• Stars
    star
    438
  • Rank 99,453 (Top 2 %)
  • Language QMake
  • License
    MIT License
  • Created over 6 years ago
  • Updated 4 months ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

XNTSV program for detailed viewing of system structures for Windows.

Donate GitHub tag (latest SemVer) GitHub All Releases gitlocalized

XNTSV program for detailed viewing of system structures in Windows.

During process creation in Windows, special system structures appear in the system such as:

  • PEB
  • TEB *
  • PEB_LDR_DATA
  • LDR_DATA_TABLE_ENTRY
  • RTL_USER_PROCESS_PARAMETERS
  • EPROCESS etc.

The list of different structures is large and specific for each version of the operating system.

You could easily add your own structs (Edit structs/ARCH/custom.json)

Officially it is not fully documented and change in different Windows versions.

This program shows complete information about these structures. It can be useful for researchers of Windows internals, as well as creators of software protection.

The program supports now:

  • Windows 7
  • Windows 7 SP1
  • Windows 8
  • Windows 8.1
  • Windows Server 2016
  • Windows Server 2019
  • Windows 10 (all builds)
  • Windows 11 (build 22000)

The program does not support now Windows 2000,XP and Vista. If you need structs for these OS use old versions of XNTSV.

The program supports now kernel mode. But you need sign driver with valid driver cert or use test cert. https://docs.microsoft.com/en-us/windows-hardware/drivers/install/how-to-test-sign-a-driver-package

alt text

alt text alt text alt text alt text alt text

Special Thanks

More Repositories

1

Detect-It-Easy

Program for determining types of files for Windows, Linux and MacOS.
JavaScript
7,333
star
2

DIE-engine

DIE engine
C++
2,250
star
3

XELFViewer

ELF file viewer/editor for Windows, Linux and MacOS.
C++
1,321
star
4

XPEViewer

PE file viewer/editor for Windows, Linux and MacOS.
QMake
936
star
5

x64dbg-Plugin-Manager

Plugin manager for x64dbg
C++
782
star
6

PDBRipper

PDBRipper is a utility for extract an information from PDB-files.
C
775
star
7

XMachOViewer

XMachOViewer is a Mach-O viewer for Windows, Linux and MacOS
C++
759
star
8

XAPKDetector

APK/DEX detector for Windows, Linux and MacOS.
C++
588
star
9

Nauz-File-Detector

Linker/Compiler/Tool detector for Windows, Linux and MacOS.
C++
509
star
10

XOpcodeCalc

Opcode calculator / ASM calculator
C++
361
star
11

stringsx64dbg

Strings plugin for x64dbg
C
224
star
12

nfdx64dbg

Plugin for x64dbg Linker/Compiler/Tool detector.
C
153
star
13

pex64dbg

C
134
star
14

horsicq.github.io

SCSS
36
star
15

XTranslation

34
star
16

die_library

C++
25
star
17

Formats

Binary formats
C++
24
star
18

build_tools

Shell
21
star
19

XDecompiler

C++
12
star
20

XNEViewer

C++
11
star
21

YARA-sort

Yara sort
YARA
11
star
22

XVelesDA

QMake
11
star
23

XInfoDB

C++
11
star
24

XPDFViewer

11
star
25

SpecAbstract

C++
10
star
26

old-DIE

old DIE
Pascal
10
star
27

XMSDOSViewer

C++
10
star
28

XLEViewer

C++
10
star
29

StaticScan

Static scan.
C++
9
star
30

die_script

C++
9
star
31

XCapstone

C++
8
star
32

nfd_library

C++
8
star
33

DIE-sort

C++
8
star
34

XWinPDB

C
8
star
35

XNetDumper

C++
8
star
36

XDebugScript

C++
7
star
37

SICQ

OSCAR(ICQ/AIM)
C++
7
star
38

XDebugger

C++
7
star
39

XDepends

C++
7
star
40

XIPADetector

QMake
7
star
41

die_widget

C++
6
star
42

NFD-sort

C++
6
star
43

QHexView

C++
6
star
44

XRegistersView

C++
6
star
45

XHexEdit

C++
6
star
46

XDEX

C++
6
star
47

signatures

6
star
48

XDisasm

C++
6
star
49

XHexViewer

C++
5
star
50

XBinaryViewer

C++
5
star
51

XDisasmView

C++
5
star
52

XDemangle

C++
5
star
53

XDynStructsEngine

C++
5
star
54

trkdbg

C++
5
star
55

Translate_all

QMake
5
star
56

XDebuggerWidget

C++
5
star
57

DIE-internal

Internal detects for DIE
5
star
58

XScanEngine

C++
5
star
59

XCppfilt

C++
5
star
60

XVirusTotalViewer

4
star
61

FormatDialogs

C++
4
star
62

XSpecDebugger

C++
4
star
63

XShortcuts

C++
4
star
64

Controls

C++
4
star
65

QYara

C
4
star
66

XMemoryMapWidget

C++
4
star
67

XFileInfo

C++
4
star
68

XCallStackWidget

QMake
4
star
69

XHashWidget

C++
4
star
70

XVisualizationWidget

C++
4
star
71

XVedogon

C++
4
star
72

XHexView

C++
4
star
73

XYara

YARA
3
star
74

XDynStructsWidget

C++
3
star
75

XOptions

C++
3
star
76

XArchive

C++
3
star
77

XProcess

C++
3
star
78

XGithub

C++
3
star
79

FormatWidgets

C++
3
star
80

XDemangler

3
star
81

XEntropyWidget

C++
3
star
82

XWinDbgDriver

C++
3
star
83

XQwt

CMake
3
star
84

QOpenSSL

C
3
star
85

XSymbolsWidget

C++
3
star
86

XStyles

3
star
87

XSingleApplication

C++
2
star
88

XDemangleWidget

C++
2
star
89

XDynStructs

2
star
90

XMIME

C++
2
star
91

XMIMEWidget

C++
2
star
92

yara_widget

C++
2
star
93

XExtractor

C++
2
star
94

XPDF

C++
2
star
95

video_tutorials

2
star
96

horsicq

2
star
97

XWinIODriver

C++
2
star
98

nfd_widget

C++
2
star
99

XWinSystemWidget

C++
2
star
100

XProcessWidget

C++
2
star