Flag: Tornado! Hurricane!

OpenRCE Win32 Call Chains Database

This reference section was initially contributed to OpenRCE by pedram.

The Win32 Call Chains database attempts to provide a useful and comprehensive interface to the function call trees of the main Microsoft Windows Dynamic Link Libraries (DLLs). The data-set was originally contructed during the development of a proof of concept Windows Intrusion Prevention System (IPS), similar to NAI Entercept and Okena/Cisco CSA. The information provided here was necessary to avoid the common mistake of not hooking "deep enough" (See Phrack 62 - 0x05) and is made available in hopes that others will find it useful and expand on it. The database is sectioned by Operating System and can be browsed and searched interactively. The following quick and dirty scripts were used to generate the data-set: An interactive Java visualization is available for each module under the 'graph' link, some of them are broken and still being debugged. If someone can write a nice custom graphing applet, please share.

 Windows 2000 SP4  Windows XP SP1  Windows XP SP2
  ADVAPI32   Graph
  GDI32   Graph
  KERNEL32   Graph
  NETAPI32   Graph
  NTDLL   Graph
  SHLWAPI   Graph
  USER32   Graph
  WININET   Graph
  WS2_32   Graph
  WS2HELP   Graph
  ADVAPI32   Graph
  GDI32   Graph
  KERNEL32   Graph
  NETAPI32   Graph
  NTDLL   Graph
  SHLWAPI   Graph
  USER32   Graph
  WININET   Graph
  WS2_32   Graph
  WS2HELP   Graph
  ADVAPI32   Graph
  GDI32   Graph
  KERNEL32   Graph
  NETAPI32   Graph
  NTDLL   Graph
  SHLWAPI   Graph
  USER32   Graph
  WININET   Graph
  WS2_32   Graph
  WS2HELP   Graph
 
 Windows 2003 SE  Windows 2003 SE SP1  
  ADVAPI32   Graph
  GDI32   Graph
  KERNEL32   Graph
  NETAPI32   Graph
  NTDLL   Graph
  SHLWAPI   Graph
  USER32   Graph
  WININET   Graph
  WS2_32   Graph
  WS2HELP   Graph
  ADVAPI32   Graph
  GDI32   Graph
  KERNEL32   Graph
  NETAPI32   Graph
  NTDLL   Graph
  SHLWAPI   Graph
  USER32   Graph
  WININET   Graph
  WS2_32   Graph
  WS2HELP   Graph
 

There are 31,310 total registered users.


Recently Created Topics
[help] Unpacking VMP...
Mar/12
Reverse Engineering ...
Jul/06
hi!
Jul/01
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06


Recent Forum Posts
Finding the procedur...
rolEYder
Question about debbu...
rolEYder
Identify RVA data in...
sohlow
let 'IDAPython' impo...
sohlow
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n


Recent Blog Entries
halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

oleavr
Aug/27
CryptoShark: code tracer ba...

oleavr
Jun/25
Build a debugger in 5 minutes

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit