

Red Team C code repo

"In-depth reverse engineering analysis of Vidar Stealer 2.0 covering Task Scheduler tampering (1999 timestamps), Explorer.exe process hollowing, and…

Complete analysis of CVE-2025-21298, a double free vulnerability related to ole32 library in windows.

This Repository Talks about the Follina MSDT from Defender Perspective

Honeypot for CVE-2025-53770 aka ToolShell

Universal signature generation for any system function from all Windows Builds using Winbindex

Identifies the bytes that Microsoft Defender flags on.

Identifies the bytes that Microsoft Defender / AMSI Consumer flags on.

GC2 is a Command and Control application that allows an attacker to execute commands on the target machine using Google Sheet or Microsoft SharePoint…

CVE-2021-40444 - Fully Weaponized Microsoft Office Word RCE Exploit

Exploit toolkit CVE-2017-0199 - v4.0 is a handy python script which provides pentesters and security researchers a quick and effective way to test…

Two IDAPython Scripts help you to reconstruct Microsoft COM (Component Object Model) Code

Lockbit3.0 Microsoft Defender MpClient.dll DLL Hijacking PoC

Evade behavioral analysis by executing malicious code within trusted Microsoft call stacks, patchless hooking library IAT/EAT.

User-friendly Microsoft Windows Debugger for Malware Analysts.

Enable Microsoft PDB support in Ghidra without installing Visual Studio

Static analysis tool for investigating potentially malicious Microsoft Excel files, extracting metadata, macros, and embedded objects to aid digital…