


First open source and publicly available System Management Mode backdoor for UEFI based platforms. Good as general purpose playground for various SMM…

Heap analysis tooling for mempool

Tools for analyzing and reverse engineering MediaTek baseband firmware, including file extraction, symbol parsing, and Ghidra integration for modem…

Library for WCH CH56x-based boards with tested USB3/USB2/HSPI/SerDes drivers, logging and deferred interrupts

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

Python Command-Line Ghidra MCP

CVE-2025-21479 proof-of-concept, I think

An implementation of the Fusee Gelee exploit (CVE-2018-6242) for the Nintendo Switch, along with a custom payload.


Cookie-based authentication vulnerability on Tk-Rt-Wr135G

Technical writeup for CVE-2024-20154

Research based on https://ktln2.org/2020/03/29/exploiting-mips-router/#testing-environment

LLVM based static binary analysis framework

From Solder to Shell: Full Hardware Exploitation of the Linksys WRT54GL Router (CVE-2022-43973)

A complete browser-based reverse engineering platform built on Rizin, running entirely client-side via WebAssembly.


N-gram-based type recovery tool for binaries, recovering structures and function signatures from decompiled code with high throughput and actionable…