Flag: Tornado! Hurricane!

OpenRCE Win32 Call Chains Database

This reference section was initially contributed to OpenRCE by pedram.

The Win32 Call Chains database attempts to provide a useful and comprehensive interface to the function call trees of the main Microsoft Windows Dynamic Link Libraries (DLLs). The data-set was originally contructed during the development of a proof of concept Windows Intrusion Prevention System (IPS), similar to NAI Entercept and Okena/Cisco CSA. The information provided here was necessary to avoid the common mistake of not hooking "deep enough" (See Phrack 62 - 0x05) and is made available in hopes that others will find it useful and expand on it. The database is sectioned by Operating System and can be browsed and searched interactively. The following quick and dirty scripts were used to generate the data-set: An interactive Java visualization is available for each module under the 'graph' link, some of them are broken and still being debugged. If someone can write a nice custom graphing applet, please share.

 Windows 2000 SP4  Windows XP SP1  Windows XP SP2
  ADVAPI32   Graph
  GDI32   Graph
  KERNEL32   Graph
  NETAPI32   Graph
  NTDLL   Graph
  SHLWAPI   Graph
  USER32   Graph
  WININET   Graph
  WS2_32   Graph
  WS2HELP   Graph
  ADVAPI32   Graph
  GDI32   Graph
  KERNEL32   Graph
  NETAPI32   Graph
  NTDLL   Graph
  SHLWAPI   Graph
  USER32   Graph
  WININET   Graph
  WS2_32   Graph
  WS2HELP   Graph
  ADVAPI32   Graph
  GDI32   Graph
  KERNEL32   Graph
  NETAPI32   Graph
  NTDLL   Graph
  SHLWAPI   Graph
  USER32   Graph
  WININET   Graph
  WS2_32   Graph
  WS2HELP   Graph
 
 Windows 2003 SE  Windows 2003 SE SP1  
  ADVAPI32   Graph
  GDI32   Graph
  KERNEL32   Graph
  NETAPI32   Graph
  NTDLL   Graph
  SHLWAPI   Graph
  USER32   Graph
  WININET   Graph
  WS2_32   Graph
  WS2HELP   Graph
  ADVAPI32   Graph
  GDI32   Graph
  KERNEL32   Graph
  NETAPI32   Graph
  NTDLL   Graph
  SHLWAPI   Graph
  USER32   Graph
  WININET   Graph
  WS2_32   Graph
  WS2HELP   Graph
 

There are 29,892 total registered users.


Recently Created Topics
Decompiling raw bina...
May/22
Incorrect bitness wh...
May/20
PaiMei stalker modul...
May/19
Attach to program us...
May/13
IDA PRO how to make ...
May/12
FACT: OpenRCE is dead.
May/08
Int 3 anti debug?
May/05
help needed - Beginn...
May/03
Attaching IDA Pro to...
Apr/27
File type
Apr/21


Recent Forum Posts
Ollydbg 2.0 - Plugin...
openrce...
IDA PRO how to make ...
codeinject
FACT: OpenRCE is dead.
codeinject
IDA Resource Viewer ...
r2x64
FACT: OpenRCE is dead.
djnemo
FACT: OpenRCE is dead.
codeinject
FACT: OpenRCE is dead.
pedram
help needed - Beginn...
araujo
Attaching IDA Pro to...
codeinject
Int 3 anti debug?
codeinject


Recent Blog Entries
nfljerseysmart
May/23


nfljerseysmart
May/23


laangels
May/22
The Reason You Need A Mark ...

laangels
May/22
Buy Albert Pujols Jersey an...

lowpriority
Apr/13
OllyMigrate Plugin for Olly...

More ...


Recent Blog Comments
clarisonic on:
Apr/03
New version of Ollydbg!

clarisonic on:
Apr/03
New version of Ollydbg!

trackerx90 on:
Mar/04
SuppressDebugMsg As Anti-De...

coachfactory on:
Feb/25
Portable Executable Format ...

coachfactory on:
Feb/25
A new Anti-Olly trick.

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit