
windiff
Tool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across different versions of the OS, using a Web UI…

Tool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across different versions of the OS, using a Web UI…

An strace-like program for the Windows 'native' API

"In-depth reverse engineering analysis of Vidar Stealer 2.0 covering Task Scheduler tampering (1999 timestamps), Explorer.exe process hollowing, and…

MAPS cloud scanner and response parser for Microsoft Defender research.

Sample extensions, scripts, and API uses for WinDbg.

Universal signature generation for any system function from all Windows Builds using Winbindex

Microsoft HEIF Extension (msheif_store.dll) OOB-read


Curated collection of P/Invoke definitions from pinvoke.net with Microsoft documentation links, enabling quick Windows API prototyping for security…

Documentation of Microsoft's Warbird obfuscation

A PowerShell front-end for the Windows debugger engine.

An x64dbg plugin which marks XFG call signatures as data

User-friendly Microsoft Windows Debugger for Malware Analysts.

Collection of extracted Microsoft Defender data for security research purposes


Root cause analysis and PoC for a Microsoft SQL Server Stack Overflow Vulnerability by reversing svl.dll.