#1Hardware hacking, modding, JTAG, UART, SPI, and embedded device exploitation tools.
Kitploit recommended

Protocol client and CLI framework for interacting with wireless hacking devices, enabling security researchers to explore, test, and automate…
The new generation chameleon based on NRF52840 makes the performance of card emulation more stable. And gave the chameleon the ability to read,…

Low-cost open-source software-defined radio platform with hardware designs and firmware for RF transmission, reception, and signal analysis from 1…

Open-source hardware security toolchain for power trace capture, side-channel analysis, and glitching/fault-injection attacks on embedded devices and…

Custom firmware for Flipper Zero enabling Sub-GHz radio, NFC/RFID emulation, infrared, and BadUSB attack features for hardware security testing.

C library providing a portable API for acquiring signals from logic analyzers, oscilloscopes, multimeters, and other test instruments, with…

Boots a custom Linux kernel on rooted LG webOS TVs via kexec, with reverse-engineered SoC watchdog support, framebuffer payloads, and an initramfs…

UNISOC BootROM/FDL flasher for macOS: patched spd_dump with CVE-2022-38694 exec_addr2, protocol reference, partition rules, backup verification…

CVE-2024-56426 Exynos9830 Bootrom Exploit - SM-G985F

From a bare PCB to root: hardware-hacking a ZyXEL P-870HN (BCM6368) over UART — CVE-2025-0890 + CVE-2024-40891, on my own hardware.

Unlocking _everything_ on the CPU with DRAM scrambling

Latency x-ray for undocumented hardware

The open-source wireless research platform for ESP32.

A very very very very very very very long interrupt

The C-based Firmware Patching Framework for Broadcom/Cypress WiFi Chips that enables Monitor Mode, Frame Injection and much more

SPI flash read MitM attack PoC

Bootloader exploit for Google Nest Hub (2nd Gen) (elaine)

Exploit writeups I've authored