
SwishDbgExt
Incident Response & Digital Forensics Debugging Extension

Incident Response & Digital Forensics Debugging Extension

Static analysis of 2 malicious Office documents on REMnux using oletools; identified CVE-2017-11882 and obfuscated macros.

A Linux version of the ProcDump Sysinternals tool

MAPS cloud scanner and response parser for Microsoft Defender research.

An strace-like program for the Windows 'native' API

Collection of extracted Microsoft Defender data for security research purposes

POC OF CVE-2022-21970

Fully undetectable and evasive ransomware written in Rust, leveraging a BYOVD technique to disable AV/EDR solutions on the infected systems.

Exploration of the Follina (CVE-2022-30190) Microsoft Office vulnerability, including a detailed analysis, proof-of-concept exploitation in a…

Python toolkit for analyzing MS OLE2 and Office documents, extracting VBA macros, detecting exploits, and performing forensic analysis of structured…

Curated collection of P/Invoke definitions from pinvoke.net with Microsoft documentation links, enabling quick Windows API prototyping for security…

NCC Group's analysis and exploitation of CVE-2017-8759 along with further refinements

Generates malicious DOCX documents exploiting CVE-2021-40444 (Microsoft Office RCE) with a hosted server for DLL payload delivery, based on…


