Tagged: Windows kernel drivers


DriverBuddy: IDA Python script to assist with the reverse engineering of Windows kernel drivers

DriverBuddy is an IDAPython plugin that helps automate some of the tedium surrounding the reverse engineering of Windows kernel drivers. Image: NCCGROUP Quickstart DriverBuddy Installation Instructions Clone the repo: git clone https://github.com/nccgroup/DriverBuddy.git Copy DriverBuddy folder...