
fwhunt-scan
Tools for analyzing UEFI firmware and checking UEFI modules with FwHunt rules

Tools for analyzing UEFI firmware and checking UEFI modules with FwHunt rules

CERT Kaiju is a binary analysis framework extension for the Ghidra software reverse engineering suite. This repository is a "mirror" -- please file…

Platform security assessment tool for dumping and analyzing UEFI/SMM registers, PCI config space, physical memory, SPI flash, and S3 bootscripts with…

Notes, binaries, and related information from analysis of the CVE-2015-7755 & CVE-2015-7756 issues within Juniper ScreenOS

SentinelNav: zero-dependency, pure Python binary visualization and forensics tool.

Static binary analysis with Detect It Easy — 100% in your browser, no uploads.


wpa3 functionality for the wifi chip in a 2014 macbook pro

IoT protocol threat detection tool that scans devices for vulnerabilities, searches CVEs/PoCs, analyzes firmware, and monitors MQTT/UPnP traffic to…

PoC for CVE-2020-11896 Treck TCP/IP stack and device asset investigation

First public analysis of SoftLanding UEFI bootkit: Ring -2 implant, CVE-2025-7029, 240+ Gigabyte boards, GPU AI evasion, dual C2. YARA + Sigma +…

Binwalk Remote Command Execution

Static reverse-engineering of a GIGABYTE H510M K V2 (`H510MKV2.F3`) BIOS image: full UEFI firmware-volume extraction analysis of the PI-spec SMM Core…

CVE-2025-1242: Hardcoded iothubowner Connection String — Gardyn Home Kit (ICSA-26-055-03)

Hashes and shim versions for the UEFI Secure Boot shims affected by CVE-2026-8863

Bazzite plus a TPM boot attestation layer. Work in progress: builds unverified, UKI mechanism unresolved. Spec: github.com/plunder707/attested-gaming

Files and tools for CVE-2021-26258

DoS against Belkin smart plugs via crafted firmware injection