Corelan Research

Two decades of exploit development research, techniques, and knowledge — shared openly and for free with the community.

Quick links:

Corelan Exploit Development tutorials
Support the community, get Corelan merchandise
Professional Exploit Development training

All articles:

 CSO : Common Sense Operator/Operations

As the CSO/CISO/person responsible for Information Security, your job is to...  well ... do you even know?  Does upper management …

​ Read More

 HITB2014AMS - Day 2 - On Her Majesty's Secret Service: GRX & A Spy Agency

Last year, Belgacom got hacked by an intelligence service (GCHQ?), Rob says. "What is so interesting about this hack, why did they hack into …

​ Read More

 HITB2014AMS - Day 2 - Exploring and Exploiting iOS Web Browsers

iOS Browsers & UIWebview iOS is very popular (according to StatCounter, it's the 3rd most popular platform used).  Mobile browsers take about …

​ Read More

 HITB2014AMS - Day 2 - Keynote 4: Hack It Forward

Good morning Amsterdam, good morning readers, welcome to the second day of the Hack In The Box conference. The speaker for the first keynote didn't …

​ Read More

 HITB2014AMS - Interview with Katie Moussouris

Hi all, I had the pleasure to meet with Katie Moussouris after her keynote at Hack In The Box. After the announcement that she has left Microsoft …

​ Read More

 HITB2014AMS - Day 1 - State of the ART: Exploring the New Android KitKat Runtime

Good afternoon and welcome back to Hack In the Box.  I can't think of anything better than a talk on ART, the new Android KitKat Runtime, to digest …

​ Read More

Corelan Research is a long-running cybersecurity research project focused on exploit development, vulnerability research and Windows internals.
Since 2009, we have published deep technical tutorials covering topics such as stack-based exploitation, heap exploitation, shellcoding, reverse engineering and debugging.
These tutorials have helped thousands of security researchers, penetration testers, exploit developers and exploit dev trainers learn how modern memory corruption vulnerabilities work.