bitmap to find previously executable but currently hidden shellcode regions☆134May 17, 2023Updated 2 years ago
- Monitor Kernel pool allocations tags☆77Nov 2, 2023Updated 2 years ago
- ☆31Dec 1, 2022Updated 3 years ago
- anti-ransomware file-system filter☆69Sep 3, 2024Updated last year