Corelan Research

Two decades of exploit development research, techniques, and knowledge — shared openly and for free with the community.

Quick links:

Corelan Exploit Development tutorials
Support the community, get Corelan merchandise
Professional Exploit Development training

All articles:

 Freetools website down ! - Update : website online again

Hello all, Just wanted to let you know that the website hosting my free tools (http://users.telenet.be/internet.activities/freetools or …

​ Read More

 Exchange 2007 - Multi Account Domain to Single Resource Forest replication with IIFP and custom Rules Extension

Introduction The title of this post may be a bit misleading - synchronizing multiple account domains to a single domain or forest is not limited to…

​ Read More

 Merging & Syncing multiple Active Directory databases into one ADAM instance

Keywords : ldap authentication multiple domains combine adam adamsync adschemaanalyzer ldap proxy chain ldifde MS-ADAMSyncconf.xml …

​ Read More

 Free Tool - Cisco Ironport C350 Safelist / Blocklist merge utility

If you have multiple Cisco Ironport C350 devices, you may have noticed that safelist / blocklist entries are bound to an individual device. So if …

​ Read More

 Free tool - Attachment filtering with Exchange 2007/2010 (custom transport agent)

Keywords : microsoft exchange 2007 attachment size filtering quarantine block reject small zip files attached When messaging admins need to …

​ Read More

 Windows 2008 PKI / Certificate Authority (AD CS) basics

Keywords : Windows 2008 PKI Certificate Authority certutil certreq template root CA Enterprise CA convert pfx to pem generate custom certificate …

​ Read More

Corelan Research is a long-running cybersecurity research project focused on exploit development, vulnerability research and Windows internals.
Since 2009, we have published deep technical tutorials covering topics such as stack-based exploitation, heap exploitation, shellcoding, reverse engineering and debugging.
These tutorials have helped thousands of security researchers, penetration testers, exploit developers and exploit dev trainers learn how modern memory corruption vulnerabilities work.