![]() |
Remora Hook
hi,
I just open-sourced my tool: Remora Hook. Win64 API monitor that hooks a target process using Export Address Table (EAT) and Import Address Table (IAT) patching -- no code modification on API bodies, no debugger attachment. Works with both normally compiled executables and heavily obfuscated, packed binaries with multiple unpacking layers, so you get a useful API log without fighting the protector first. There is also a short demo GIF on the website showing it in action. https://github.com/arkup/remora |
Question about your ArkDasm here: https://forum.exetools.com/showthrea...e=2#post135940
|
Quote:
v2.0 is missing debugger integration, so Ghidra is ahead there |
| All times are GMT +8. The time now is 07:45. |
Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX