
SwishDbgExt
Incident Response & Digital Forensics Debugging Extension

Incident Response & Digital Forensics Debugging Extension

MAPS cloud scanner and response parser for Microsoft Defender research.

An strace-like program for the Windows 'native' API

Tool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across different versions of the OS, using a Web UI…

Collection of extracted Microsoft Defender data for security research purposes

Curated collection of P/Invoke definitions from pinvoke.net with Microsoft documentation links, enabling quick Windows API prototyping for security…

Malicious DOCX generator exploiting CVE-2021-40444 for remote code execution via crafted Office documents, with integrated hosting server for payload…

Generates malicious DOCX files exploiting CVE-2021-40444 to achieve remote code execution via crafted CAB and HTML payloads, with a built-in hosting…

"In-depth reverse engineering analysis of Vidar Stealer 2.0 covering Task Scheduler tampering (1999 timestamps), Explorer.exe process hollowing, and…

Microsoft HEIF Extension (msheif_store.dll) OOB-read

Documentation of Microsoft's Warbird obfuscation

Sample extensions, scripts, and API uses for WinDbg.

Runtime Windows API interception library for hooking, monitoring, and instrumenting function calls. Supports binary rewriting and DLL injection,…

Universal signature generation for any system function from all Windows Builds using Winbindex

A PowerShell front-end for the Windows debugger engine.

Two IDAPython Scripts help you to reconstruct Microsoft COM (Component Object Model) Code

User-friendly Microsoft Windows Debugger for Malware Analysts.

Enable Microsoft PDB support in Ghidra without installing Visual Studio