
CVE-2025-27840-WIP
Work-in-progress PoC for CVE-2025-27840, an ESP32 Bluetooth vulnerability involving undocumented HCI commands enabling memory access and device…

Work-in-progress PoC for CVE-2025-27840, an ESP32 Bluetooth vulnerability involving undocumented HCI commands enabling memory access and device…

Linux kernel-space HID injection attack detector using eBPF. Monitors USB and Bluetooth HID devices for anomalous keystroke timing and automatically…

bluetooth mesh chat, IRC vibes

iNTERCEPT, a free and open-source platform that unites the best signal intelligence tools into a single, accessible interface.

Native Android messaging app using Bluetooth LE, TCP, or RNode (LoRa) over LXMF and Reticulum

Monitor your local neighbourhood's bluetooth activity

Hakku Framework penetration testing

The Python Code Tutorials

ESP32DIV is a multi-purpose wireless offensive and defensive toolkit powered by an ESP32

WiFi, Bluetooth and Ethernet Threat Detection.

Snoopy v2.0 - modular digital terrestrial tracking framework

Active Bluetooth BR/EDR Sniffer/Injector as cheap as any ESP32 board can get. Works with Scapy ;-)

Bluetooth Low Energy (BLE) scanner with Resolvable Private Address (RPA) resolution using Identity Resolving Keys (IRKs)

Three-stage Bluetooth BDADDR extraction, DoS & hijack on Fast Pair devices; unpatched primitives outside CVE-2025-36911 scope (no Ubertooth needed)

Reverse-engineered Logi Options+ agent IPC protocol. Switch Logitech multi-host devices programmatically via Unix socket (macOS) or named pipe…

Proof of concept IoT/Ham Radio mesh network with global routing over the internet

Weak encryption in Acer Wireless Keyboard SK-9662 allows attacker in physical proximity to both decrypt wireless keystrokes and inject wireless…

Proof-of-concept and writeup showing how to retrieve Wi-Fi SSID/password from a D-Link Komfy smart switch over BLE by reversing the iOS app’s custom…