
ExtractedDefender
Collection of extracted Microsoft Defender data for security research purposes

Collection of extracted Microsoft Defender data for security research purposes

Sample extensions, scripts, and API uses for WinDbg.

User-friendly Microsoft Windows Debugger for Malware Analysts.

An x64dbg plugin which marks XFG call signatures as data

Enable Microsoft PDB support in Ghidra without installing Visual Studio

Microsoft HEIF Extension (msheif_store.dll) OOB-read

Universal signature generation for any system function from all Windows Builds using Winbindex


Root cause analysis and PoC for a Microsoft SQL Server Stack Overflow Vulnerability by reversing svl.dll.

Documentation of Microsoft's Warbird obfuscation

An strace-like program for the Windows 'native' API

MAPS cloud scanner and response parser for Microsoft Defender research.


A PowerShell front-end for the Windows debugger engine.

"In-depth reverse engineering analysis of Vidar Stealer 2.0 covering Task Scheduler tampering (1999 timestamps), Explorer.exe process hollowing, and…

Incident Response & Digital Forensics Debugging Extension