
emba
EMBA - The firmware security analyzer

EMBA - The firmware security analyzer

Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking

Firmware repository for CatSniffer, a multi-protocol IoT security research board supporting BLE, Zigbee, Sub-1 GHz, and more, with version-specific…

A Curated list of Security Resources for all connected things

Platform independent Near Field Communication (NFC) library

Bluetooth experimentation framework for Broadcom and Cypress chips.

Converting your AR150 to a Wifi Pineapple NANO

Build repo from Universal Wifi pineapple hardware cloner

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

Independent IoT security research, vulnerability disclosures, and PoCs focusing on firmware analysis, hardware interfaces, and cryptographic flaws.

Ultra-lightweight RTOS for IoT with preemptive scheduling, TLS/DTLS, MQTT, CoAP, POSIX compatibility, and MPU-based memory protection. Kernel under…

Curated guide to IoT penetration testing hardware and software tools for 2025, covering Bluetooth, Zigbee, Z-Wave, WiFi, RFID, automotive, and…

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

BLE-based tool that automatically discovers and exploits Shining LED Masks by uploading a custom image without user interaction, proving security…

Proof-of-concept exploit for CVE-2021-34600, demonstrating a key generation vulnerability in Telenot access control systems using Proxmark3 RFID…

*Proof of concept* Attacks a Windows machine running Windows 7 or later, creating a persistent Backdoor.

Proof-of-concept exploit suite for U-Boot bootloader vulnerabilities, including insecure update mechanisms, hardcoded credentials, debugging…

A repository that contains all the working PoC I have crafted for known CVEs, and details on any ongoing research I am currently doing (mostly Iot…