zodiacon / WFPExplorer
Windows Filtering Platform Explorer
☆249Updated 2 months ago
Alternatives and similar repositories for WFPExplorer:
Users that are interested in WFPExplorer are comparing it to the libraries listed below
- PE Viewer☆168Updated 2 months ago
- Collection of undocumented Windows API declarations.☆305Updated this week
- Native API online documentation, based on the System Informer (formerly Process Hacker) phnt headers☆232Updated this week
- A small tool that allows to run WinAPI functions through command line parameters☆185Updated 2 years ago
- Process Monitor X v2☆603Updated last year
- Authenticode Hash Calculator for PE32/PE32+ files☆109Updated last year
- Run the program with the specified permission level (C++20 required)☆341Updated last month
- DSE bypass using a leaked cert and adjusting the current clock.☆147Updated 2 years ago
- Samples for the book Windows Kernel Programming, 2nd edition☆327Updated 3 months ago
- Document ETW providers☆223Updated 4 years ago
- Explore Kernel Objects on Windows☆207Updated last year
- open source process monitor☆265Updated last year
- Controlling Windows PP(L)s☆301Updated last year
- Windows Anti-Rootkit Tool☆487Updated last week
- Yet another PE Viewer☆139Updated 2 years ago
- This tiny project prevents the signtool from verifing cert time validity and let you sign your bin with outdated cert without changing sy…☆230Updated 6 years ago
- A DTrace on Windows Reimplementation☆341Updated last month
- View ETW Provider manifest☆465Updated 4 months ago
- Bootkit for Windows Sandbox to disable DSE/PatchGuard.☆274Updated 5 months ago
- RPC Monitor tool based on Event Tracing for Windows☆341Updated 7 months ago
- Load self-signed drivers without TestSigning or disable DSE. Transferred from https://github.com/DoubleLabyrinth/Windows10-CustomKernelSi…☆722Updated 5 years ago
- XNTSV program for detailed viewing of system structures for Windows.☆456Updated this week
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆289Updated 10 months ago
- 🗜️ A packer for Windows x86 executable files written in C and Intel x86 Assembly. The new file after packing can obstruct reverse engine…☆336Updated 5 months ago
- The Kernel-Mode Winsock library, supporting TCP, UDP and Unix sockets (DGRAM and STREAM).☆245Updated last month
- A global injection and hooking example☆135Updated last year
- DLL that hooks the NtQuerySystemInformation API and hides a process name☆287Updated last year
- Enhanced version of the classic Spy++ tool☆188Updated 11 months ago
- ntdll.h - compatible with MSVC 6.0, Intel C++ Compiler and MinGW. Serves as a complete replacement for Windows.h☆134Updated 5 years ago
- Some Code Samples for Windows based Inter-Process-Communication (IPC)☆171Updated last year