
unleashed-firmware
Custom firmware for Flipper Zero enabling Sub-GHz radio, NFC/RFID emulation, infrared, and BadUSB attack features for hardware security testing.

Custom firmware for Flipper Zero enabling Sub-GHz radio, NFC/RFID emulation, infrared, and BadUSB attack features for hardware security testing.

Proof-of-concept exploit for CVE-2020-25749 targeting Rubetek cameras with hardcoded Telnet credentials, enabling remote root shell access and full…

A suite of WiFi/Bluetooth offensive and defensive tools for the ESP32

Mediatek Flash and Repair Utility

Bluetooth 5 and 4.x LE sniffer for TI CC1352/CC26x2 hardware with support for extended advertising, all PHY modes, MAC/RSSI filtering, and PCAP…

Open-source firmware for HydraBus, a multi-tool for embedded hardware debugging, hacking, and penetration testing, supporting protocols like SPI,…

ESP32DIV is a multi-purpose wireless offensive and defensive toolkit powered by an ESP32

Modern WiFi auditing library for ESP32 using advanced 802.11 techniques. Captures WPA/WPA2/WPA3 handshakes via PMKID extraction and CSA injection…

Reverse Shell CVE for iDRAC 7 & 8 with firmware 2.52.52.52 and below.

Top-level repository for LFI: Practical, Efficient, and Secure Software-based Sandboxing

From UART to Root: Breaking Into the Xiaomi C200 via U-Boot

Low-level kernel modules and device tree source for the OnePlus 11 (sm8550), enabling hardware bring-up, driver analysis, and embedded system…

AirPods liberated from Apple's ecosystem.

Ghidra extension for PC firmware reverse engineering, providing loaders for PCI option ROMs, Intel Flash Descriptor, coreboot CBFS, and UEFI firmware…

Flipper Zero firmware source code

:articulated_lorry: Awesome CAN bus tools, hardware and resources for Cyber Security Researchers, Reverse Engineers, and Automotive Electronics…

CANToolz - framework for black-box CAN network analysis

Temproot for Bravia TV via CVE-2019-2215.