![]() |
|
#1
|
||||
|
||||
|
Remora Hook
hi,
I just open-sourced my tool: Remora Hook. Win64 API monitor that hooks a target process using Export Address Table (EAT) and Import Address Table (IAT) patching -- no code modification on API bodies, no debugger attachment. Works with both normally compiled executables and heavily obfuscated, packed binaries with multiple unpacking layers, so you get a useful API log without fighting the protector first. There is also a short demo GIF on the website showing it in action. https://github.com/arkup/remora |
| The Following 6 Users Say Thank You to cyberbob For This Useful Post: | ||
bolo2002 (09-05-2026), CRC32 (09-06-2026), Fyyre (09-06-2026), Gyrus (09-06-2026), MarcElBichon (09-05-2026), user_hidden (09-05-2026) | ||
|
#2
|
|||
|
|||
|
Question about your ArkDasm here: https://forum.exetools.com/showthrea...e=2#post135940
|
|
#3
|
||||
|
||||
|
Quote:
v2.0 is missing debugger integration, so Ghidra is ahead there |
| The Following User Says Thank You to cyberbob For This Useful Post: | ||
MarcElBichon (09-06-2026) | ||
![]() |
| Thread Tools | |
| Display Modes | |
|
|