Skip to content

Instantly share code, notes, and snippets.

Avatar

hshrzd

View GitHub Profile
@hshrzd
hshrzd / readme.md
Created Jun 4, 2021 — forked from lancejpollard/readme.md
System Call List for Windows, Mac, and Linux
@hshrzd
hshrzd / pe_file.cpp
Last active May 29, 2021
Common structs for IDA
View pe_file.cpp
typedef struct _IMAGE_DOS_HEADER
{
_WORD e_magic;
_WORD e_cblp;
_WORD e_cp;
_WORD e_crlc;
_WORD e_cparhdr;
_WORD e_minalloc;
_WORD e_maxalloc;
_WORD e_ss;
@hshrzd
hshrzd / scrdec18-VC8.exe
Created Feb 17, 2021 — forked from bcse/scrdec18-VC8.exe
Windows Script Decoder 1.8 (Decoding JScript.Encoded)
@hshrzd
hshrzd / strref.py
Created Aug 6, 2020
IDA script to fetch string references
View strref.py
import idautils
sc = idautils.Strings()
for s in sc:
curr_str = str(s)
str_offset = s.ea
for xref in idautils.XrefsTo(s.ea):
func = idaapi.get_func(xref.frm)
if not func:
@hshrzd
hshrzd / immunity_list_calls_via_reg.py
Created Apr 18, 2020
Immunity PyCommand: list calls via registry
View immunity_list_calls_via_reg.py
#!/usr/bin/env python
"""
(c) hAsh, 2015 run via ImmunityDbg
"""
__VERSION__ = '0.3.1'
__AUTHOR__ = 'hAsh'
import immlib
import pefile