qHooK is very simple python script (dependent on pydbg) which hooks user defined Win32 APIs in any process and monitor then while process is running and at last prepare a CSV report with various interesting information which can help reverse engineer to track down / analyse unknown exploit samples / shellcode.
Python
Switch branches/tags
Nothing to show
Clone or download
Fetching latest commit…
Cannot retrieve the latest commit at this time.
Permalink
Failed to load latest commit information.
README.md First Commit Jan 27, 2015
qHooK.py Minor Changes Jan 31, 2015

README.md

qHooK

qHooK is very simple and straight forward python script (dependent on pydbg) which hooks user defined Win32 APIs in any process and monitor then while process is running and at last prepare a CSV report with various interesting information which can help reverse engineer to track down / analyse unknown exploit samples / shellcode.

Out Put of qHooK

This is how the final CSV looks(Obviously after little bit excel formatting). alt text

Video Demo of qHooK(with Voice)

Sorry about my weak voice. My laptop mic sucks :(

IMAGE ALT TEXT HERE