Joe's Lab
  • Home
  • About
WinMine

Reverse Engineering WinMine: Finding the Board Buffer and Mine Placement Logic

Part 2! Previously we identified that the board is held by DAT_01005340. If we want to track down where the mines come in, that seems like a good place to start. What references DAT_01005340? DAT_01005340 XREF[20]: FUN_01002eab:01002eba(*), FUN_01002ed5:01002f04(W), FUN_01002ed5:0

WinMine

Reverse Engineering WinMine: Finding the Board Representation

Disclaimer: This article documents my reverse engineering process for the classic Windows Minesweeper (WinMine). The goal is to understand how the game represents the board internally, not simply to modify it. The Goal I wanted to find where WinMine stores the actual game board in memory. Finding counters such as

QRadar

QRadar: How do I get rid of status messages in the log source app?

Disclaimer: This is my own personal blog and wiki and should not be treated as official advice. Refreshing log source status Log source status should be updated by toggling the log source or restarting ingress. This allows the log sources to reconnect. Sometimes, that doesn't work and the

WinMine

View all →

Reverse Engineering WinMine: Finding the Board Buffer and Mine Placement Logic

Reverse Engineering WinMine: Finding the Board Representation

QRadar

View all →

QRadar: How do I get rid of status messages in the log source app?

  • Sign up
Joe's Lab © 2026. Powered by Ghost