Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Quantum-Silicon-Core-Loader — Executes at the silicon boundary | Kitploit
Tools/GitHubGitHub/sharif-bot-cmd/quantum-silicon-core-loader
Embedded Systems SecurityPrivilege EscalationMemory ForensicsExploitationReverse EngineeringDebuggersFuzzingPenetration TestingHardware Security

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Binary Analysis
Firmware Analysis
GitHubsharif-bot-cmd/quantum-silicon-core-loader

Quantum-Silicon-Core-Loader

Executes at the silicon boundary

View Repository
299222 months agoReviewed by Kitploit

Quantum Silicon Core Loader

Primary Core: qslcl.asm (v0.0.2) (under development)

Assistant Module: qslcl.bin (v0.7.4)

Universal Controller: qslcl.py (v2.2.2)

Legally Protected Research - This project operates under established legal frameworks for security research, right to repair, and academic freedom. Learn more


Overview

Quantum Silicon Core Loader (QSLCL) is a post-bootloader, post-vendor, post-os layer operating directly at the silicon boundary.

It executes beyond traditional security models and is capable of surviving firmware transitions, negotiating trust, and interpreting device state without CVEs or patches.

QSLCL runs in:

  • Qualcomm EDL / Firehose
  • MediaTek BROM / Preloader
  • Apple DFU (Dynamic detection - no hardcoded PIDs)
  • Engineering / META / Diagnostic Modes
  • Any USB/Serial exposed interface

"You don't run QSLCL — silicon interprets it."


What's New in v2.2.2

Slowm8 GETINFO Integration

  • After successful code injection, Slowm8 automatically calls GETINFO to verify device state
  • Confirms injection didn't crash the device
  • Detects and reports abnormal device behavior
  • Adds device_info field to bug reports with status, code, and error details

Enhanced Bug Confirmation

  • Device state verification after every successful injection
  • Abnormal state detection - flags if device shows errors post-injection
  • Rich output in final results showing device status for each confirmed bug

Improved Error Handling

  • Better handling of unresponsive devices after injection
  • Clearer error messages when GETINFO fails
  • Graceful fallback when device doesn't respond to verification

Example output:

[*] Injection confirmed! Fetching device info...
[*] GETINFO response: SUCCESS - OK

[CONFIRMED BUGS]
  1. memory_corruption (conf: 80%)
      Unexpected large response: 2048 bytes
      Device state after injection: SUCCESS - OK
  2. memory_corruption (conf: 75%)
      Unexpected large response: 4096 bytes
      Device state after injection: SUCCESS - OK

QSLCL Binary Layout (v0.7.4):
┌─────────────────────────────────────────────┐
│ 0x000000  QSLCLBIN (Main Header + Ptrs)     │
│ 0x000200+ QSLCLCMD (28 Commands)            │
│ 0x004000+ QSLCLDIS (Dispatch Table)         │
│ 0x005000+ QSLCLUSB (USB Micro-Engine)       │
│ 0x006000+ QSLCLBLK (64 Endpoints)           │
│ 0x007000+ QSLCLBST (Bootstrap Engine)       │
│ 0x008000+ QSLCLVM5 (Nano-Kernel)            │
│ 0x009000+ QSLCLSPT (USB Setup Packets)      │
│ 0x00A000+ QSLCLRTF (Runtime Fault Table)    │
│ 0x00B000+ QSLCLENC (Encryption Layer)       │
│ 0x00C000+ QSLCLDAT (Data Protocol)          │
│ 0x00D000+ QSLCLSYN (Sync Block)             │
│ 0x00E000+ QSLCLHDR (Certificate)            │
│ 0x00F000+ QSLCLINT (Integrity Footer)       │
│ 0x010000+ USB4V2MC (USB4 v2.0 80Gbps)      │
└─────────────────────────────────────────────┘

Total Size: ~72KB (44% reduction from 128KB)
Commands: 28 (added TEST, FUZZ)

How it works (automatic):

# Build with quantum architecture (recommended)
python build.py qslcl.bin --arch quantum --encrypt --usb4-v2

# Or generic build
python build.py qslcl.bin

# Just run normally - watchdog disables automatically!
python qslcl.py hello --loader=qslcl.bin

# Expected output:
# [+] Loader uploaded.
# [*] Auto-disabling watchdog...
# [*] Detected SoC type: APPLE
# [*] Checking 10 candidate offsets...
# [*] Watchdog detected at 0x20E00000 = 0x00000001
# [+] Watchdog disabled at offset 0x20E00000
# [*] Exposing QSLCL in USB configuration...

Complete Command List (v2.2.1)

Core Memory Operations:

CommandDescription
readPartitions Reading
writePartitions Writing
erasePartitions Erasing
peekMemory inspection with type interpretation and pointer analysis
pokePrecision memory writes with bit operations (AND/OR/XOR)
patchBinary patching with backup, verification, and dry-run support
dumpBulk memory dumping with compression, verification, and metadata

Device Interaction:

CommandDescription
helloDevice handshake and capability detection
pingRound-trip latency testing
getinfoShows device, DFU mode, watchdog, loader features

System Control:

CommandDescription
resetSystem reset
powerPower management
configConfiguration management

Voltage & Hardware:

CommandDescription
voltageVoltage read/set/monitor/scale with safety ranges
rawstateLow-level hardware state inspection and manipulation

Security & Analysis:

CommandDescription
rawmodePrivilege escalation with session audit logging
bypassSecurity bypass with auto-detection and enforcement analysis
verifySystem verification
footerFooter analysis with validation and security assessment

Diagnostic & Testing:

CommandDescription
crashControlled crash injection with recovery monitoring
glitchHardware fault injection with parameter scanning
bruteforceAutomated testing
slowm8USB stress tester with auto-detection and bug injection

Manufacturing & ODM:

CommandDescription
oemOEM operations
odmODM operations

Installation & Quick Start

Requirements

pip install pyserial pyusb
pip install pycryptodome   # optional, for crypto operations
pip install capstone        # optional, for disassembly

Basic Usage

# Build with quantum architecture (recommended)
python build.py qslcl.bin --arch quantum --usb4-v2 --encrypt --debug

# Or standard generic build
python build.py qslcl.bin

# Get detailed device information
python qslcl.py getinfo --loader=qslcl.bin

# Expected output:
# ==================================================
# QSLCL DEVICE INFORMATION
# ==================================================
# [DEVICE]
#   Transport: USB
#   VID:PID: 05AC:1281
#   Product: iPhone 15 Pro
#   USB Class: 0xFE (Application Specific)
# 
# [DFU MODE]
#   Status: ACTIVE
#   Generation: A12 or newer (ARM64e, PAC enabled)
# 
# [WATCHDOG]
#   Detected SoC: Apple A-series
#   Typical offset: 0x20E00000
# 
# [QSLCL LOADER]
#   Architecture: quantum
#   Binary size: 73728 bytes (72 KB)
#   Features: Encryption, USB4 v2.0 80Gbps
# ==================================================

# Auto-DFU boot + Loader + Hello (All-in-One)
python qslcl.py hello --loader=qslcl.bin --dfu-boot

# Just boot into DFU mode (like palera1n)
python qslcl.py --dfu-boot

# Test basic functionality
python qslcl.py hello --loader=qslcl.bin --usb4
python qslcl.py ping --loader=qslcl.bin

Slowm8 - USB Stress Tester (v2.2.2)

Enhanced with GETINFO verification! After confirming a bug, Slowm8 automatically fetches device state to verify injection success.

# Basic stress test with device verification
python qslcl.py slowm8 --loader=qslcl.bin

# Expected output with GETINFO:
# [*] Injection confirmed! Fetching device info...
# [*] GETINFO response: SUCCESS - OK
# [+] Bug confirmed! Device state: healthy

Slowm8 Auto-Detection Features

Download Tool