<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/css" href="http://www.woodmann.com/collaborative/tools/skins/common/feed.css?97"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title>Collaborative RCE Tool Library - Categorized by Target Type (including sub-categories)</title>
		<link>http://www.woodmann.com/collaborative/tools/index.php/Special:FeedListing/Categorized_by_Target_Type/feed?recursive=1&amp;feed_type=rss</link>
		<description>Update Notification Feed for Category: Categorized by Target Type (and its sub-categories)</description>
		<language>en</language>
		<generator>MediaWiki 1.11.2 via dELTA feed generator</generator>
		<lastBuildDate>Sat, 21 Nov 2009 07:53:29 GMT</lastBuildDate>
		<item>
			<title>Tool Updated: CFF Explorer</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/CFF_Explorer</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:.NET_Executable_Editors&quot;&gt;.NET Executable Editors&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:PE_Executable_Editors&quot;&gt;PE Executable Editors&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;7.4.0.1&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;November 10, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;The CFF Explorer was designed to make PE editing as easy as possible, but without losing sight on the portable executable's internal structure. This application includes a series of tools which might help not only reverse engineers but also programmers. It offers a multi-file environment and a switchable interface.&lt;br /&gt;&lt;br /&gt;Also, it's the first PE editor with full support for the .NET file format. With this tool you can easily edit metadata's fields and flags. If you're programming something that has to do with .NET metadata, you will need this tool. The resource viewer supports .NET image formats like icons, bitmaps, pngs. You'll be able to analyze .NET files without having to install the .NET framework, this tool has its own functions to access the .NET format.&lt;br /&gt;&lt;br /&gt;Also includes a cool new scripting engine!&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Tue, 10 Nov 2009 18:26:13 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: Radare</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/Radare</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:.NET_Disassemblers&quot;&gt;.NET Disassemblers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Assemblers&quot;&gt;Assemblers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Binary_Diff_Tools&quot;&gt;Binary Diff Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Code_Injection_Tools&quot;&gt;Code Injection Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Debuggers&quot;&gt;Debuggers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Disassemblers&quot;&gt;Disassemblers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Hex_Editors&quot;&gt;Hex Editors&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Java_Disassembler_Libraries&quot;&gt;Java Disassembler Libraries&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Linux_Debuggers&quot;&gt;Linux Debuggers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Linux_Disassemblers&quot;&gt;Linux Disassemblers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Linux_Tools&quot;&gt;Linux Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Memory_Dumpers&quot;&gt;Memory Dumpers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Memory_Patchers&quot;&gt;Memory Patchers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Process_Dumpers&quot;&gt;Process Dumpers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Reverse_Engineering_Frameworks&quot;&gt;Reverse Engineering Frameworks&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Ring_3_Debuggers&quot;&gt;Ring 3 Debuggers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:String_Finders&quot;&gt;String Finders&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Symbol_Retrievers&quot;&gt;Symbol Retrievers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:SysCall_Monitoring_Tools&quot;&gt;SysCall Monitoring Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Tracers&quot;&gt;Tracers&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.4.1&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;November 3, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;&amp;lt;nowiki&amp;gt;The radare project aims to provide a complete unix-like toolchain for working with binary files. It currently provides a set of tools to work with x86, arm and java with some ones powerpc.&lt;br /&gt;&lt;br /&gt;The core is a raw hexadecimal editor for commandline with scripting features and perl/python extensions that gets extended with IO plugins that hooks the open/read/write/close/system calls.&lt;br /&gt;&lt;br /&gt;The debugger and disassembler has a code analysis module for x86, mips, arm and java. This way it's possible to draw graphs using Cairo on a GTK window or store the flow execution of a program on a log file and use the information to diff't against another trace or binary.&lt;br /&gt;&lt;br /&gt;The toolchain provides assemblers and disasemblers for x86, arm, mips (Loongson2F), sparc, CSR, m68k, powerpc, msil and java.&lt;br /&gt;&lt;br /&gt;The disassembler has been enhaced to handle inline comments, code block detections and flag references (data pointers or so).&lt;br /&gt;&lt;br /&gt;The debugger is mainly developed on linux and {Net&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Wed, 04 Nov 2009 09:18:47 GMT</pubDate>								</item>
		<item>
			<title>Tool Added: FoxPro file manager - Total Commander plugin</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/FoxPro_file_manager_-_Total_Commander_plugin</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:FoxPro_Tools&quot;&gt;FoxPro Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;0.95&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;25.10.2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;

&lt;/p&gt;</description>
			<pubDate>Mon, 02 Nov 2009 18:15:02 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: VBReFormer</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/VBReFormer</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Visual_Basic_Decompilers&quot;&gt;Visual Basic Decompilers&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;

&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;

&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Good VB decompiler.&lt;br /&gt;&lt;br /&gt;The attached older trial version (3.7) was the last demo version of VBReformer that allowed changes to be re-compiled, although it is a decompiler of dubious worth, it's main useful purpose that I have found is in changing forms and dialog boxes - enabling grayed out functions, inserting text and enabling non working functions - it only will work with native VB apps it will not work with P-code, I've found it more useful than Olly and Smartcheck for instance you MAY be able to disable a serial number check. As you work with it you'll appreciate it's simplicity. Oh, and it will default to install in French, but the language can be changed under the &amp;quot;Fichier&amp;quot; menu.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Wed, 02 Sep 2009 11:13:54 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: Process Hacker</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/Process_Hacker</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Malware_Analysis_Tools&quot;&gt;Malware Analysis Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Process_Monitoring_Tools&quot;&gt;Process Monitoring Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.4&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;August 22, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Process Hacker is a feature-packed tool for manipulating processes and services on your computer.&lt;br /&gt;&lt;br /&gt;Key features of Process Hacker:&lt;br /&gt;- A simple, customizable tree view with highlighting showing you the processes running on your computer.&lt;br /&gt;&lt;br /&gt;- Detailed performance graphs.&lt;br /&gt;&lt;br /&gt;- A complete list of services and full control over them (start, stop, pause, resume and delete).&lt;br /&gt;&lt;br /&gt;- A list of network connections.&lt;br /&gt;&lt;br /&gt;- Comprehensive information for all processes: full process performance history, thread listing and stacks with dbghelp symbols, token information, module and mapped file information, virtual memory map, environment variables, handles, ...&lt;br /&gt;&lt;br /&gt;- Full control over all processes, even processes protected by rootkits or security software. Its kernel-mode driver has unique abilities which allows it to terminate, suspend and resume all processes and threads, including software like IceSword, avast! anti-virus, AVG Antivirus, COMODO Internet Security, etc. (just to name a few).&lt;br /&gt;&lt;br /&gt;- Find hidden processes and terminate them. Process Hacker detects processes hidden by simple rootkits such as Hacker Defender and FU.&lt;br /&gt;&lt;br /&gt;- Easy DLL injection and unloading - simply right-click a process and select &amp;quot;Inject DLL&amp;quot; to inject and right-click a module and select &amp;quot;Unload&amp;quot; to unload!&lt;br /&gt;&lt;br /&gt;- Many more features...&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Sat, 22 Aug 2009 13:51:09 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: Explorer Suite</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/Explorer_Suite</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:.NET_Executable_Editors&quot;&gt;.NET Executable Editors&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:.NET_Resource_Editors&quot;&gt;.NET Resource Editors&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:.NET_Signature_Removers&quot;&gt;.NET Signature Removers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:.NET_Tools&quot;&gt;.NET Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Dependency_Analyzer_Tools&quot;&gt;Dependency Analyzer Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Exe_Analyzers&quot;&gt;Exe Analyzers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Executable_CRC_Calculators&quot;&gt;Executable CRC Calculators&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Hex_Editors&quot;&gt;Hex Editors&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Import_Editors&quot;&gt;Import Editors&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Memory_Dumpers&quot;&gt;Memory Dumpers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:PE_Executable_Editors&quot;&gt;PE Executable Editors&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Process_Dumpers&quot;&gt;Process Dumpers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Protection_Identifiers&quot;&gt;Protection Identifiers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Resource_Editors&quot;&gt;Resource Editors&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;III&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;August 19, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;A freeware suite of tools including a PE editor called CFF Explorer and a process viewer. The PE editor has full support for PE32/64. Special fields description and modification (.NET supported), utilities, rebuilder, hex editor, import adder, signature scanner, signature manager, extension support, scripting, disassembler, dependency walker etc. First PE editor with support for .NET internal structures. Resource Editor (Windows Vista icons supported) capable of handling .NET manifest resources. The suite is available for x86, x64 and Itanium.&lt;br /&gt;&lt;br /&gt;Features:&lt;br /&gt;&lt;br /&gt;    * Process Viewer&lt;br /&gt;    * Windows Viewer&lt;br /&gt;    * PE and Memory Dumper&lt;br /&gt;    * Full support for PE32/64&lt;br /&gt;    * Special fields description and modification (.NET supported)&lt;br /&gt;    * PE Utilities&lt;br /&gt;    * PE Rebuilder (with Realigner, IT Binder, Reloc Remover, Strong Name Signature Remover, Image Base Changer)&lt;br /&gt;    * View and modification of .NET internal structures&lt;br /&gt;    * Resource Editor (full support for Windows Vista icons)&lt;br /&gt;    * Support in the Resource Editor for .NET resources (dumpable as well)&lt;br /&gt;    * Hex Editor&lt;br /&gt;    * Import Adder&lt;br /&gt;    * PE integrity checks&lt;br /&gt;    * Extension support&lt;br /&gt;    * Visual Studio Extensions Wizard&lt;br /&gt;    * Powerful scripting language&lt;br /&gt;    * Dependency Walker&lt;br /&gt;    * Quick Disassembler (x86, x64)&lt;br /&gt;    * Name Unmangler&lt;br /&gt;    * Extension support&lt;br /&gt;    * File Scanner&lt;br /&gt;    * Directory Scanner&lt;br /&gt;    * Deep Scan method&lt;br /&gt;    * Recursive Scan method&lt;br /&gt;    * Multiple results&lt;br /&gt;    * Report generation&lt;br /&gt;    * Signatures Manager&lt;br /&gt;    * Signatures Updater&lt;br /&gt;    * Signatures Collisions Checker&lt;br /&gt;    * Signatures Retriever&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Wed, 19 Aug 2009 15:45:19 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: Dotnet IL Editor (DILE)</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/Dotnet_IL_Editor_%28DILE%29</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:.NET_Debuggers&quot;&gt;.NET Debuggers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:.NET_Disassemblers&quot;&gt;.NET Disassemblers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:.NET_Executable_Editors&quot;&gt;.NET Executable Editors&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;0.2.6&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;September 30, 2007&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Dotnet IL Editor (DILE) is an editor program which helps modifying .NET assemblies. It is intended to be able to disassemble .NET assemblies, modify the IL code, recompile it and run inside a debugger.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Sun, 09 Aug 2009 13:13:28 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: IDA Pro</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/IDA_Pro</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:.NET_Disassemblers&quot;&gt;.NET Disassemblers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Disassemblers&quot;&gt;Disassemblers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:IPhone_Tools&quot;&gt;IPhone Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Linux_Debuggers&quot;&gt;Linux Debuggers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Linux_Disassemblers&quot;&gt;Linux Disassemblers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Mobile_Platform_Debuggers&quot;&gt;Mobile Platform Debuggers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Mobile_Platform_Disassemblers&quot;&gt;Mobile Platform Disassemblers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Ring_3_Debuggers&quot;&gt;Ring 3 Debuggers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Symbian_Tools&quot;&gt;Symbian Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;5.5&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;June 15, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;The IDA Pro Disassembler and Debugger is an interactive, programmable, extendible, multi-processor disassembler hosted on Windows or on Linux. IDA Pro has become the de-facto standard for the analysis of hostile code, vulnerability research and COTS validation.&lt;br /&gt;&lt;br /&gt;There is also a free (crippled) version available (IDA Pro Free). See its own entry in the library for more info.&lt;br /&gt;&lt;br /&gt;As of January 7, 2007, the official IDA Pro website moved from the old URL (http://www.datarescue.com/idabase) to the one listed above.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Thu, 06 Aug 2009 16:22:01 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: WinApiOverride</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/WinApiOverride</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:.NET_Tracers&quot;&gt;.NET Tracers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:API_Monitoring_Tools&quot;&gt;API Monitoring Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:COM_Monitoring_Tools&quot;&gt;COM Monitoring Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;5.1.11&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;July 18, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;WinAPIOverride32 is an advanced api monitoring software.&lt;br /&gt;You can monitor and/or override any function of a process.&lt;br /&gt;This can be done for API functions or executable internal functions.&lt;br /&gt;&lt;br /&gt;It tries to fill the gap between classical API monitoring softwares and debuggers.&lt;br /&gt;It can break targeted application before or after a function call, allowing memory or registers changes; and it can directly call functions of the targeted application.&lt;br /&gt;Main differences between other API monitoring softwares :&lt;br /&gt;  - You can define filters on parameters or function result&lt;br /&gt;  - You can define filters on dll to discard calls from windows system dll&lt;br /&gt;  - You can hook functions inside the target process not only API&lt;br /&gt;  - You can hook asm functions with parameters passed through registers&lt;br /&gt;  - Double and float results are logged&lt;br /&gt;  - Preserve registers, floating stack and LastError&lt;br /&gt;  - You can easily override any API or any process internal function&lt;br /&gt;  - You can break process before or/and after function call to change memory or registers&lt;br /&gt;  - You can call functions which are inside the remote processes&lt;br /&gt;  - Can hook COM OLE and ActiveX interfaces&lt;br /&gt;  - All is is done like modules : you can log or override independently for any function&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Sun, 19 Jul 2009 05:08:24 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: MyAut2Exe</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/MyAut2Exe</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Installer_Decompilers&quot;&gt;Installer Decompilers&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;2.07&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;July 18, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;AutoIT Script Decompiler&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Sun, 19 Jul 2009 05:02:05 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: DE Decompiler</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/DE_Decompiler</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Decompilers&quot;&gt;Decompilers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Delphi_Decompilers&quot;&gt;Delphi Decompilers&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;2.0 (updated)&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;July 18, 2008&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;DE Decompiler is the unique solution for decompiling the Delphi generated programs (EXE, DLL, OCX). As you know the Delphi programs is the native win32 executable files.&lt;br /&gt;&lt;br /&gt;DE Decompiler restores most parts of the compiled code and helps you to recover most parts of the lost sources. It contans the powerful disassembler which supports Pentium Pro commands including MMX and SSE extensions. Also it has a useful smart assembler code emulation engine. The build-in disassembler allows you to disassemble a lots of functions and represents it in semi-decompiled mode. DE Decompiler has a wonderful code analyzer which makes your work easy and fast. In addition to all it can search for all the API function's calls and the string references in the disassembled code and comment them out for analyzed strings.&lt;br /&gt;&lt;br /&gt;If you lost your source codes - DE Decompiler save your time and helps you to restore it.&lt;br /&gt;&lt;br /&gt;In general, DE Decompiler is the ideal tool for analyzing programs and it is perfect if you lose your source code and need to partially restore the project.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Sun, 19 Jul 2009 05:00:29 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: Reflector for .NET</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/Reflector_for_.NET</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:.NET_Decompilers&quot;&gt;.NET Decompilers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:.NET_Disassemblers&quot;&gt;.NET Disassemblers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Decompilers&quot;&gt;Decompilers&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;5.1.4.0&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;July 18, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;From website:&lt;br /&gt;&lt;br /&gt;&amp;quot;Reflector is a very powerful class browser, explorer, analyzer and documentation viewer for .NET. Reflector allows to easily view, navigate, search, decompile and analyze .NET assemblies in C#, Visual Basic and IL.&amp;quot;&lt;br /&gt;&lt;br /&gt;This is one of the most powerful .NET decompilers that you can't buy - just download :)&lt;br /&gt;Many of the popular commercial tools achieving the same goal &amp;quot;suddenly&amp;quot; got a boost when this masterpiece of work saw a daylights (and besides that those are commercial, still have hard time with obfuscators).&lt;br /&gt;&lt;br /&gt;Just give it a try, it will last literally five minutes - load some well known assembly of yours, choose target .NET language (!) and let'em work. Then compare it with the original.&lt;br /&gt;&lt;br /&gt;You'll surely not forget this one.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Sun, 19 Jul 2009 04:59:56 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: PEBrowse Professional</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/PEBrowse_Professional</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:.NET_Disassemblers&quot;&gt;.NET Disassemblers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:.NET_Tools&quot;&gt;.NET Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:COM_Tools&quot;&gt;COM Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Delphi_Tools&quot;&gt;Delphi Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Disassemblers&quot;&gt;Disassemblers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Exe_Analyzers&quot;&gt;Exe Analyzers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Memory_Dumpers&quot;&gt;Memory Dumpers&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;10.0.1&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;July 12, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;PEBrowse Professional is a static-analysis tool and disassembler for Win32/Win64 executables and Microsoft .NET assemblies produced according to the Portable Executable specifications published by Microsoft.  For Microsoft Windows Vista, Windows XP, Windows 2000, and others.  (We have received reports that the software also works on other OSes, including Wine (!) and Windows CE.)&lt;br /&gt;&lt;br /&gt;With the PEBrowse disassembler, one can open and examine any executable without the need to have it loaded as part of an active process with a debugger.  Applications, system DLLs, device-drivers and Microsoft .NET assemblies are all candidates for offline analysis using PEBrowse.  The information is organized in a convenient treeview index with the major divisions of the PE file displayed as nodes.  In most cases selecting nodes will enable context-sensitive multiple view menu options, including binary dump, section detail, disassembly and structure options as well as displaying sub-items, such as optional header directory entries or exported functions, that can be found as part of a PE file unit.  Several table displays, hex/ASCII equivalents, window messages and error codes, as well as a calculator and scratchpads are accessible from the main menu. &lt;br /&gt;&lt;br /&gt; While the binary dump display offers various display options, e.g., BYTE, WORD, or DWORD alignment, the greatest value of PEBrowse comes when one disassembles an entry-point.  An entry-point in PEBrowse is defined as:&lt;br /&gt;&lt;br /&gt;    * Module entry-point&lt;br /&gt;    * Exports (if any)&lt;br /&gt;    * Debug-symbols (if a valid PDB, i.e., program database file, is present)&lt;br /&gt;    * Imported API references&lt;br /&gt;    * Relocation addresses&lt;br /&gt;    * Internal functions/subroutines&lt;br /&gt;    * Any valid address inside of the module&lt;br /&gt;&lt;br /&gt;Selecting and disassembling any number of these entry-points produces a versatile display rich in detail including upper/lowercase display, C/Pascal/Assembler suffix/prefixing, object code, color-coded statements, register usage highlighting, and jump/call target preview popups.  Additional information, such as variable and function names, will also be present if one has access to a valid PDB file.  Disassembly comes in two flavors: linear sweep (sequential disassembly from a starting address) and recursive traversal, aka, analysis mode (disassembly of all statements reachable by non-call statements - extended analysis disassembles all internal call statements as well).  The latter mode also presents local variables with cross-referencing, highlighting, and renaming options.  If one adds/changes variable name or adds comments to specific lines, these can be displayed in a session file which will record and save all currently opened displays.&lt;br /&gt;&lt;br /&gt;PEBrowse Professional will decompile type library information either embedded inside of the binary as the resource &amp;quot;TYPELIB&amp;quot; or inside of individual type libraries, i.e., .TLB or .OLB files.&lt;br /&gt;&lt;br /&gt;PEBrowse Professional also displays all metadata for .NET assemblies and displays IL (Intermediate Language) for .NET methods.  It seamlessly handles mixed assemblies, i.e., those that contain both native and managed code.&lt;br /&gt;&lt;br /&gt;Finally, PEBrowse can be employed as a file browse utility for any type of file with the restriction that the file must be small enough that it can be memory-mapped.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Sat, 18 Jul 2009 23:05:32 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: VB Decompiler</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/VB_Decompiler</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Decompilers&quot;&gt;Decompilers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Visual_Basic_Decompilers&quot;&gt;Visual Basic Decompilers&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;7.6&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;July 12, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;VB Decompiler is decompiler for programs (EXE, DLL or OCX) written in Visual Basic 5.0/6.0. As you know, programs in Visual Basic can be compiled into interpreted p-code or into native code.&lt;br /&gt;&lt;br /&gt;Since p-code consists of high-level commands, there is a real possibility to decompile it into the source code (of course, the names of variables, functions, etc. will not be decompiled). VB Decompiler  restores many p-code instructions and although there is a long way to the generation of the source code that can be compiled, the decompiler will make analyzing the program algorithm much easier and partially restore its source code.&lt;br /&gt;&lt;br /&gt;If a program was compiled into the native code, restoring the source code from machine instructions is not possible. But VB decompiler can help to analyze the program even in this situation as well. It contains a powerful disassembler that supports Pentium Pro commands including MMX and SSE. It allows you to disassemble all functions. There is also a code analyzer that searches for all API function calls and string references in the disassembled code and changes them into comments for analyzed strings. In general, VB Decompiler is an ideal tool for analyzing programs and it is perfect if you lose the source code and need to partially restore the project.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Sun, 12 Jul 2009 19:56:38 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: EDB Linux Debugger</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/EDB_Linux_Debugger</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Debuggers&quot;&gt;Debuggers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Linux_Debuggers&quot;&gt;Linux Debuggers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Ring_3_Debuggers&quot;&gt;Ring 3 Debuggers&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;0.9.10&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;July 8, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Features&lt;br /&gt;    * Intuitive GUI interface&lt;br /&gt;    * The usual debugging operations (step-into/step-over/run/break)&lt;br /&gt;    * Conditional breakpoints&lt;br /&gt;    * Debugging core is implemented as a plugin so people can have drop in replacements. Of course if a given platform has several debugging APIs available, then you may have a plugin that implements any of them.&lt;br /&gt;    * Basic instruction analysis&lt;br /&gt;    * View/Dump memory regions&lt;br /&gt;    * Effective address inspection&lt;br /&gt;    * The data dump view is tabbed, allowing you to have several views of memory open at the same time and quickly switch between them.&lt;br /&gt;    * Importing of symbol maps&lt;br /&gt;    * Plugins&lt;br /&gt;          o Search for binary strings&lt;br /&gt;          o Code Bookmarks&lt;br /&gt;          o Breakpoint management&lt;br /&gt;          o Check for updates&lt;br /&gt;          o Environment variable viewer&lt;br /&gt;          o Heap block enumeration&lt;br /&gt;          o Opcode search engine plugin has basic functionality (similar to msfelfscan/msfpescan)&lt;br /&gt;          o Open file enumeration&lt;br /&gt;          o Reference finder&lt;br /&gt;          o String searching (like strings command in *nix)&lt;br /&gt;&lt;br /&gt;One of the main goals of this debugger is isolation of the debugger core from the display you see. The interface is written in QT4 and thus source portable to many platforms. The debugger core is actually a plugin and the platform specific code is isolated to just a few files, porting to a new OS would require porting these few files and implementing a plugin which implements the &amp;quot;DebuggerCoreInterface&amp;quot; interface. Also, because the plugins are based on the QPlugin API, and do their work through the DebuggerCoreInterface object, they are almost always portable with just a simple recompile. So far, the only plugin I have written which would not port with just a recompile is the heap analysis plugin, due to it's highly system specific nature.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Thu, 09 Jul 2009 01:47:28 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: PIX with callstack patch</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/PIX_with_callstack_patch</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:API_Monitoring_Tools&quot;&gt;API Monitoring Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:DirectX_Tools&quot;&gt;DirectX Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;

&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;July 3, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;MSDN describes the DirectX tool &amp;quot;PIX&amp;quot; as follows (at http://msdn.microsoft.com/en-us/library/bb173085(VS.85).aspx):&lt;br /&gt;&amp;quot;PIX is a debugging and analysis tool that captures detailed information from a Direct3D application as it executes. PIX can be configured to gather data, such as the list of Direct3D APIs called, timing information, mesh vertices before and after transformations, screenshots, and select statistics. PIX can also be used for debugging vertex and pixel shaders, including setting breakpoints and stepping through shader code.&amp;quot;&lt;br /&gt;&lt;br /&gt;Thus, a highly useful tool right from the MS DirectX SDK for e.g. finding the cause of a rendering problem: for any captured frame, you can click through the executed DX API functions and see how the frame is being built up, eventually finding out what part is to blame.&lt;br /&gt;&lt;br /&gt;But what about reversing a closed source application's renderer? PIX does not store a call stack; it merely logs *what* DX functions are called, but not from *where*. Therefore it is not very useful for reversing by default.&lt;br /&gt;&lt;br /&gt;I didn't want to let such a great tool go to waste. After some reversing work I ended up patching PIX to log and show (part of) the call stack for each DirectX call that the target program makes. Each call stack entry has both the virtual address and the module name.&lt;br /&gt;&lt;br /&gt;Example usage of the resulting modified tool is finding out about and messing with a game's renderer, or more simply locating the HUD rendering code and quickly finding the data that it represents (e.g. health, money) rather than having to resort to memory scanning.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Fri, 03 Jul 2009 20:33:40 GMT</pubDate>								</item>
		<item>
			<title>Tool Added: BDS S.I.C.K</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/BDS_S.I.C.K</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Delphi_Tools&quot;&gt;Delphi Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Exe_Analyzers&quot;&gt;Exe Analyzers&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;

&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;March 26, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;BDS S.I.C.K (Some Info Collection Kit) is a tool designed to help you to analyze compiled Delphi applications. It may be helpful when you need to know what units are inside, used classes, methods and the addresses. When you know this you can open it with your favorite disassembler or debugger and explore it. You don't need to vaste time for routine work.&lt;br /&gt;&lt;br /&gt;    * SICK has simple internal disassembler for quick analysis.&lt;br /&gt;    * Collecting info about objects, forms and classes.&lt;br /&gt;    * Objects are represented in tree form, so you can easily navigate&lt;br /&gt;    * Search objects by full or partial name (F3 in objects window)&lt;br /&gt;    * Exporting names and procedures to IDA&lt;br /&gt;    * Supporting all Win32 Delphi editions&lt;br /&gt;&lt;br /&gt;Features to be added:&lt;br /&gt;&lt;br /&gt;    * Improving classes info collection&lt;br /&gt;    * Smart functions disassembly (analysis during disassembly)&lt;br /&gt;    * Plugins API (in development)&lt;br /&gt;    * VCL recognition (allow recognize well known functions)&lt;br /&gt;    * Reading PACKAGE info and some stuff from resources.&lt;br /&gt;&lt;br /&gt;This tool is developed to be used with clean Delphi executables.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Sun, 28 Jun 2009 13:09:17 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: Dedexer</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/Dedexer</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Mobile_Platform_Disassemblers&quot;&gt;Mobile Platform Disassemblers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Mobile_Platform_Tools&quot;&gt;Mobile Platform Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Needs_New_Category&quot;&gt;Needs New Category&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.4&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;June 25, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;&amp;quot;Dedexer is a disassembler tool for DEX files. DEX is a format introduced by the creators of the Android platform. The format and the associated opcode set is in distant relationship with the Java class file format and Java bytecodes. Dedexer is able to read the DEX format and turn into an &amp;quot;assembly-like format&amp;quot;. This format was largely influenced by the Jasmin syntax but contains Dalvik opcodes. For this reason, Jasmin is not able to compile the generated files.&amp;quot;&lt;br /&gt;&lt;br /&gt;Needs new category&lt;br /&gt;This is a tool for Android dex files.  There should be an Android tools category like the iPhone, Symbian, and Blackberry categories.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Fri, 26 Jun 2009 04:01:54 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: CSharpFuscator</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/CSharpFuscator</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:.NET_Packers&quot;&gt;.NET Packers&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.0&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;June 24, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;The CSharpFuscator tool scrambles .NET source code to make it very difficult to understand or reverse-engineer. This provides significant protection for source code intellectual property, and even provides protection against the all-too-disassembly of .NET object code.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Thu, 25 Jun 2009 00:44:49 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: Kernel Detective</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/Kernel_Detective</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Hook_Detection_Tools&quot;&gt;Hook Detection Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Kernel_Hook_Detection_Tools&quot;&gt;Kernel Hook Detection Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Kernel_Tools&quot;&gt;Kernel Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Malware_Analysis_Tools&quot;&gt;Malware Analysis Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.3.0&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;June 20, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Kernel Detective is a free tool that help you detect, analyze, manually modify and fix some Windows NT kernel modifications. Kernel Detective gives you the access to the kernel directly so it's not oriented for newbies. Changing essential kernel-mode objects without enough knowledge will lead you to only one result ... BSoD !&lt;br /&gt;&lt;br /&gt;Supported NT versions :&lt;br /&gt;XP/Vista&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Kernel Detective gives you the ability to :&lt;br /&gt;1- Detect Hidden Processes.&lt;br /&gt;3- Detect Hidden Threads.&lt;br /&gt;2- Detect Hidden DLLs.&lt;br /&gt;3- Detect Hidden Handles.&lt;br /&gt;4- Detect Hidden Driver.&lt;br /&gt;5- Detect Hooked SSDT.&lt;br /&gt;6- Detect Hooked Shadow SSDT.&lt;br /&gt;7- Detect Hooked IDT.&lt;br /&gt;8- Detect Kernel-mode code modifications and hooks.&lt;br /&gt;9- Disassemble (Read/Write) Kernel-mode/User-mode memory.&lt;br /&gt;10- Monitor debug output on your system.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Enumerate running processes and print important values like Process Id, Parent Process Id, ImageBase, EntryPoint, VirtualSize, PEB block address and EPROCESS block address. Special undocumented detection algorithms were implemented to detect hidden processes.&lt;br /&gt;&lt;br /&gt;Detect hidden and suspicious threads in system and allow user to forcely terminate them .&lt;br /&gt;&lt;br /&gt;Enumerate a specific running process Dynamic-Link Libraries and show every Dll ImageBase, EntryPoint, Size and Path. You can also inject or free specific module.&lt;br /&gt;&lt;br /&gt;Enumerate a specific running process opened handles, show every handle's object name and address and give you the ability to close the handle.&lt;br /&gt;&lt;br /&gt;Enumerate loaded kernel-mode drivers and show every driver ImageBase, EntryPoint, Size, Name and Path. Undocumented detection algorithms were implemented to detect hidden drivers.&lt;br /&gt;&lt;br /&gt;Scan the system service table (SSDT) and show every service function address and the real function address, detection algorithm improved to bypass KeServiceDescriptorTable EAT/IAT hooks.You can restore single service function address or restore the whole table.&lt;br /&gt;&lt;br /&gt;Scan the shadow system service table (Shadow SSDT) and show every shadow service function address and the real function address. You can restore single shadow service function address or restore the whole table&lt;br /&gt;&lt;br /&gt;Scan the interrupts table (IDT) and show every interrupt handler offset, selector, type, Attributes and real handler offset. This is applied to every processor in a multi-processors machines.&lt;br /&gt;&lt;br /&gt;Scan the important system kernel modules, detect the modifications in it's body and analyze it. For now it can detect and restore inline code modifications, EAT and IAT hooks. I'm looking for more other types of hooks next releases of Kernel Detective.&lt;br /&gt;&lt;br /&gt;A nice disassembler rely on OllyDbg disasm engine, thanks Oleh Yuschuk for publishing your nice disasm engine .With it you can disassemble, assemble and hex edit virtual memory of a specific process or even the kernel space memory. Kernel Detective use it's own Read/Write routines from kernel-mode and doesn't rely on any windows API. That make Kernel Detective able to R/W processes VM even if NtReadProcessMemory/NtWriteProcessMemory is hooked, also bypass the hooks on other kernel-mode important routines like KeStackAttachProcess and KeAttachProcess.&lt;br /&gt;&lt;br /&gt;Show the messages sent by drivers to the kernel debugger just like Dbgview by Mark Russinovich. It's doing this by hooking interrupt 0x2d wich is responsible for outputing debug messages. Hooking interrupts may cause problems on some machines so DebugView is turned off by default, to turn it on you must run Kernel Detective with &amp;quot;-debugv&amp;quot; parameter.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Sat, 20 Jun 2009 17:36:45 GMT</pubDate>								</item>
	</channel>
</rss>