
DMA-ProcessDumper
Simple Process Dumper using DMA over a PCIe FPGA device

Simple Process Dumper using DMA over a PCIe FPGA device

Research tooling to boot Linux on iPad mini 1 via checkm8, patched iBSS/iBEC, and custom bare-metal payloads, including device tree port, kernel…

Vankyo MatrixPad S30 (Unisoc SC9863A) — Bootloader unlock via CVE-2022-38694 FDL1 method

USB Rubber Ducky payload that exploits CVE-2021-4034 to escalate privileges and spawn a root shell on Unix-like systems in under 10 seconds.

The new generation chameleon based on NRF52840 makes the performance of card emulation more stable. And gave the chameleon the ability to read,…

Open-source hardware security toolchain for power trace capture, side-channel analysis, and glitching/fault-injection attacks on embedded devices and…

Boots a custom Linux kernel on rooted LG webOS TVs via kexec, with reverse-engineered SoC watchdog support, framebuffer payloads, and an initramfs…

UNISOC BootROM/FDL flasher for macOS: patched spd_dump with CVE-2022-38694 exec_addr2, protocol reference, partition rules, backup verification…

CVE-2024-56426 Exynos9830 Bootrom Exploit - SM-G985F

From a bare PCB to root: hardware-hacking a ZyXEL P-870HN (BCM6368) over UART — CVE-2025-0890 + CVE-2024-40891, on my own hardware.

Unlocking _everything_ on the CPU with DRAM scrambling

SPI flash read MitM attack PoC

Voltage fault-injection modchip for black-box security evaluation of Starlink terminals, bypassing bootloader signature verification to execute…

A list of public attacks on BitLocker

Full duplex 433 MHz Signal jammer, recorder, decoder and hacking multitool device based on ESP32 microcontroller and RFM69HW radios. This version of…

ST25TB / SRx NFC Emulator / Initiator based on TI TRF7970A with MSP430

A Collection of Over 60 Scripts - updated specifically for the BadUSB function on the FlipperZero.

CVE-2022-38694 Hardened Exploit - RP2350 USB Host Auto Flasher for Unisoc devices