Exetools  

Go Back   Exetools > General > Community Tools

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 04-21-2026, 11:25
foosaa foosaa is offline
Friend
 
Join Date: Dec 2005
Posts: 112
Rept. Given: 36
Rept. Rcvd 14 Times in 11 Posts
Thanks Given: 179
Thanks Rcvd at 93 Times in 34 Posts
foosaa Reputation: 14
Cool NtWarden - Windows Analysis and Research Toolkit

Good morning folks!

I hope this will come in handy for performing Windows application analysis and research.

A small gist of it's capabilities:

NtWarden is a user-mode windows inspection tool that provides good visibility into processes, services, networking, registry, IPC, and system internals, with real-time performance overlays and ETW/log tracing etc.

With the help of kernel mode component (KWinSys), it can extend into low-level analysis of detecting hidden processes, kernel hooks, SSDT tampering, callbacks, drivers, and integrity violations and can also do process level heuristics for identifying injection, process hollowing, syscall abuses, and other stealth techniques.

https://github.com/mrT4ntr4/NtWarden

I hope this will come in handy while performing reverse engineering, malware analysis and protection technique analysis.

Do let me know if it useful. Thanks and have a fantastic day!

Last edited by foosaa; 04-21-2026 at 11:26. Reason: Updated usage.
Reply With Quote
The Following 2 Users Gave Reputation+1 to foosaa For This Useful Post:
Fyyre (04-26-2026), wx69wx2023 (04-24-2026)
The Following 6 Users Say Thank You to foosaa For This Useful Post:
blue_devil (04-21-2026), MarcElBichon (04-21-2026), new_profile (04-23-2026), niculaita (04-21-2026), tame_mpeg (04-21-2026), user1 (04-25-2026)
  #2  
Old 04-22-2026, 12:50
Jupiter's Avatar
Jupiter Jupiter is offline
Lo*eXeTools*rd
 
Join Date: Jan 2005
Location: Moscow, Russia
Posts: 234
Rept. Given: 43
Rept. Rcvd 62 Times in 37 Posts
Thanks Given: 37
Thanks Rcvd at 191 Times in 57 Posts
Jupiter Reputation: 62
Note: DirectX 11 required for ImGui.

Looks like a hacker tool in Hollywood action movies
__________________
EnJoy!
Reply With Quote
  #3  
Old 04-26-2026, 09:29
Fyyre's Avatar
Fyyre Fyyre is offline
Fyyre
 
Join Date: Dec 2009
Location: 0°N 0°E / 0°N 0°E / 0; 0
Posts: 295
Rept. Given: 106
Rept. Rcvd 93 Times in 44 Posts
Thanks Given: 203
Thanks Rcvd at 397 Times in 130 Posts
Fyyre Reputation: 93
It's the old new thing!
__________________
Pax in vultu, bellum in corde.

--

https://github.com/Fyyre
Reply With Quote
  #4  
Old 05-01-2026, 03:33
HarrySpoofer HarrySpoofer is offline
Friend
 
Join Date: Jul 2018
Posts: 47
Rept. Given: 0
Rept. Rcvd 5 Times in 3 Posts
Thanks Given: 10
Thanks Rcvd at 50 Times in 19 Posts
HarrySpoofer Reputation: 5
Quote:
Originally Posted by Jupiter View Post
Note: DirectX 11 required for ImGui.
My OS does not support DX11. I protest !
Why does a low-level utility need DX at all?, pfffff...
Reply With Quote
  #5  
Old 05-02-2026, 02:04
Ibrahim_Mihai Ibrahim_Mihai is offline
Friend
 
Join Date: Feb 2026
Posts: 8
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 3
Thanks Rcvd at 2 Times in 2 Posts
Ibrahim_Mihai Reputation: 0
Quote:
Originally Posted by HarrySpoofer View Post
My OS does not support DX11. I protest !
Why does a low-level utility need DX at all?, pfffff...
Use System Informer instead: https://systeminformer.sourceforge.io/downloads
Download the portable version: https://sourceforge.net/projects/systeminformer/files/systeminformer-3.2.25011-release-bin.zip/download
I use it all the time.

It evolved from Process Hacker: https://processhacker.sourceforge.io/downloads.php
-Ibrahim Mihai
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 11:10.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )