
spd_dump-macos
UNISOC BootROM/FDL flasher for macOS: patched spd_dump with CVE-2022-38694 exec_addr2, protocol reference, partition rules, backup verification…

UNISOC BootROM/FDL flasher for macOS: patched spd_dump with CVE-2022-38694 exec_addr2, protocol reference, partition rules, backup verification…

Exploit kit for Exynos 9830 bootROM that delivers signed-boot bypass, custom key injection, and memory-dump payloads for Samsung SM-G985F devices.

From a bare PCB to root: hardware-hacking a ZyXEL P-870HN (BCM6368) over UART — CVE-2025-0890 + CVE-2024-40891, on my own hardware.

Exploits DRAM-controller address scrambling to remap physical memory and access CPU-protected regions, including PSP, SMM, and microcode, on AMD…

Latency x-ray for undocumented hardware

The open-source wireless research platform for ESP32.

A very very very very very very very long interrupt

The C-based Firmware Patching Framework for Broadcom/Cypress WiFi Chips that enables Monitor Mode, Frame Injection and much more

SPI flash read MitM attack PoC

Bootloader exploit for Google Nest Hub (2nd Gen) (elaine)

Exploit writeups I've authored

PCI Express DIY hacking toolkit for Xilinx SP605. This repository is also home of Hyper-V Backdoor and Boot Backdoor, check readme for links and info


Intel Management Engine JTAG Proof of Concept - 2022 Instructions

Firmware for a portable hardware hacking device with RFID/NFC, sub-GHz, infrared, and BLE support for wireless security testing and signal emulation.

Long Range Pager Systems pagers and coasters URH and YS1 (yardstick one / cc11xx) information and brute force tool

Active Bluetooth BR/EDR Sniffer/Injector as cheap as any ESP32 board can get. Works with Scapy ;-)

Curated hub of payloads, dumps, and guides for hardware hacking, RFID/NFC, sub-GHz, and wireless security experimentation.