Corelan Research

Two decades of exploit development research, techniques, and knowledge — shared openly and for free with the community.

Quick links:

Corelan Exploit Development tutorials
Support the community, get Corelan merchandise
Professional Exploit Development training

All articles:

 Windows 7 Beta vs Release Candidate

If you are still running Windows 7 Beta, then it’s time to check out the Release Candidate version. Microsoft has reported on the Windows team blog…

​ Read More

 Introduction to Exchange 2010 - free e-Learning Clinic now available

Hi, I just want to share with you that, as reported on the Microsoft Readiness and training blog, Microsoft has released a new free, one-hour …

​ Read More

 Exchange 2007/2010 : Renaming attachments ‘on the fly’ - custom transport agent

It may sound a bit extraordinary, but I needed to have the ability to change attachment filenames while they were being processed by the transport …

​ Read More

 Fixing Exchange 2007 Offline Address Book generation (oalgen) and distribution issues

Today, I’m going to share some ‘notes from the field’ about fixing oab issues in Exchange 2007 In order to fully understand the oab generation and …

​ Read More

 Pro-Exchange website revamped

The 2 most important resources I’m using to stay up-to-date with Exchange are the MS Exchange team blog and the Pro-Exchange website. The …

​ Read More

 Delegating Exchange 2007 Distribution List Management to End Users

One of the challenges that result from operating a messaging environment is making sure the company’s internal Distribution Lists stay up to …

​ Read More

Corelan Research is a long-running cybersecurity research project focused on exploit development, vulnerability research and Windows internals.
Since 2009, we have published deep technical tutorials covering topics such as stack-based exploitation, heap exploitation, shellcoding, reverse engineering and debugging.
These tutorials have helped thousands of security researchers, penetration testers, exploit developers and exploit dev trainers learn how modern memory corruption vulnerabilities work.