

Hardware tool for RFID analysis, emulation, and penetration testing. Supports 125kHz, 13.56MHz protocols (MIFARE, iClass, ISO14443/15693) with key…

EMBA - The firmware security analyzer

Raspberry Pi Pico Arduino core, for all RP2040 and RP2350 boards


Unlocking _everything_ on the CPU with DRAM scrambling


Offline nested attack tool that recovers MIFARE Classic authentication keys using known default or user-supplied keys for assessing NFC/RFID card…

A fully implemented kernel exploit for the PS4 on 5.05FW

First open source and publicly available System Management Mode backdoor for UEFI based platforms. Good as general purpose playground for various SMM…

Bluetooth experimentation framework for Broadcom and Cypress chips.

Mifare Classic Plus - Hardnested Attack Implementation for SCL3711 LibNFC USB reader

A very very very very very very very long interrupt

Simple Windows and Linux keystroke injection tool that exfiltrates stored WiFi data (SSID and password).

Mousejack for ATmega32u4

TPM Genie is an I2C bus interposer for discrete Trusted Platform Modules

Interface for interacting with PlayStation 5 EMC and EFC

Concierge Toolkit: Physical Access Control Identification and Exploitation