Skip to content

Instantly share code, notes, and snippets.



View GitHub Profile
hshrzd /
Created Jun 4, 2021 — forked from lancejpollard/
System Call List for Windows, Mac, and Linux
hshrzd / pe_file.cpp
Last active May 29, 2021
Common structs for IDA
View pe_file.cpp
typedef struct _IMAGE_DOS_HEADER
_WORD e_magic;
_WORD e_cblp;
_WORD e_cp;
_WORD e_crlc;
_WORD e_cparhdr;
_WORD e_minalloc;
_WORD e_maxalloc;
_WORD e_ss;
hshrzd / scrdec18-VC8.exe
Created Feb 17, 2021 — forked from bcse/scrdec18-VC8.exe
Windows Script Decoder 1.8 (Decoding JScript.Encoded)
hshrzd /
Created Aug 6, 2020
IDA script to fetch string references
import idautils
sc = idautils.Strings()
for s in sc:
curr_str = str(s)
str_offset = s.ea
for xref in idautils.XrefsTo(s.ea):
func = idaapi.get_func(xref.frm)
if not func:
hshrzd /
Created Apr 18, 2020
Immunity PyCommand: list calls via registry
#!/usr/bin/env python
(c) hAsh, 2015 run via ImmunityDbg
__VERSION__ = '0.3.1'
__AUTHOR__ = 'hAsh'
import immlib
import pefile