
ida_bochs_windows
Helper script for Windows kernel debugging with IDA Pro on native Bochs debugger (including PDB symbols)

Helper script for Windows kernel debugging with IDA Pro on native Bochs debugger (including PDB symbols)

Static Binary Instrumentation tool for Windows x64 executables

An strace-like program for the Windows 'native' API

An API hooking framework for intercepting and monitoring Windows applications

Winstrument is a framework of modular scripts to aid in instrumenting Windows software using Frida for reverse engineering and attack surface…

Runtime Windows API interception library for hooking, monitoring, and instrumenting function calls. Supports binary rewriting and DLL injection,…

Runtime instrumentation framework for building dynamic analysis tools: tracing, profiling, code coverage, memory debugging, fuzzing, and disassembly…

Rusty Hypervisor - Windows Kernel Blue Pill Type-2 Hypervisor in Rust (Codename: Matrix)

Windows NT ioctl bruteforcer and modular fuzzer

Detect, analyze and uniquely identify crashes in Windows applications

User-mode x86_64 binary emulator for malware analysis and reverse engineering. Supports PE, ELF, memory dumps, and raw binaries with syscall tracing,…

Sample extensions, scripts, and API uses for WinDbg.

An Interactive Binary Patching Plugin for IDA Pro

A DTrace on Windows Reimplementation

Toy scripts for playing with WinDbg JS API

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会

Cargo subcommand for coverage-guided Rust fuzzing with libFuzzer: create and run fuzz targets, minimize failures and corpora, and report coverage.