Duncan Ogilvie
Duncan Ogilvie
AppInitHook
Global user-mode hooking framework, based on AppInit_DLLs. The goal is to allow you to rapidly develop hooks to inject in an arbitrary process.
dumpulator
An easy-to-use library for emulating memory dumps. Useful for malware analysis (config extraction, unpacking) and dynamic analysis in general (sandboxing).
TitanHide
Hiding kernel-driver for x86/x64.
JitMagic
Simple tool that allows you to have multiple Just-In-Time debuggers at once.
NtPhp
Ever wanted to execute PHP in your kernel driver? Look no further!
driver_unpacking
Ghetto user mode emulation of Windows kernel drivers.
CEAutoAttach
Tool to automatically make Cheat Engine attach to a process via the command line.