
x64dbg
An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

ProcMon-style IRP monitor for Windows drivers. Captures and logs I/O Request Packets via a kernel driver and user-land broker, outputting JSON for…

Helper script for Windows kernel debugging with IDA Pro on native Bochs debugger (including PDB symbols)

A MCP Debugger Server for Windows executables (x86 and x64). Exposes debugger functionality as MCP Tools for static / dynamic analysis of the…

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

Memory Debugger for Windows, Linux, Mac, and Android

SoftICE-like kernel debugger for Windows 11

Drltrace is a library calls tracer for Windows and Linux applications.

Hardware breakpoint hooking engine for Windows that uses debug registers to hook functions, bypass ETW/AMSI, and evade user-land EDR monitoring.


A Linux version of the ProcDump Sysinternals tool

User-friendly Microsoft Windows Debugger for Malware Analysts.

An strace-like program for the Windows 'native' API

A PowerShell front-end for the Windows debugger engine.

PoC for CVE-2022-21971 "Windows Runtime Remote Code Execution Vulnerability"

PoCs and tools for investigation of Windows process execution techniques

bespoke tooling for offensive security's Windows Usermode Exploit Dev course (OSED)

Windows command-line utility for reading, writing, and executing kernel-mode code from Administrator context using a font validation execution…