Skip to content

qHooK is very simple python script (dependent on pydbg) which hooks user defined Win32 APIs in any process and monitor then while process is running and at last prepare a CSV report with various interesting information which can help reverse engineer to track down / analyse unknown exploit samples / shellcode.

Branch: master
Go to file
Code

Latest commit

Files

Permalink
Failed to load latest commit information.
Type
Name
Latest commit message
Commit time
 
 
 
 

README.md

qHooK

qHooK is very simple and straight forward python script (dependent on pydbg) which hooks user defined Win32 APIs in any process and monitor then while process is running and at last prepare a CSV report with various interesting information which can help reverse engineer to track down / analyse unknown exploit samples / shellcode.

Out Put of qHooK

This is how the final CSV looks(Obviously after little bit excel formatting). alt text

Video Demo of qHooK(with Voice)

Sorry about my weak voice. My laptop mic sucks :(

IMAGE ALT TEXT HERE

About

qHooK is very simple python script (dependent on pydbg) which hooks user defined Win32 APIs in any process and monitor then while process is running and at last prepare a CSV report with various interesting information which can help reverse engineer to track down / analyse unknown exploit samples / shellcode.

Resources

Releases

No releases published

Languages

You can’t perform that action at this time.