Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.
翻译 - 用于自动简化 Windows 内核反编译的 Hex-Rays 微码插件。
Web-based tool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across different versions of the OS.
The history of Windows Internals via symbols.
翻译 - Windows Internals通过符号的历史记录。
Enumerate user mode shared memory mappings on Windows.
Kernel Level NMI Callback Blocker
Windows kernel debugger for Linux hosts running Windows under KVM/QEMU
Collect various versions of ntoskrnl files
Analysis of the vulnerability
Kernel Mode DLL Manual Mapper
A fast method to intercept syscalls from any user-mode process using InstrumentationCallback and detect any process using InstrumentationCallback.
EPROCESS Unlinking example in "C" using DKOM Manipulation
PsLoadedModuleList Unlinking through DKOM Manipulation
All undocumented ntoskrnl structs crawled from vergiliusproject.com