
windiff
Tool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across different versions of the OS, using a Web UI…

Tool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across different versions of the OS, using a Web UI…

Proof of concept for CVE-2021-24086, a NULL dereference in tcpip.sys triggered remotely.

Red Team C code repo

"In-depth reverse engineering analysis of Vidar Stealer 2.0 covering Task Scheduler tampering (1999 timestamps), Explorer.exe process hollowing, and…

Automated scanner for discovering DLL search order hijacking candidates in Windows executables, featuring import table parsing, runtime module…

Fuzzing the Microsoft Windows DNS client library. Inspired by CVE-2026-41096.

Microsoft HEIF Extension (msheif_store.dll) OOB-read

Documentation of Microsoft's Warbird obfuscation

Universal signature generation for any system function from all Windows Builds using Winbindex

A PowerShell front-end for the Windows debugger engine.

Identifies the bytes that Microsoft Defender flags on.

Identifies the bytes that Microsoft Defender / AMSI Consumer flags on.

Two IDAPython Scripts help you to reconstruct Microsoft COM (Component Object Model) Code

User-friendly Microsoft Windows Debugger for Malware Analysts.

Enable Microsoft PDB support in Ghidra without installing Visual Studio

High-performance SMT solver for automated theorem proving, constraint solving, and program verification. Supports multiple theories and language…

Distributed, code-coverage guided snapshot-based fuzzer for user and kernel-mode targets on Windows and Linux, with emulator and hypervisor backends.

An x64dbg plugin which marks XFG call signatures as data