Inter-binary control flow graphing
☆39Feb 25, 2026Updated 6 months ago
Alternatives and similar repositories for marco
Users that are interested in marco are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- POC tool to abuse windows server failover clusters☆57Aug 7, 2025Updated last year
- Keep it secret, keep it safe☆77Feb 6, 2025Updated last year
- Tool that gathers a customizable set of ETW telemetry and generates user-defined detections☆56Jan 28, 2026Updated 7 months ago
- An example MS-W32T client to show how to use midl.exe in a project managed by CMake☆11Feb 25, 2023Updated 3 years ago
- A local tool for ingesting Windows Patch Tuesday CVEs, diffing patched binaries with Ghidriff and surfacing LLM-generated security analys…☆58Jul 31, 2026Updated last month
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Autonomous Windows POC developer from patchwatch diff reports☆66Jul 30, 2026Updated last month
- rpv-web is a browser based frontend for the rpv library☆28Nov 21, 2025Updated 9 months ago
- Serving payloads only to allowed processes using Windows projected file system feature☆25Feb 7, 2026Updated 6 months ago
- Demonstrates consuming from a SecurityTrace ETW session by consuming from the Threat-Intelligence ETW provider without a driver or PPL pr…☆83Jan 19, 2026Updated 7 months ago
- Windows Portable Device COM BOF☆17Mar 30, 2026Updated 5 months ago
- Thats it! An Open-Source Windows UEFI Rootkit☆42Jul 19, 2025Updated last year
- .NET tool used to enrich RPC telemetry☆102Jan 24, 2026Updated 7 months ago
- WinDbg plugin to trace module transitions from a debugged driver.☆53Dec 22, 2025Updated 8 months ago
- One PsExec client to rule them all☆15Mar 25, 2026Updated 5 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A lightweight Windows Prefetch file parser to extract programs' execution history☆70Jan 12, 2026Updated 7 months ago
- Patchestry is a binary patching framework built with MLIR and Ghidra.☆87Jun 12, 2026Updated 2 months ago
- Demo to show how write ALPC Client & Server using native Ntdll.dll syscalls.☆21Jan 25, 2022Updated 4 years ago
- A Nemesis powered Retrieval-Augmented Generation (RAG) chatbot proof-of-concept.☆70Aug 4, 2025Updated last year
- A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, wit…☆298Feb 21, 2026Updated 6 months ago
- Block Windows Defender by deny ACL☆91Jan 12, 2026Updated 7 months ago
- A simple speed reading application that supports .txt, .pdf, and image text extraction☆17Jun 17, 2026Updated 2 months ago
- Reversed cassandra source code for educational purposes☆35Jul 3, 2026Updated last month
- A few examples of how to trap virtual memory access on Windows.☆40Dec 18, 2024Updated last year
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Source code for XTRIDE: "Practical Type Inference: High-Throughput Recovery of Real-World Structures and Function Signatures"☆26Jun 24, 2026Updated 2 months ago
- Shellcode capable of bypassing EAF / IAF mitigations☆30Apr 11, 2023Updated 3 years ago
- A Ghidra extension for running Kotlin scripts☆16May 21, 2020Updated 6 years ago
- Demos and presentation from SECArmy Village Grayhat 2020☆36Mar 15, 2023Updated 3 years ago
- [DEPRECATED, use specter instead] like ngrok, but ambitious☆37Apr 5, 2022Updated 4 years ago
- Parser and reconciliation tooling for large Active Directory environments.☆33Feb 18, 2025Updated last year
- Havoc Professional backend plugin to allow ingesting of events and logs to Ghostwriter☆16Feb 25, 2026Updated 6 months ago
- Dump LSASS via physical memory read primitives in vulnerable kernel drivers☆340Feb 2, 2026Updated 6 months ago
- ☆56Nov 7, 2024Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Binary Ninja plugin to perform automated analysis of Windows drivers☆20Aug 8, 2019Updated 7 years ago
- Wrapper around Ghidra's analyzeHeadless script☆13Feb 5, 2022Updated 4 years ago
- HvLoader.efi is an EFI application for loading an external hypervisor loader☆73Jun 12, 2023Updated 3 years ago
- LLM-based automated patch diffing☆102Sep 15, 2025Updated 11 months ago
- drvtriks kernel driver for Windows 7 SP1 and 8.1 x64, that tricks around in your system.☆33Oct 6, 2017Updated 8 years ago
- REcon 2024 Repo, slides for talk "GOP Complex: Image parsing bugs, EBC polymorphic engines and the Deus ex machina of UEFI exploit dev""☆14Mar 31, 2025Updated last year
- PoC for exploiting CVE-2026-26128.☆63May 6, 2026Updated 3 months ago