
fnprint
match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

(Hopefully) A tool to root for (most) Android devices through CVE-2026-43499

Generates per-device kernel offsets from boot.img and compiles a preload library to exploit CVE-2026-43499 Android arm64 local privilege escalation.

From a bare PCB to root: hardware-hacking a ZyXEL P-870HN (BCM6368) over UART — CVE-2025-0890 + CVE-2024-40891, on my own hardware.

Talk to your Intel Management Engine directly — zero-dependency Python tool. Finds memory leaks, partition manifest, live MKHI probing. First public…

The first analysis framework for CPU microcode


Towards Large-Scale Emulation of IoT Firmware for Dynamic Analysis

A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices


A fuzzer for full VM kernel/driver targets

The Binarly Firmware Hunt (FwHunt) rule format was designed to scan for known vulnerabilities in UEFI firmware.

A tool to recover a fully analyzable .ELF from a raw kernel, through extracting the kernel symbol table (kallsyms)

Collection of scripts for reversing Qualcomm Hexagon baseband / modem firmware


