
DbgShell
A PowerShell front-end for the Windows debugger engine.

A PowerShell front-end for the Windows debugger engine.

Sample extensions, scripts, and API uses for WinDbg.

Incident Response & Digital Forensics Debugging Extension

Tool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across different versions of the OS, using a Web UI…

An strace-like program for the Windows 'native' API

Collection of extracted Microsoft Defender data for security research purposes

User-friendly Microsoft Windows Debugger for Malware Analysts.

Two IDAPython Scripts help you to reconstruct Microsoft COM (Component Object Model) Code

MAPS cloud scanner and response parser for Microsoft Defender research.

An x64dbg plugin which marks XFG call signatures as data

Documentation of Microsoft's Warbird obfuscation

Enable Microsoft PDB support in Ghidra without installing Visual Studio

Curated collection of P/Invoke definitions from pinvoke.net with Microsoft documentation links, enabling quick Windows API prototyping for security…

Universal signature generation for any system function from all Windows Builds using Winbindex


"In-depth reverse engineering analysis of Vidar Stealer 2.0 covering Task Scheduler tampering (1999 timestamps), Explorer.exe process hollowing, and…

Microsoft HEIF Extension (msheif_store.dll) OOB-read