Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ABrake27 — iOS 27 kernelcache RE: SEP dispatch map, AMFI diff, Ghidra workflow | Kitploit
Tools/GitHubGitHub/vvirei333/abrake27
iOS SecurityVulnerability AnalysisExploitationMobile App PentestingReverse EngineeringMobile SecurityBinary AnalysisPapers & ResearchLearning & EducationPayload DevelopmentFirmware Analysis
31 day agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
GitHub
vvirei333/abrake27

ABrake27

iOS 27 kernelcache RE: SEP dispatch map, AMFI diff, Ghidra workflow

View Repository
Share

ABrake27

Linux-native cross-compiler + PoC for iOS AMFI Developer Mode activation (arm64/arm64e)

Platform Build Arch

Research-grade toolkit. Diff iOS 27.0.1 vs 27.2 firmware, reverse-engineer the AMFI IOUserClient dispatch table, cross-compile a bare-metal IOKit PoC from Linux — no Xcode required — and enable Developer Mode on iOS 27.0.1 through the stock Apple lockdown protocol (verified persistent at kernel level).


What This Is

  • IPS Firmware Diff — kernelcache, kexts, sandbox, entitlements between iOS 27.0.1 and 27.2 (iPhone 14,5).
  • AMFI dispatch table reverse-engineering — mapped every IOExternalMethodDispatch slot, identified selector 11 = armSecurityBootMode.
  • Standalone C PoC — poc/poc.c opens AppleMobileFileIntegrity/AppleCredentialManager, calls armSecurityBootMode, and logs the result. No Foundation/UIKit bloat — pure C + IOKit.
  • Linux cross-compiler — poc/build_ipa.sh produces a signed .ipa on CachyOS/Arch using clang + ld64.lld + ldid. Zero Apple/Xcode dependencies.

How to enable Developer Mode on iOS 27.0.1 (no jailbreak, no unsigned code)

The iOS Developer Mode toggle chain can be driven entirely through the stock Apple lockdown protocol (com.apple.amfi.lockdown). No jailbreak, no IPA, no entitlement forging — just pymobiledevice3 on Linux.

Verified: after the chain below, mounter query-developer-mode-status → true and the DeveloperDiskImage was mounted at /System/Developer — and both survived an independent reboot (the same checks previously flipped back to false, so persistence is the real proof; see FINDINGS_LOCK.md).

Prerequisite

Remove the passcode (Settings → Face ID & Passcode → Turn Off Passcode). With a passcode set, AMFI answers action=1/action=2 with Device has a passcode set.

Steps

# 1) enable → action=1 → REBOOT #1
flatpak-spawn --host python3 -m pymobiledevice3 amfi enable-developer-mode

# 2) after the device boots: post-restart accept → action=2 → REBOOT #2
#    (the CLI has no separate accept command — call the service method directly,
#     e.g. via poc/verify_now2.py)

# 3) reveal the Settings toggle → action=0
flatpak-spawn --host python3 -m pymobiledevice3 amfi reveal-developer-mode

Verify (kernel-level, independent of the AMFI service)

flatpak-spawn --host python3 -m pymobiledevice3 mounter query-developer-mode-status   # → true
flatpak-spawn --host python3 -m pymobiledevice3 mounter list                           # → IsMounted: true, /System/Developer
flatpak-spawn --host python3 -m pymobiledevice3 mounter auto-mount                    # → DeveloperDiskImage mounted successfully

Protocol summary

actionMeaningEffect
0revealShows the Developer Mode toggle in Settings
1enableSets the flag, reboots the device
2acceptPost-restart confirmation, reboots again

⚠️ pymobiledevice3 short-circuits: if the status is already true, enable-developer-mode just logs "Developer mode is already enabled" and sends nothing. The two reboots are part of the Apple protocol, not incidental.


Quick Start (Linux → iPhone in 4 minutes)

Prerequisites (CachyOS / Arch)

sudo pacman -S clang lld zip          # compiler + Mach-O linker
yay -S ldid                           # entitlement injector (AUR)
# iOS SDK:
mkdir -p poc/SDK
git clone https://github.com/theos/sdks poc/tmp && mv poc/tmp/iPhoneOS*.sdk poc/SDK/iPhoneOS.sdk

Build

cd poc
IOS_SDK=/path/to/iPhoneOS.sdk ./build_ipa.sh
# Output: EnableAMFIDevMode.ipa

Install on iPhone

# Via ideviceinstaller (libimobiledevice):
ideviceinstaller --install EnableAMFIDevMode.ipa

# Via TrollStore (if jailbroken/CT-bypass device):
# → TrollStore app → "+" → pick EnableAMFIDevMode.ipa

# Via SideStore/AltStore:
# → Add to SideStore → sign with your Apple ID

Run

# On device (SSH / NewTerm):
./EnableAMFIDevMode 1
cat /tmp/amfi_devmode_poc.log
# Then REBOOT to activate Developer Mode

Alternative: CoreDevice / DVT launch from Linux (run_dvt.sh)

A second, IPA-free path exists: cross-compile the standalone IOKit binary on Linux and push it to the device through the iOS 17+ CoreDevice / RSD tunnel, then run it with the DVT process-control service (outside the App Sandbox — no installd, no free-sign IPA).

./run_dvt.sh enable      # build (clang + ld64.lld) → deploy → `dvt launch --stream`

run_dvt.sh automates the whole chain:

  1. starts/verifies usbmuxd, checks the device with ideviceinfo (libimobiledevice);
  2. cross-compiles poc/poc.c to a bare arm64 Mach-O (no Apple toolchain): clang -c → ld64.lld -platform_version ios … -syslibroot … -undefined dynamic_lookup; the SDK version is read from the binary SDKSettings.plist via plistlib;
  3. opens a userspace RSD tunnel (pymobiledevice3) and invokes dvt launch --stream.

Status: the Linux cross-compile works (a real arm64 Mach-O is produced). The on-device deploy step is still WIP — see HANDOFF.md «Сессия 12». Also note the PoC’s IOKit path (AppleMobileFileIntegrity selector 11) requires the platform-restricted entitlement com.apple.private.amfi.developer-mode-control, so a non-Apple-signed binary will be refused by the userclient even when launched via DVT — the supported way to enable Developer Mode is the lockdown protocol documented above.


How It Works

Two clean steps per architecture slice (avoids clang driver swallowing -arch/-platform_version when delegating to ld64.lld):

  1. clang -c — Mach-O object, no linking
  2. ld64.lld — executable with explicit -arch arm64 -platform_version ios <min> <sdk>

Auto-detects clang-20...15, ld64.lld/lld, llvm-lipo, ldid. Graceful fallback: arm64e → arm64 if toolchain lacks ptrauth support.


Repo Layout

Download Tool