
wtf
Distributed, code-coverage guided snapshot-based fuzzer for user and kernel-mode targets on Windows and Linux, with emulator and hypervisor backends.

Distributed, code-coverage guided snapshot-based fuzzer for user and kernel-mode targets on Windows and Linux, with emulator and hypervisor backends.

⭐⭐ Join us at SNIA SDC for the SMB3 IO Lab (September 28 - October 1, 2026), see upcoming Interoperability Events

A self-hosted Fuzzing-As-A-Service platform

MAPS cloud scanner and response parser for Microsoft Defender research.

Proof of concept for CVE-2021-24086, a NULL dereference in tcpip.sys triggered remotely.

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and…

Proof-of-concept exploit for CVE-2020-16947, a Microsoft Outlook RCE triggered by malformed HTML content leading to a heap buffer overflow and remote…

Fuzzing the Microsoft Windows DNS client library. Inspired by CVE-2026-41096.

PoC for CVE-2021-28476 a guest-to-host "Hyper-V Remote Code Execution Vulnerability" in vmswitch.sys.

POC Of CVE-2022-26937

Microsoft HEIF Extension (msheif_store.dll) OOB-read