Alnoor (snowkoan)

snowkoan

Geek Repo

Company:Stairwell

Location:Ottawa, Canada

Home Page:https://needleinathreadstack.wordpress.com/

Github PK Tool:Github PK Tool

Alnoor's starred repositories

readdirectorychanges

Sample code that goes with "Understanding ReadDirectoryChangesW"

Language:C++License:MITStargazers:112Issues:0Issues:0

wtrace

Command line tracing tool for Windows, based on ETW.

Language:C#License:MITStargazers:668Issues:0Issues:0

icomake

Combine multiple ICO/PNGs into single .ICO file, retaining format of each sub-image, optimizing the order.

Language:C++Stargazers:28Issues:0Issues:0

Kdrill

Python tool to check rootkits in Windows kernel

Language:PythonLicense:BSD-3-ClauseStargazers:162Issues:0Issues:0

ETViewer

An alternative to Windows TraceView util

Language:C++License:GPL-2.0Stargazers:19Issues:0Issues:0

ImHex

🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.

Language:C++License:GPL-2.0Stargazers:44421Issues:0Issues:0
Language:HTMLStargazers:182Issues:0Issues:0

Koppeling

Adaptive DLL hijacking / dynamic export forwarding

Language:C++License:GPL-3.0Stargazers:725Issues:0Issues:0

x509-cert-testcorpus

X.509 certificate test corpus that was scraped from public TLS servers

Language:PythonLicense:CC0-1.0Stargazers:1Issues:0Issues:0

atomic-red-team

Small and highly portable detection tests based on MITRE's ATT&CK.

Language:CLicense:MITStargazers:9664Issues:0Issues:0

auxlib

Full reversing of the Microsoft Auxiliary Windows API Library and ported to C

Language:CLicense:MITStargazers:23Issues:0Issues:0

ghidra-scripts

A collection of my Ghidra scripts to facilitate reverse engineering and vulnerability research.

Language:JavaLicense:MITStargazers:225Issues:0Issues:0

ETW-Almulahaza

ETW-Almulahaza is a consumer python-based tool that help you monitor ETW events of the operating system

Language:PythonLicense:Apache-2.0Stargazers:12Issues:0Issues:0

malware_training_vol1

Materials for Windows Malware Analysis training (volume 1)

Language:AssemblyStargazers:1930Issues:0Issues:0

awesome-executable-packing

A curated list of awesome resources related to executable packing

License:CC0-1.0Stargazers:1180Issues:0Issues:0

Backstab

A tool to kill antimalware protected processes

Language:CStargazers:1374Issues:0Issues:0

UmdhGui

Graphical user interface for the UMDH tool

Language:C#License:MITStargazers:8Issues:0Issues:0

PoolmonViz

Powershell script to view kernel memory pool information

Language:PythonStargazers:2Issues:0Issues:0

WinObjEx64

Windows Object Explorer 64-bit

Language:CLicense:BSD-2-ClauseStargazers:1635Issues:0Issues:0

AutoHCK

AutoHCK is a tool for automating HCK/HLK testing, doing all the boilerplate steps in the process leaving you with simply choosing which driver you want to test on what os.

Language:RubyLicense:BSD-2-ClauseStargazers:26Issues:0Issues:0

yara

The pattern matching swiss knife

Language:CLicense:BSD-3-ClauseStargazers:8212Issues:0Issues:0

yarGen

yarGen is a generator for YARA rules

Language:PythonLicense:NOASSERTIONStargazers:1545Issues:0Issues:0

windowskernelprogrammingbook

The Windows Kernel Programming book samples

Language:C++License:MITStargazers:597Issues:0Issues:0
Language:PythonStargazers:237Issues:0Issues:0

docs

documentations, slides decks...

Language:TeXStargazers:775Issues:0Issues:0

sysmon-modular

A repository of sysmon configuration modules

Language:PowerShellLicense:MITStargazers:2640Issues:0Issues:0

Windows-Containers

Welcome to our Windows Containers GitHub community! Ask questions, report bugs, and suggest features -- let's work together.

Language:PowerShellLicense:MITStargazers:416Issues:0Issues:0

dotnet-computevirtualization

Sample class library for interfacing with Windows host compute service.

Language:C#License:MITStargazers:133Issues:0Issues:0

lsobj

Lists all visible objects in the Windows kernel object namespace, a command-line WinObj

Language:CStargazers:11Issues:0Issues:0

ApplicationInspector

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using static analysis with a json based rules engine. Ideal for scanning components before use or detecting feature level changes.

Language:C#License:MITStargazers:4231Issues:0Issues:0