
DefenderCheck
Identifies the bytes that Microsoft Defender flags on.

Identifies the bytes that Microsoft Defender flags on.

A PowerShell front-end for the Windows debugger engine.

High-performance SMT solver for automated theorem proving, constraint solving, and program verification. Supports multiple theories and language…

Distributed, code-coverage guided snapshot-based fuzzer for user and kernel-mode targets on Windows and Linux, with emulator and hypervisor backends.

Identifies the bytes that Microsoft Defender / AMSI Consumer flags on.

Red Team C code repo

Tool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across different versions of the OS, using a Web UI…

Proof of concept for CVE-2021-24086, a NULL dereference in tcpip.sys triggered remotely.

User-friendly Microsoft Windows Debugger for Malware Analysts.

Two IDAPython Scripts help you to reconstruct Microsoft COM (Component Object Model) Code

Automated scanner for discovering DLL search order hijacking candidates in Windows executables, featuring import table parsing, runtime module…

An x64dbg plugin which marks XFG call signatures as data

Documentation of Microsoft's Warbird obfuscation

Python based tool for generating Shellcode from PIC C

Enable Microsoft PDB support in Ghidra without installing Visual Studio

Universal signature generation for any system function from all Windows Builds using Winbindex

Microsoft-Office-Word-MSHTML-Remote-Code-Execution-Exploit

"In-depth reverse engineering analysis of Vidar Stealer 2.0 covering Task Scheduler tampering (1999 timestamps), Explorer.exe process hollowing, and…