Reverse Engineering Deep Dive

The 13-Stage Scan Pipeline Inside Defender

A complete reverse engineering breakdown of mpengine.dll — the monolithic engine behind Windows Defender. Every file scanned on a Windows machine flows through this single 14.3 MB binary.

mpengine.dll v1.1.24120.x · PE32 x86 · 90 exports

Launch Presentation Explore Pipeline GitHub
0Pipeline Stages
0Threat Definitions
0Lua Detection Scripts
0Emulated Win APIs
Architecture

The Complete Scan Pipeline

Presentation Decks

Deep Dive Into Each Stage