Corelan Research

Two decades of exploit development research, techniques, and knowledge — shared openly and for free with the community.

Quick links:

Corelan Exploit Development tutorials
Support the community, get Corelan merchandise
Professional Exploit Development training

All articles:

 HITB2014AMS - Day 1 - Harder, Better, Faster Fuzzer: Advances in BlackBox Evolutionary Fuzzing

Vulnerability Hunting Active security testing, Fabien explains, is the process of generating input which travel in the application, hit a sink and …

​ Read More

 HITB2014AMS - Day 1 - Keynote 2: Building a Strategic Defense Against the Global Threat Landscape

Kristin starts her keynote by explaining that she has been in the business about 22 years ago and used to be in public services.  A long time ago, …

​ Read More

 HITB2014AMS - Day 1 - Keynote 1: Security at the End of the Universe

Good morning friends,  welcome to Hack In The Box 2014, hosted at "De Beurs van Berlage" in the beautiful city of Amsterdam.   This year's edition …

​ Read More

 HITB2014AMS - Hack In The Box / Haxpo 2014 Amsterdam

Dear friends, I'm getting ready for a short trip to Amsterdam, to attend the 5th Hack In The Box conference tomorrow ... and I'm "hashtag" excited …

​ Read More

 On CVE-2014-1770 / ZDI-14-140 : Internet Explorer 8 "0day"

Hi all, I have received a ton of questions regarding a recently published ZDI advisory, which provides some details about a bug I discovered and …

​ Read More

 Happy 5th Birthday Corelan Team

Introduction Corelan Team was founded in September of 2009. Over the last few years, the team has written and published numerous tutorials on …

​ Read More

Corelan Research is a long-running cybersecurity research project focused on exploit development, vulnerability research and Windows internals.
Since 2009, we have published deep technical tutorials covering topics such as stack-based exploitation, heap exploitation, shellcoding, reverse engineering and debugging.
These tutorials have helped thousands of security researchers, penetration testers, exploit developers and exploit dev trainers learn how modern memory corruption vulnerabilities work.