Exetools

Exetools (https://forum.exetools.com/index.php)
-   Community Tools (https://forum.exetools.com/forumdisplay.php?f=47)
-   -   NtWarden - Windows Analysis and Research Toolkit (https://forum.exetools.com/showthread.php?t=21574)

foosaa 04-21-2026 11:25

NtWarden - Windows Analysis and Research Toolkit
 
Good morning folks!

I hope this will come in handy for performing Windows application analysis and research.

A small gist of it's capabilities:

NtWarden is a user-mode windows inspection tool that provides good visibility into processes, services, networking, registry, IPC, and system internals, with real-time performance overlays and ETW/log tracing etc.

With the help of kernel mode component (KWinSys), it can extend into low-level analysis of detecting hidden processes, kernel hooks, SSDT tampering, callbacks, drivers, and integrity violations and can also do process level heuristics for identifying injection, process hollowing, syscall abuses, and other stealth techniques.

https://github.com/mrT4ntr4/NtWarden

I hope this will come in handy while performing reverse engineering, malware analysis and protection technique analysis.

Do let me know if it useful. Thanks and have a fantastic day! :)

Jupiter 04-22-2026 12:50

Note: DirectX 11 required for ImGui.

Looks like a hacker tool in Hollywood action movies ;)

Fyyre 04-26-2026 09:29

It's the old new thing!

HarrySpoofer 05-01-2026 03:33

Quote:

Originally Posted by Jupiter (Post 135097)
Note: DirectX 11 required for ImGui.

My OS does not support DX11. I protest !
Why does a low-level utility need DX at all?, pfffff...

Ibrahim_Mihai 05-02-2026 02:04

Quote:

Originally Posted by HarrySpoofer (Post 135150)
My OS does not support DX11. I protest !
Why does a low-level utility need DX at all?, pfffff...

Use System Informer instead: https://systeminformer.sourceforge.io/downloads
Download the portable version: https://sourceforge.net/projects/systeminformer/files/systeminformer-3.2.25011-release-bin.zip/download
I use it all the time.

It evolved from Process Hacker: https://processhacker.sourceforge.io/downloads.php
-Ibrahim Mihai


All times are GMT +8. The time now is 12:07.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX