


Passive wireless OSINT platform that detects and maps Wi-Fi, Bluetooth, CCTV, IoT devices, and cell towers using radio signal intelligence for…

Mediatek Flash and Repair Utility

Centralized firmware scanning and reporting platform with a web UI, REST API, and automated analysis workflows for securing embedded/IoT devices.

Firmware for converting consumer LoRa radios into KISS TNC modems with serial CLI, BLE packet sniffing, and APRS/AX.25 compatibility for packet radio…

sniff HDMI DDC (I2C) traffic

Automated Application Generation for Stack Overflow Types on Wireless Routers

Exploit and tooling for Amlogic-based Sonos devices: dumps OTP/eFUSE via an EL3 exploit, extracts LUKS decryption keys, and fetches/decrypts OTA…


Instrumented fuzzer for PLC-based ICS control applications, targeting Codesys runtime on Wago controllers to uncover memory corruption and…

Decrypt encrypted SonicOSX firmware images

EDID (Enhanced Display Identification Data) Fuzzer

CVE-2017-5693 Denial of service vulnerability in Puma 6 modems

Explotation framework for CVE-2019-11687

Framework for controlling QKD devices and managing symmetric keys. See the [project page here](https://qcomms.gitlab.io/cqptoolkit/)

Demonstrate some functionalities of Morion by generating an exploit for CVE-2022-27646 (stack buffer overflow on Netgear R6700v3 routers).

Watchguard Sysa-dl file format

RMASmoke main repo. CVE-2025-1122