DLL_Imports_BOF

PE DLL inspector

An enumeration tool to inspect PE files and extract information about loaded DLLs and their imported functions

A BOF to parse the imports of a provided PE-file, optionally extracting symbols on a per-dll basis.

GitHub

83 stars
3 watching
10 forks
Language: C
last commit: almost 5 years ago

Related projects:

RepositoryDescriptionStars
espressocake/dll-hijack-search-order-bofA tool to enumerate the search order of DLL resolution and potentially gain information about a file's mutability.141
espressocake/process_protection_level_bofA tool that helps operators determine the protection level of a process before attempting to access its memory51
espressocake/defender_exclusions-bofTools to determine Windows Defender exclusions241
espressocake/ppldump_bofA tool for dumping the memory contents of a protected process on Windows136
espressocake/needle_sift_bofA tool for searching for specific strings within files using a needle-sift algorithm30
espressocake/firewall_walker_bofAn exploit technique allowing interaction with Windows software firewall via COM interfaces.100
boku7/xpipeThis tool lists active Windows pipes and returns their owners and DACL permissions75
hiddenillusion/analyzepeAnalyzes PE files by combining data from various tools to generate a centralized report.204
espressocake/self_deletion_bofBOF implementation of a research concept allowing for controlled deletion of processes171
espressocake/toggle_token_privileges_bofA tool to add or remove specific privilege rights from the token of the current process52
dragon-dreamer/binary-valentineAn executable file analyzer tool that detects security, configuration, optimization, system, and format issues in Windows executables18
netero1010/servicemove-bofA tool that exploits a Windows vulnerability to execute arbitrary code on remote systems using a technique called DLL hijacking.284
petoolse/petoolsA toolkit for analyzing and manipulating Portable Executable (PE) files used in Windows applications.1,057
fzakaria/ebpf-mpls-encap-decapDemonstrates packet encapsulation and decapsulation with MPLS labels using eBPF54
med0x2e/sigflipA tool for modifying signed executable files without invalidating the signature or integrity checks.1,094