System Structure Tools

Questions concerning tools (other than OllyDbg) - IDA Pro, SoftIce, member contributions, etc.
<b>NOTE:</b> You must <b>always</b> make sure you cannot find what you are looking for in our <a href="/collaborative/tools">Collaborative RCE Tool Library</a> before asking for <b>any</b> tools that can do this or that though!
Post by Kayaker »

Someone added a couple of interesting tools to the CRCETL recently (Thank You!) They're rather unique so I thought they deserved mention.

Both are from

The first, XNTSV, is a utility that displays detailed information about Windows system structures, both user and kernel, for running processes. You can traverse linked structures, read the values, create and save prototypes, etc. A lot easier than working with a bunch of cryptic Windbg commands to accomplish the same thing.

The second, PDBRipper, does what it says, extract structure/enum/type information from PDB files.

Both fun to play with if you're into that kind of thing.

http://www.woodmann.com/collaborative/t ... .php/XNTSV
http://www.woodmann.com/collaborative/t ... /PDBRipper