- check os architecture
- get windows driver via sign from msdl
- get driver's pdb file from msdl
- parser new struct named dvrt in PE
- file system redirection trick for wow64 process
- disassemble shellcode quickly
- python script to deal with E-language
- Hook Windows API demo