
uEmu
Tiny cute emulator plugin for IDA based on unicorn.

Tiny cute emulator plugin for IDA based on unicorn.

First open source and publicly available System Management Mode backdoor for UEFI based platforms. Good as general purpose playground for various SMM…

FPGA based microcomputer sandbox for software and RTL experimentation

An implementation of the Fusee Gelee exploit (CVE-2018-6242) for the Nintendo Switch, along with a custom payload.

Ghidra Processor for the Play Station 2's Emotion Engine MIPS based CPU

Library for WCH CH56x-based boards with tested USB3/USB2/HSPI/SerDes drivers, logging and deferred interrupts


Technical writeup for CVE-2024-20154

Tools for analyzing and reverse engineering MediaTek baseband firmware, including file extraction, symbol parsing, and Ghidra integration for modem…

Provisioning and sharing system for SBCs

CVE-2025-21479 proof-of-concept, I think

N-gram-based type recovery tool for binaries, recovering structures and function signatures from decompiled code with high throughput and actionable…

Heap analysis tooling for mempool

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…


IoTGoat is a deliberately insecure firmware based on OpenWrt.


From Solder to Shell: Full Hardware Exploitation of the Linksys WRT54GL Router (CVE-2022-43973)