
FACT_core
Automated firmware analysis platform that unpacks, analyzes, and compares embedded device firmware to identify components, vulnerabilities, and…

Automated firmware analysis platform that unpacks, analyzes, and compares embedded device firmware to identify components, vulnerabilities, and…

Proof-of-concept exploit for CVE-2024-44815 demonstrating extraction of plaintext router credentials from SPI flash via hardware teardown, UART…

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

Security advisory detailing multiple vulnerabilities in HelpFlash IoT OTA firmware update mechanism, including hard-coded WiFi credentials,…

Flipper Zero app for infrared electronic shelf-label (ESL) protocol research, featuring custom image transmission, NFC tag scanning, and a web-based…

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

Review process for signing UEFI shim bootloaders, providing a structured template for submitting binaries, build logs, and security patch…

Deliberately insecure OpenWrt firmware with OWASP IoT Top 10 vulnerability challenges for hands-on IoT security testing, firmware analysis, and…

Firmware security analysis of BD Alaris 8015 infusion pump: extracts plaintext Wi-Fi credentials, identifies 6 compound vulnerabilities (HTTP…

Static analysis tool that sifts through embedded device firmware to identify vulnerable indicators including SSH/SSL keys, IPs, URLs, shell scripts,…

Lightweight TLS 1.3/DTLS 1.3 library with FIPS 140-3 validated cryptography, hardware entropy support, and post-quantum cipher suites for embedded,…

Post-authentication command injection exploit for Wavlink AC1200 routers. Leverages improper input sanitization in adm.cgi to execute arbitrary shell…

Cross-platform library to parse, modify, and abstract ELF, PE, and MachO executable formats. Supports C++, Python, and Rust APIs with disassembler,…

A Hardware Hacking Tool with Web-Based CLI That Speaks Every Protocol

Raspberry Pi Pico Arduino core, for all RP2040 and RP2350 boards

The C-based Firmware Patching Framework for Broadcom/Cypress WiFi Chips that enables Monitor Mode, Frame Injection and much more

IDA plugin and loader for UEFI firmware analysis and reverse engineering automation

Script for searching the extracted firmware file system for goodies!