<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/css" href="http://www.woodmann.com/collaborative/tools/skins/common/feed.css?97"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://www.woodmann.com/collaborative/tools/index.php/Special:FeedListing/Monitoring_Tools/feed?recursive=1&amp;feed_type=atom</id>
		<title>Collaborative RCE Tool Library - Monitoring Tools (including sub-categories)</title>
		<link rel="self" type="application/atom+xml" href="http://www.woodmann.com/collaborative/tools/index.php/Special:FeedListing/Monitoring_Tools/feed?recursive=1&amp;feed_type=atom"/>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/Special:FeedListing/Monitoring_Tools/feed?recursive=1&amp;feed_type=atom"/>
		<updated>2009-11-21T11:46:22Z</updated>
		<subtitle>Update Notification Feed for Category: Monitoring Tools (and its sub-categories)</subtitle>
		<generator>MediaWiki 1.11.2 via dELTA feed generator</generator>

	<entry>
		<id>http://www.woodmann.com/collaborative/tools/index.php/Regshot_Unicode</id>
		<title>Tool Updated: Regshot Unicode</title>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/Regshot_Unicode"/>
				<updated>2009-11-10T06:46:09Z</updated>
		
		<summary type="html">&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Registry_Diff_Tools&quot;&gt;Registry Diff Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Registry_Monitoring_Tools&quot;&gt;Registry Monitoring Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;2.0.1.68 Unicode&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;November 9, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Regshot is a small, free and open source (GPL) registry compare utility that allows you to quickly take a snapshot of your registry and then compare it with a second one - done after doing system changes or installing a new software product. The changes report can be produced in text or HTML format and contains a list of all modifications that have taken place between snapshot1 and snapshot2. In addition, you can also specify folders (with sub filders) to be scanned for changes as well.&lt;/i&gt;
&lt;/p&gt;</summary>
			</entry>

	<entry>
		<id>http://www.woodmann.com/collaborative/tools/index.php/Radare</id>
		<title>Tool Updated: Radare</title>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/Radare"/>
				<updated>2009-11-04T09:18:47Z</updated>
		
		<summary type="html">&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:.NET_Disassemblers&quot;&gt;.NET Disassemblers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Assemblers&quot;&gt;Assemblers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Binary_Diff_Tools&quot;&gt;Binary Diff Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Code_Injection_Tools&quot;&gt;Code Injection Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Debuggers&quot;&gt;Debuggers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Disassemblers&quot;&gt;Disassemblers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Hex_Editors&quot;&gt;Hex Editors&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Java_Disassembler_Libraries&quot;&gt;Java Disassembler Libraries&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Linux_Debuggers&quot;&gt;Linux Debuggers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Linux_Disassemblers&quot;&gt;Linux Disassemblers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Linux_Tools&quot;&gt;Linux Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Memory_Dumpers&quot;&gt;Memory Dumpers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Memory_Patchers&quot;&gt;Memory Patchers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Process_Dumpers&quot;&gt;Process Dumpers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Reverse_Engineering_Frameworks&quot;&gt;Reverse Engineering Frameworks&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Ring_3_Debuggers&quot;&gt;Ring 3 Debuggers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:String_Finders&quot;&gt;String Finders&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Symbol_Retrievers&quot;&gt;Symbol Retrievers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:SysCall_Monitoring_Tools&quot;&gt;SysCall Monitoring Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Tracers&quot;&gt;Tracers&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.4.1&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;November 3, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;&amp;lt;nowiki&amp;gt;The radare project aims to provide a complete unix-like toolchain for working with binary files. It currently provides a set of tools to work with x86, arm and java with some ones powerpc.&lt;br /&gt;&lt;br /&gt;The core is a raw hexadecimal editor for commandline with scripting features and perl/python extensions that gets extended with IO plugins that hooks the open/read/write/close/system calls.&lt;br /&gt;&lt;br /&gt;The debugger and disassembler has a code analysis module for x86, mips, arm and java. This way it's possible to draw graphs using Cairo on a GTK window or store the flow execution of a program on a log file and use the information to diff't against another trace or binary.&lt;br /&gt;&lt;br /&gt;The toolchain provides assemblers and disasemblers for x86, arm, mips (Loongson2F), sparc, CSR, m68k, powerpc, msil and java.&lt;br /&gt;&lt;br /&gt;The disassembler has been enhaced to handle inline comments, code block detections and flag references (data pointers or so).&lt;br /&gt;&lt;br /&gt;The debugger is mainly developed on linux and {Net&lt;/i&gt;
&lt;/p&gt;</summary>
			</entry>

	<entry>
		<id>http://www.woodmann.com/collaborative/tools/index.php/Filter_Monitor</id>
		<title>Tool Updated: Filter Monitor</title>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/Filter_Monitor"/>
				<updated>2009-10-20T21:33:29Z</updated>
		
		<summary type="html">&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Kernel_Filter_Monitoring_Tools&quot;&gt;Kernel Filter Monitoring Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.1.0&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;October 20, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;This utility can list kernel mode filters and also unregister them. Monitored filters are, for instance, registry filters, create process and thread notifications. FilterMon comes both for x64 and x86 and it should work on all Windows systems from Vista RTM to Windows 7 RTM. However, I only tested it on Windows 7 RTM on x64 and I can't guarantee that it will work on future versions of Windows as it relies heavily on system internals.&lt;br /&gt;&lt;br /&gt;As you probably all know the Service Descriptor Table has been a playground on x86 for all sorts of things: rootkits, anti-viruses, system monitors etc. On x64 modifying the Service Descriptor Table is no longer possible, at least not without subverting the Patch Guard technology.&lt;br /&gt;&lt;br /&gt;Thus, programs have now to rely on the filtering/notification technologies provided by Microsoft. And that's why I wrote this little utility which monitors some key filters.&lt;br /&gt;&lt;br /&gt;Since I haven't signed the driver of my utility, you have to press F8 at boot time and then select the &amp;quot;Disable Driver Signature Enforcement&amp;quot; option. If you have a multiple boot screen like myself, then you can take your time. Otherwise you have to press F8 frenetically to not miss right moment.&lt;/i&gt;
&lt;/p&gt;</summary>
			</entry>

	<entry>
		<id>http://www.woodmann.com/collaborative/tools/index.php/Process_Monitor</id>
		<title>Tool Updated: Process Monitor</title>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/Process_Monitor"/>
				<updated>2009-09-19T12:30:27Z</updated>
		
		<summary type="html">&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:File_Monitoring_Tools&quot;&gt;File Monitoring Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Process_Monitoring_Tools&quot;&gt;Process Monitoring Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Registry_Monitoring_Tools&quot;&gt;Registry Monitoring Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;2.7&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;September 18, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Process Monitor is an advanced monitoring tool for Windows that shows real-time file system, Registry and process/thread activity. It combines the features of two legacy Sysinternals utilities, Filemon and Regmon, and adds an extensive list of enhancements including rich and non-destructive filtering, comprehensive event properties such session IDs and user names, reliable process information, full thread stacks with integrated symbol support for each operation, simultaneous logging to a file, and much more. Its uniquely powerful features will make Process Monitor a core utility in your system troubleshooting and malware hunting toolkit.&lt;/i&gt;
&lt;/p&gt;</summary>
			</entry>

	<entry>
		<id>http://www.woodmann.com/collaborative/tools/index.php/GMER</id>
		<title>Tool Updated: GMER</title>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/GMER"/>
				<updated>2009-09-15T21:44:21Z</updated>
		
		<summary type="html">&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Kernel_Hook_Detection_Tools&quot;&gt;Kernel Hook Detection Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.0.15.15087&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;September 15, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;GMER is an application that detects and removes  rootkits .&lt;br /&gt;&lt;br /&gt;It scans for:&lt;br /&gt;* Hidden processes&lt;br /&gt;* Hidden threads&lt;br /&gt;* Hidden modules&lt;br /&gt;* Hidden services&lt;br /&gt;* Hidden files&lt;br /&gt;* Hidden Alternate Data Streams&lt;br /&gt;* Hidden registry keys&lt;br /&gt;* Drivers hooking SSDT&lt;br /&gt;* Drivers hooking IDT&lt;br /&gt;* Drivers hooking IRP calls&lt;br /&gt;* Inline hooks&lt;br /&gt;	&lt;br /&gt;	&lt;br /&gt;GMER also allows to monitor the following system functions:&lt;br /&gt;* Processes creating&lt;br /&gt;* Drivers loading&lt;br /&gt;* Libraries loading&lt;br /&gt;* File functions&lt;br /&gt;* Registry entries&lt;br /&gt;* TCP/IP connections&lt;br /&gt;&lt;br /&gt;GMER runs on Windows NT/W2K/XP/VISTA&lt;/i&gt;
&lt;/p&gt;</summary>
			</entry>

	<entry>
		<id>http://www.woodmann.com/collaborative/tools/index.php/TR</id>
		<title>Tool Added: TR</title>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/TR"/>
				<updated>2009-08-30T23:08:03Z</updated>
		
		<summary type="html">&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:16_bit_and_DOS_Tracers&quot;&gt;16 bit and DOS Tracers&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;2.52&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;November 30, 1998&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Advanced tracer for 16 bit x86 code (DOS programs).&lt;br /&gt;&lt;br /&gt;From readme:&lt;br /&gt;&lt;br /&gt;If you have used DEBUG, SYMDEB, TD (Turbo Debugger), CV (CodeView) or SoftICE, you should try TR which has more powerful functions than debuggers mentioned above.&lt;br /&gt;&lt;br /&gt;TR(tracer) is a debugger based on the CPU simulation technology.&lt;br /&gt;&lt;br /&gt;The main features are:&lt;br /&gt;&lt;br /&gt;1. Interpret Mode&lt;br /&gt;&lt;br /&gt;=================&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;  TR runs a program by interpreting its code just like a REAL Intel CPU&lt;br /&gt;&lt;br /&gt;  would, step by step. TR understands every CPU opcode and will give the&lt;br /&gt;&lt;br /&gt;  correct result, without INT1, INT3, DR0-DR8, or protected mode.&lt;br /&gt;&lt;br /&gt;  Theoretically, TR will never be found by any program which is&lt;br /&gt;&lt;br /&gt;  traced, and you can never find a program which can't be traced :-)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;  Traditional debuggers or tracers have too many shortages:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;  (1) Using INT1 and the Trap Flag&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;      Because they use INT1 and TF to step the program, so it's easy&lt;br /&gt;&lt;br /&gt;      to cheat and detect it!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;  (2) Using INT3&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;      These debuggers insert INT3(CCh) into the program's code after every&lt;br /&gt;&lt;br /&gt;      instruction. If the program destroys the INT3 vector or tests&lt;br /&gt;&lt;br /&gt;      itself, the tracer would not work well :-(&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;  (3) SoftICE doesn't use above two methods, but uses 386 hardware&lt;br /&gt;&lt;br /&gt;      interrupts instead. SoftICE is very strong but so easy to be&lt;br /&gt;&lt;br /&gt;      found :(&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;  Overall, traditional debuggers &amp;amp; tracers trace the program using standard&lt;br /&gt;&lt;br /&gt;  tracing methods which can be found in INTEL's CPU manual. They could&lt;br /&gt;&lt;br /&gt;  only trace those programs which haven't any anti-debug code. If the&lt;br /&gt;&lt;br /&gt;  program won't cooperate, they all cannot work well :-( But TR will&lt;br /&gt;&lt;br /&gt;  trace all the programs that the CPU can deal with, even another TR&lt;br /&gt;&lt;br /&gt;  session.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;  On the other hand, traditional debuggers or tracers simply insert a&lt;br /&gt;&lt;br /&gt;  breakpoint into the program and wait until they catch the control back.&lt;br /&gt;&lt;br /&gt;  They don't know whether they will get control back or what the program&lt;br /&gt;&lt;br /&gt;  intends to do. TR runs the program in interpret mode, it controls all&lt;br /&gt;&lt;br /&gt;  things absolutely. Just because of that, TR can set more and more&lt;br /&gt;&lt;br /&gt;  complex breakpoints.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;  Interpret Run is the main difference between TR and all other&lt;br /&gt;&lt;br /&gt;  debuggers, and this is also why TR has a higher performance.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2.Batch File&lt;br /&gt;&lt;br /&gt;============&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;  Although batch is not a new word to you, you can find no one using it&lt;br /&gt;&lt;br /&gt;  in a debugger. In TR, you can put all your commands in a text file and&lt;br /&gt;&lt;br /&gt;  use it just like you execute a DOS batch file. TR as well has a special&lt;br /&gt;&lt;br /&gt;  batch file named &amp;quot;AUTORUN.TR&amp;quot;. Just like its name, this file can be&lt;br /&gt;&lt;br /&gt;  executed automatically every time you start TR.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;3.Magic Offset&lt;br /&gt;&lt;br /&gt;==============&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;  Everyone is used to the &amp;quot;G 100&amp;quot; command which means run and stop at&lt;br /&gt;&lt;br /&gt;  address CS:100. In general, debuggers do it like this: insert a&lt;br /&gt;&lt;br /&gt;  breakpoint(INT3/CC) at CS:100 and GO the program. When the CPU meets&lt;br /&gt;&lt;br /&gt;  the INT3, the program will be stopped. So, the debuggers can only set a&lt;br /&gt;&lt;br /&gt;  breakpoint at current CS and offset 100. But not TR! TR can stop the&lt;br /&gt;&lt;br /&gt;  program at every offset 100! What does this mean? It means when IP=100,&lt;br /&gt;&lt;br /&gt;  the program will be stopped! We call this Magic Offset. Hmm, what's the&lt;br /&gt;&lt;br /&gt;  use? Too many! Think by yourself :-) One simplest and direct usage is&lt;br /&gt;&lt;br /&gt;  use &amp;quot;G 100&amp;quot; you can *UNPACK* all .COM files!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;4.Assembly Language Command&lt;br /&gt;&lt;br /&gt;===========================&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;  It's a good idea that you can use ASM opcode in your debug environment.&lt;br /&gt;&lt;br /&gt;  You can accomplish your wish in TR! You may use either &amp;quot;R AX 001A&amp;quot; or&lt;br /&gt;&lt;br /&gt;  &amp;quot;MOV AX, 001A&amp;quot;. Both do the same thing. Remember, all assembly opcode&lt;br /&gt;&lt;br /&gt;  can be used in TR, e.g. &amp;quot;CLI&amp;quot;, &amp;quot;MOV [WORD 1234], 4567&amp;quot;, &amp;quot;IN AL,21&amp;quot;...&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;5.Add Comments During Tracing&lt;br /&gt;&lt;br /&gt;=============================&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;  &amp;quot;CALL 7FDE&amp;quot; is not good compared to &amp;quot;CALL OPEN_FILE&amp;quot;. But most tracers&lt;br /&gt;&lt;br /&gt;  must face such opcodes. Even if you have known what the procedure&lt;br /&gt;&lt;br /&gt;  would do, you could only write it down on paper. Now TR can write&lt;br /&gt;&lt;br /&gt;  your comments directly into the program and saved them into another file&lt;br /&gt;&lt;br /&gt;  automatically. From now on all programs are easy for understand. TR will&lt;br /&gt;&lt;br /&gt;  as well display comments for most INT21 function calls automatically for&lt;br /&gt;&lt;br /&gt;  you.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;6.Automatic Jump&lt;br /&gt;&lt;br /&gt;================&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;  Many protectors use lots of JMP codes to make the decryptor of their&lt;br /&gt;&lt;br /&gt;  protection unreadable. In most situations, you can only see some JMPs in&lt;br /&gt;&lt;br /&gt;  the code window. At the target address, in general, you can't see the&lt;br /&gt;&lt;br /&gt;  correct disassemble opcode because the protect programs likely insert&lt;br /&gt;&lt;br /&gt;  some DATA in front of that address, so, it's difficult to understand&lt;br /&gt;&lt;br /&gt;  these programs. With the Automatic Jump feature, TR displays the correct&lt;br /&gt;&lt;br /&gt;  code at the JMP address in code window instead of displaying a &amp;quot;JMP&lt;br /&gt;&lt;br /&gt;  xxxx&amp;quot;. This way you can see the correct codes sequence but not lots of&lt;br /&gt;&lt;br /&gt;  jumps: the code is easy to read!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;7.Log&lt;br /&gt;&lt;br /&gt;=====&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;  TR could save all CS:IP on interpret-run. This makes it possible to&lt;br /&gt;&lt;br /&gt;  analyse the program easily. If the program exits with an error, you can&lt;br /&gt;&lt;br /&gt;  find the problem by backtracing your LOG. Command 'LOGPRO' can get all&lt;br /&gt;&lt;br /&gt;  the key opcode program run. The program will have no secret after you&lt;br /&gt;&lt;br /&gt;  LOG it. Refer to the commands LOG, LOGS, VLOG and LOGPRO.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;8.Write EXE file from memory&lt;br /&gt;&lt;br /&gt;============================&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;  You can find many universal unpackers on the net, but what would you do&lt;br /&gt;&lt;br /&gt;  if they tell you &amp;quot;I can't unpack it&amp;quot;? Unpack functions should be in&lt;br /&gt;&lt;br /&gt;  debuggers. TR's MKEXE function let you make EXE file easy!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;9.Various Complex breakpoints, One-time breakpoints&lt;br /&gt;&lt;br /&gt;===================================================&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;  All other debuggers' breakpoints are what INTEL prepared. They cannot&lt;br /&gt;&lt;br /&gt;  fit the need of modern trace technology. TR has many revolutionary&lt;br /&gt;&lt;br /&gt;  breakpoints:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;   (1) BP conditions&lt;br /&gt;&lt;br /&gt;       Conditional break-point. ex.:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;       BP IP&amp;gt;4000&lt;br /&gt;&lt;br /&gt;       BP ah=2 dl=80 ch&amp;gt;30&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;   (2) BPINT intnum [conditions]&lt;br /&gt;&lt;br /&gt;       Interrupt break-point.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;   (3) BPXB bytes [conditions]&lt;br /&gt;&lt;br /&gt;       Break-point if ??? code is encountered. For example, &amp;quot;MOV AX,????&amp;quot;&lt;br /&gt;&lt;br /&gt;       is assembled in HEX &amp;quot;B8????&amp;quot;, so you can use&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;       BPXB b8&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;       to break on all &amp;quot;mov ax,????&amp;quot; opcodes. Other examples:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;       BPXB cd          ;all interrupt&lt;br /&gt;&lt;br /&gt;       BPXB 33 c0       ;xor ax,ax&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;   (4) BPREG REG''&lt;/i&gt;
&lt;/p&gt;</summary>
			</entry>

	<entry>
		<id>http://www.woodmann.com/collaborative/tools/index.php/Process_Hacker</id>
		<title>Tool Updated: Process Hacker</title>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/Process_Hacker"/>
				<updated>2009-08-22T13:51:09Z</updated>
		
		<summary type="html">&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Malware_Analysis_Tools&quot;&gt;Malware Analysis Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Process_Monitoring_Tools&quot;&gt;Process Monitoring Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.4&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;August 22, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Process Hacker is a feature-packed tool for manipulating processes and services on your computer.&lt;br /&gt;&lt;br /&gt;Key features of Process Hacker:&lt;br /&gt;- A simple, customizable tree view with highlighting showing you the processes running on your computer.&lt;br /&gt;&lt;br /&gt;- Detailed performance graphs.&lt;br /&gt;&lt;br /&gt;- A complete list of services and full control over them (start, stop, pause, resume and delete).&lt;br /&gt;&lt;br /&gt;- A list of network connections.&lt;br /&gt;&lt;br /&gt;- Comprehensive information for all processes: full process performance history, thread listing and stacks with dbghelp symbols, token information, module and mapped file information, virtual memory map, environment variables, handles, ...&lt;br /&gt;&lt;br /&gt;- Full control over all processes, even processes protected by rootkits or security software. Its kernel-mode driver has unique abilities which allows it to terminate, suspend and resume all processes and threads, including software like IceSword, avast! anti-virus, AVG Antivirus, COMODO Internet Security, etc. (just to name a few).&lt;br /&gt;&lt;br /&gt;- Find hidden processes and terminate them. Process Hacker detects processes hidden by simple rootkits such as Hacker Defender and FU.&lt;br /&gt;&lt;br /&gt;- Easy DLL injection and unloading - simply right-click a process and select &amp;quot;Inject DLL&amp;quot; to inject and right-click a module and select &amp;quot;Unload&amp;quot; to unload!&lt;br /&gt;&lt;br /&gt;- Many more features...&lt;/i&gt;
&lt;/p&gt;</summary>
			</entry>

	<entry>
		<id>http://www.woodmann.com/collaborative/tools/index.php/Memory_Hacking_Software</id>
		<title>Tool Updated: Memory Hacking Software</title>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/Memory_Hacking_Software"/>
				<updated>2009-08-14T20:32:08Z</updated>
		
		<summary type="html">&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Code_Coverage_Tools&quot;&gt;Code Coverage Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Memory_Data_Tracing_Tools&quot;&gt;Memory Data Tracing Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Memory_Search_Tools&quot;&gt;Memory Search Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Trainer_Generators&quot;&gt;Trainer Generators&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;5.009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;August 14, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Highly advanced software for memory search/analysis and trainer creation. Recommended!&lt;br /&gt;&lt;br /&gt;MHS 5.005 (bundle):&lt;br /&gt;Bundle includes MHS.exe, zlib1.dll, MHS Help.chm, and ChangeLog.txt.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Features:&lt;br /&gt;* Fastest Searching&lt;br /&gt;-- Data-Type Search&lt;br /&gt;-- Pointer Search&lt;br /&gt;-- String Search (ASCII, Unicode, Hex Bytes, Wildcard, Regular Expressions)&lt;br /&gt;-- Group Search (Includes Pattern Matching)&lt;br /&gt;-- Expression Search (Extremely Flexible)&lt;br /&gt;-- Script Search (The Ultimate in Custom Searching)&lt;br /&gt;&lt;br /&gt;* Debugger&lt;br /&gt;-- Very Stable&lt;br /&gt;-- Customizable Breakpoints&lt;br /&gt;&lt;br /&gt;* Disassembler&lt;br /&gt;&lt;br /&gt;* Code Filter&lt;br /&gt;-- Easiest Way to Find Functions&lt;br /&gt;&lt;br /&gt;* Auto-Hack&lt;br /&gt;&lt;br /&gt;* Auto-Assembler&lt;br /&gt;-- 90% Same Language/Syntax as in Cheat Engine&lt;br /&gt;&lt;br /&gt;* DLL Injector&lt;br /&gt;-- Injects any DLL into the Target Process&lt;br /&gt;-- Uninject Later, Automatically or Manually&lt;br /&gt;-- Remotely Call ANY Functions in the Injected DLL(s), Regardless of Calling Convention, Return Type, or Number of Parameters&lt;br /&gt;&lt;br /&gt;* Integrated Script Language&lt;br /&gt;-- IDE/Compiler Built-In&lt;br /&gt;-- Syntax Matches C; No Learning Curve&lt;br /&gt;-- Compiled for Fast Execution&lt;br /&gt;-- Full API&lt;br /&gt;-- Includes Features Specially for Hacking&lt;br /&gt;&lt;br /&gt;* Real-Time Hex Editor&lt;br /&gt;-- Fully Featured Real-Time Hex Editor for Both RAM and Files&lt;br /&gt;-- Allows Browsing of Kernel RAM&lt;br /&gt;&lt;br /&gt;* Kernel Driver&lt;br /&gt;-- Allows Bypassing Anti-Cheat Systems&lt;br /&gt;-- Allows Reading/Writing of Kernel RAM&lt;br /&gt;&lt;br /&gt;* Converter&lt;br /&gt;&lt;br /&gt;* RAM Watcher&lt;br /&gt;&lt;br /&gt;* Memory Allocator&lt;br /&gt;-- Allocates Memory in the Target Process&lt;/i&gt;
&lt;/p&gt;</summary>
			</entry>

	<entry>
		<id>http://www.woodmann.com/collaborative/tools/index.php/Wireshark</id>
		<title>Tool Updated: Wireshark</title>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/Wireshark"/>
				<updated>2009-07-20T22:01:23Z</updated>
		
		<summary type="html">&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Network_Sniffers&quot;&gt;Network Sniffers&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.2.1&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;July 20, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Wireshark (previously Ethereal) is the world's foremost network protocol analyzer, and is the standard in many industries.&lt;br /&gt;&lt;br /&gt;It is the continuation of a project that started in 1998. Hundreds of developers around the world have contributed to it, and it is still under active development.&lt;br /&gt;&lt;br /&gt;Wireshark has a rich feature set which includes the following:&lt;br /&gt;&lt;br /&gt;* Hundreds of protocols are supported, with more being added all the time&lt;br /&gt;* Live capture and offline analysis are supported&lt;br /&gt;* Standard three-pane packet browser&lt;br /&gt;* Multi-platform: Runs on Windows, Linux, OS X, Solaris, FreeBSD, NetBSD, and many others&lt;br /&gt;* Captured network data can be browsed via a GUI, or via the TTY-mode TShark utility&lt;br /&gt;* The most powerful display filters in the industry&lt;br /&gt;* Rich VoIP analysis&lt;br /&gt;* Read/write many different capture file formats: tcpdump (libpcap), Catapult DCT2000, Cisco Secure IDS iplog, Microsoft Network Monitor, Network General Sniffer® (compressed and uncompressed), Sniffer® Pro, and NetXray®, Network Instruments Observer, Novell LANalyzer, RADCOM WAN/LAN Analyzer, Shomiti/Finisar Surveyor, Tektronix K12xx, Visual Networks Visual UpTime, WildPackets EtherPeek/TokenPeek/AiroPeek, and many others&lt;br /&gt;* Capture files compressed with gzip can be decompressed on the fly&lt;br /&gt;* Live data can be read from Ethernet, IEEE 802.11, PPP/HDLC, ATM, Bluetooth, USB, Token Ring, Frame Relay, FDDI, and others (depending on your platfrom)&lt;br /&gt;* Decryption support for many protocols, including IPsec, ISAKMP, Kerberos, SNMPv3, SSL/TLS, WEP, and WPA/WPA2&lt;br /&gt;* Coloring rules can be applied to the packet list, which eases analysis&lt;br /&gt;* Output can be exported to XML, PostScript®, CSV, or plain text&lt;/i&gt;
&lt;/p&gt;</summary>
			</entry>

	<entry>
		<id>http://www.woodmann.com/collaborative/tools/index.php/Syscall_Lister</id>
		<title>Tool Updated: Syscall Lister</title>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/Syscall_Lister"/>
				<updated>2009-07-19T05:11:45Z</updated>
		
		<summary type="html">&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:SysCall_Monitoring_Tools&quot;&gt;SysCall Monitoring Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;

&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;July 18, 2007&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;This program enumerates all NT kernel system calls and matches them with native API functions using dbghelp and MS symbols (internet connection is required to download these symbols).&lt;br /&gt;&lt;br /&gt;It uses kernel mode driver to access arbitrary memory locations, like System Service Descriptor Tables.&lt;/i&gt;
&lt;/p&gt;</summary>
			</entry>

	<entry>
		<id>http://www.woodmann.com/collaborative/tools/index.php/Process_Lasso</id>
		<title>Tool Updated: Process Lasso</title>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/Process_Lasso"/>
				<updated>2009-07-19T05:11:12Z</updated>
		
		<summary type="html">&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Process_Monitoring_Tools&quot;&gt;Process Monitoring Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;3.62&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;July 18, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Process Lasso is a unique new technology intended to automatically adjust the allocation of CPU cycles so that system responsiveness is improved in high-load situations. It does this by dynamically temporarily lowering the priorities of processes that are consuming too many CPU cycles, there-by giving other processes a chance to run if they are in need. This is useful for both single and multi-core processors. No longer will a single process be able to bring your system to a virtual stall.&lt;br /&gt;&lt;br /&gt;In addition, Process Lasso offers capabilities such as default process priorities, termination of disallowed processes, and logging of processes executed.&lt;br /&gt;Supporting users are able to download all past and future builds of Process Lasso and have are given a specially labelled version of Process Lasso&lt;/i&gt;
&lt;/p&gt;</summary>
			</entry>

	<entry>
		<id>http://www.woodmann.com/collaborative/tools/index.php/OSpy</id>
		<title>Tool Updated: OSpy</title>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/OSpy"/>
				<updated>2009-07-19T05:10:43Z</updated>
		
		<summary type="html">&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:API_Monitoring_Tools&quot;&gt;API Monitoring Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.9.8&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;July 18, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;oSpy is a tool which aids in reverse-engineering software running on the Windows platform. With the amount of proprietary systems that exist today (synchronization protocols, instant messaging, etc.), the amount of work required to keep up when developing interoperable solutions will quickly become a big burden when limited to traditional techniques.&lt;br /&gt;&lt;br /&gt;However, when the sniffing is done on the API level it allows a much more fine-grained view of what's going on. Seeing return-addresses for each recv/send call (for example), can prove useful when you want to look at the processing code at that spot in a debugger or static analysis tool. And if an application uses encrypted communication it's easy to intercept these calls as well. oSpy already intercepts one such API, and is the API used by MSN Messenger, Google Talk, etc. for encrypting/decrypting HTTPS data.&lt;br /&gt;&lt;br /&gt;Another neat feature is when wanting to see how an application behaves when in a firewalled environment. Normally you would have to simulate such an environment by configuring firewalls etc., which not only is time-consuming, but might also cripple the rest of the applications you've got running. oSpy solves this problem by a feature called softwalling which allows you to set rules based on the type of function-call, the return-address, local/remote address/port, etc., and lets you choose which error to signal back to the application when the rule matches. This way you can make the application think that for example a connect() timed out, connection was refused, there was no route to host, etc.&lt;/i&gt;
&lt;/p&gt;</summary>
			</entry>

	<entry>
		<id>http://www.woodmann.com/collaborative/tools/index.php/LordCHEAT</id>
		<title>Tool Updated: LordCHEAT</title>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/LordCHEAT"/>
				<updated>2009-07-19T05:10:19Z</updated>
		
		<summary type="html">&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Memory_Data_Tracing_Tools&quot;&gt;Memory Data Tracing Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.2.6&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;July 18, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;- Small &amp;amp; Powerfull Game Trainer&lt;br /&gt;- Save &amp;amp; Load memory using simple script&lt;br /&gt;- Read/Write memory using Hex Editor&lt;br /&gt;- Support 16/32 bit Windows games, macromedia flash games, *emulator, etc&lt;br /&gt;- Support Pointer to Pointer&lt;br /&gt;- Support Plugins&lt;br /&gt;- Memory monitor&lt;br /&gt;- Can run under windows 98 up to *Vista&lt;br /&gt;- etc.&lt;/i&gt;
&lt;/p&gt;</summary>
			</entry>

	<entry>
		<id>http://www.woodmann.com/collaborative/tools/index.php/Tcpdump</id>
		<title>Tool Updated: Tcpdump</title>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/Tcpdump"/>
				<updated>2009-07-19T05:09:42Z</updated>
		
		<summary type="html">&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Network_Sniffers&quot;&gt;Network Sniffers&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;4.0.0&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;July 18, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;From wikipedia's entry for tcpdump:&lt;br /&gt;&lt;br /&gt;tcpdump is a common computer network debugging tool that runs under the command line. It allows the user to intercept and display TCP/IP and other packets being transmitted or received over a network to which the computer is attached. It was originally written by Van Jacobson, Craig Leres and Steven McCanne who were, at the time, working in the Lawrence Berkeley Laboratory Network Research Group.&lt;br /&gt;&lt;br /&gt;Distributed under a permissive free software licence, tcpdump is free software.&lt;br /&gt;&lt;br /&gt;Tcpdump works on most Unix-like operating systems: Linux, Solaris, BSD, Mac OS X, HP-UX and AIX among others. In those systems, tcpdump uses the libpcap library to capture packets.&lt;br /&gt;&lt;br /&gt;There is also a port of tcpdump for Windows called WinDump; this uses WinPcap, which is a port of libpcap to Windows.&lt;br /&gt;&lt;br /&gt;In some Unix-like operating systems, a user must have superuser privileges to use tcpdump because the packet capturing mechanisms on those systems require elevated privileges. However, the -Z option may be used to drop privileges to a specific unprivileged user after capturing has been set up. In other Unix-like operating systems, the packet capturing mechanism can be configured to allow non-privileged users to use it; if that is done, superuser privileges are not required.&lt;br /&gt;&lt;br /&gt;The user may optionally apply a BPF-based filter to limit the number of packets seen by tcpdump; this renders the output more usable on networks with a high volume of traffic.&lt;/i&gt;
&lt;/p&gt;</summary>
			</entry>

	<entry>
		<id>http://www.woodmann.com/collaborative/tools/index.php/WinApiOverride</id>
		<title>Tool Updated: WinApiOverride</title>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/WinApiOverride"/>
				<updated>2009-07-19T05:08:24Z</updated>
		
		<summary type="html">&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:.NET_Tracers&quot;&gt;.NET Tracers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:API_Monitoring_Tools&quot;&gt;API Monitoring Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:COM_Monitoring_Tools&quot;&gt;COM Monitoring Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;5.1.11&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;July 18, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;WinAPIOverride32 is an advanced api monitoring software.&lt;br /&gt;You can monitor and/or override any function of a process.&lt;br /&gt;This can be done for API functions or executable internal functions.&lt;br /&gt;&lt;br /&gt;It tries to fill the gap between classical API monitoring softwares and debuggers.&lt;br /&gt;It can break targeted application before or after a function call, allowing memory or registers changes; and it can directly call functions of the targeted application.&lt;br /&gt;Main differences between other API monitoring softwares :&lt;br /&gt;  - You can define filters on parameters or function result&lt;br /&gt;  - You can define filters on dll to discard calls from windows system dll&lt;br /&gt;  - You can hook functions inside the target process not only API&lt;br /&gt;  - You can hook asm functions with parameters passed through registers&lt;br /&gt;  - Double and float results are logged&lt;br /&gt;  - Preserve registers, floating stack and LastError&lt;br /&gt;  - You can easily override any API or any process internal function&lt;br /&gt;  - You can break process before or/and after function call to change memory or registers&lt;br /&gt;  - You can call functions which are inside the remote processes&lt;br /&gt;  - Can hook COM OLE and ActiveX interfaces&lt;br /&gt;  - All is is done like modules : you can log or override independently for any function&lt;/i&gt;
&lt;/p&gt;</summary>
			</entry>

	<entry>
		<id>http://www.woodmann.com/collaborative/tools/index.php/Win32_API_Monitor</id>
		<title>Tool Updated: Win32 API Monitor</title>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/Win32_API_Monitor"/>
				<updated>2009-07-18T23:38:13Z</updated>
		
		<summary type="html">&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:API_Monitoring_Tools&quot;&gt;API Monitoring Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.3.1&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;March 24, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;API Monitor is a software that allows you to spy and display Win32 API calls made by applications. It can trace any exported APIs and display wide range of information, including  function name, call sequence, input and output parameters, function return value and more. A useful developer tool for seeing how win32 applications work and learn their tricks. &lt;br /&gt;&lt;br /&gt;Main Features &lt;br /&gt;Trace any exported APIs- Including win32 APIs and other 3rd-Party APIs, unnecessary to know the prototype of the functions.&lt;br /&gt;Display wide range of information, including  function name, call sequence, input and output parameters, function return value, GetLastError code and more.&lt;br /&gt;Predefine 82 DLLs and nearly 4000 APIs' prototype.  &lt;br /&gt;Filter Profiles are a powerful way of storing your favorite monitor settings for use in other sessions. API Monitor preset 27 API Filter Profiler, including Handles and Objects, Dynamic-Link Libraries, Event Log, Pipes and Mailslots, Debugging, Windows Classes, COMM, Application Related, Shell, Dialog Boxes, File System, Services Related, Remote Access Service, Memory Management, Print Related, Windows, Registry, Processes and Threads, File IO, WinInet, Windows Sockets, Multimedia API, Windows GUI, Network Management, WinNT Security, Access Control Functions.&lt;br /&gt;Allow content to be viewed and exported-Log content can be viewed within API Monitor, and exported to another application or saved to a file. &lt;br /&gt;Support debug version and release version with no modifications to the target application. &lt;br /&gt;Support Unicode and ANSI APIs. &lt;br /&gt;Monitor Running Process-Spy APIs in a background or console process that is already running.&lt;br /&gt;Support multithread. &lt;br /&gt;Display API calls originating from ActiveX controls and COM objects instanced by an application. &lt;br /&gt;MS Excel® style data filtering, customize filter criteria against any data item.&lt;br /&gt;Automatic click-sorting against an unlimited number of columns, descending or ascending. &lt;br /&gt;Automatic data grouping - an extremely powerful data viewing and manipulation metaphor.&lt;br /&gt;Automatic runtime column selection - easily customize the columns visible on-screen with intuitive drag and drop.&lt;br /&gt;Instant Online MSDN Help - This feature allows you to view online MSDN context-sensitive help for the currently selected API.&lt;/i&gt;
&lt;/p&gt;</summary>
			</entry>

	<entry>
		<id>http://www.woodmann.com/collaborative/tools/index.php/RegShot</id>
		<title>Tool Updated: RegShot</title>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/RegShot"/>
				<updated>2009-07-18T23:26:11Z</updated>
		
		<summary type="html">&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Registry_Diff_Tools&quot;&gt;Registry Diff Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Registry_Monitoring_Tools&quot;&gt;Registry Monitoring Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.82&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;November 3, 2007&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Regshot is a small,free and open-source(GPL) registry compare utility that allows you to quickly take a snapshot of your registry and then compare it with a second one - done after doing system changes or installing a new software product. The changes report can be produced in text or HTML format and contains a list of all modifications that have taken place between snapshot1 and snapshot2. In addition, you can also specify folders (with sub filders) to be scanned for changes as well.&lt;/i&gt;
&lt;/p&gt;</summary>
			</entry>

	<entry>
		<id>http://www.woodmann.com/collaborative/tools/index.php/BusTRACE</id>
		<title>Tool Updated: BusTRACE</title>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/BusTRACE"/>
				<updated>2009-07-18T23:15:56Z</updated>
		
		<summary type="html">&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Bus_Monitoring_Tools&quot;&gt;Bus Monitoring Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;8.0.047&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;June 15, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;busTRACE 8.0 is a comprehensive bus and device analysis tool in use by leading system OEMs, peripheral OEMs, software developers, USB developers, and storage developers all over the world. busTRACE 7.0 provides a suite of applications designed to help you perform advanced bus and device analysis.&lt;br /&gt;&lt;br /&gt;* Capture I/O Activity&lt;br /&gt;  - Capture I/O activity on local or remote computers&lt;br /&gt;  - Allow remote busTRACE users to capture I/O activity&lt;br /&gt;&lt;br /&gt;* Generate I/O Activity&lt;br /&gt;  - Send a single CDB to a storage device&lt;br /&gt;  - Send a sequence of CDBs to a storage device&lt;br /&gt;  - Perform a read/write/compare stress test&lt;br /&gt;  - View ATA/ATAPI Identify information&lt;br /&gt;&lt;br /&gt;* Simulate Device Faults&lt;br /&gt;  - Simulate a failure on one or more specified devices&lt;br /&gt;&lt;br /&gt;* Additional Tools&lt;br /&gt;  - View Device Command Descriptor Blocks&lt;br /&gt;  - View Device Sense Codes&lt;br /&gt;  - CD/DVD Exclusive Access Status&lt;/i&gt;
&lt;/p&gt;</summary>
			</entry>

	<entry>
		<id>http://www.woodmann.com/collaborative/tools/index.php/DebugView</id>
		<title>Tool Updated: DebugView</title>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/DebugView"/>
				<updated>2009-07-18T23:13:27Z</updated>
		
		<summary type="html">&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Debug_Output_Monitoring_Tools&quot;&gt;Debug Output Monitoring Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;4.76&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;October 16, 2008&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;DebugView is an application that lets you monitor debug output on your local system, or any computer on the network that you can reach via TCP/IP. It is capable of displaying both kernel-mode and Win32 debug output, so you don't need a debugger to catch the debug output your applications or device drivers generate, nor do you need to modify your applications or drivers to use non-standard debug output APIs.&lt;/i&gt;
&lt;/p&gt;</summary>
			</entry>

	<entry>
		<id>http://www.woodmann.com/collaborative/tools/index.php/Process_Explorer</id>
		<title>Tool Updated: Process Explorer</title>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/Process_Explorer"/>
				<updated>2009-07-18T23:10:58Z</updated>
		
		<summary type="html">&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Process_Monitoring_Tools&quot;&gt;Process Monitoring Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;11.33&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;February 4, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;The Process Explorer display consists of two sub-windows. The top window always shows a list of the currently active processes, including the names of their owning accounts, whereas the information displayed in the bottom window depends on the mode that Process Explorer is in: if it is in handle mode you'll see the handles that the process selected in the top window has opened; if Process Explorer is in DLL mode you'll see the DLLs and memory-mapped files that the process has loaded. Process Explorer also has a powerful search capability that will quickly show you which processes have particular handles opened or DLLs loaded.&lt;/i&gt;
&lt;/p&gt;</summary>
			</entry>

	</feed>