
SwishDbgExt
Incident Response & Digital Forensics Debugging Extension

Incident Response & Digital Forensics Debugging Extension

MAPS cloud scanner and response parser for Microsoft Defender research.

An strace-like program for the Windows 'native' API

Tool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across different versions of the OS, using a Web UI…

Collection of extracted Microsoft Defender data for security research purposes

Curated collection of P/Invoke definitions from pinvoke.net with Microsoft documentation links, enabling quick Windows API prototyping for security…


"In-depth reverse engineering analysis of Vidar Stealer 2.0 covering Task Scheduler tampering (1999 timestamps), Explorer.exe process hollowing, and…

Microsoft HEIF Extension (msheif_store.dll) OOB-read

Documentation of Microsoft's Warbird obfuscation

Sample extensions, scripts, and API uses for WinDbg.

Universal signature generation for any system function from all Windows Builds using Winbindex

A PowerShell front-end for the Windows debugger engine.

Two IDAPython Scripts help you to reconstruct Microsoft COM (Component Object Model) Code

User-friendly Microsoft Windows Debugger for Malware Analysts.

Enable Microsoft PDB support in Ghidra without installing Visual Studio

Root cause analysis and PoC for a Microsoft SQL Server Stack Overflow Vulnerability by reversing svl.dll.