
DMA-ProcessDumper
Simple Process Dumper using DMA over a PCIe FPGA device

Simple Process Dumper using DMA over a PCIe FPGA device
No-open firmware exploit for the Wyze WLPA19CV2 color bulb

Research tooling to boot Linux on iPad mini 1 via checkm8, patched iBSS/iBEC, and custom bare-metal payloads, including device tree port, kernel…

Vankyo MatrixPad S30 (Unisoc SC9863A) — Bootloader unlock via CVE-2022-38694 FDL1 method

Open-source firmware for HydraBus, a multi-tool for embedded hardware debugging, hacking, and penetration testing, supporting protocols like SPI,…

Exploit for CVE-2026-40003, an arbitrary memory write vulnerability in ZXIC/Sanechips ZX297520V3 SoC BootROM, enabling code execution via USB…

Multi-protocol firmware for a hardware hacking tool supporting SPI, I2C, JTAG, UART, 1-Wire, bus sniffing, logic analysis, and microcontroller…

Universal bus interface for hardware hacking and debugging, supporting I2C, SPI, JTAG, UART, and 1-Wire for sniffing, programming, and protocol…

Boots a custom Linux kernel on rooted LG webOS TVs via kexec, with reverse-engineered SoC watchdog support, framebuffer payloads, and an initramfs…

CVE-2024-56426 Exynos9830 Bootrom Exploit - SM-G985F

From a bare PCB to root: hardware-hacking a ZyXEL P-870HN (BCM6368) over UART — CVE-2025-0890 + CVE-2024-40891, on my own hardware.

Unlocking _everything_ on the CPU with DRAM scrambling

Latency x-ray for undocumented hardware

The C-based Firmware Patching Framework for Broadcom/Cypress WiFi Chips that enables Monitor Mode, Frame Injection and much more

Exploit writeups I've authored

Voltage fault-injection modchip for black-box security evaluation of Starlink terminals, bypassing bootloader signature verification to execute…

Intel Management Engine JTAG Proof of Concept - 2022 Instructions