
DigiTrack
Attacks for $5 or less using Arduino

Attacks for $5 or less using Arduino

sniff HDMI DDC (I2C) traffic

Keystroke injection vulnerabilities in wireless presentation clickers

Firmware repository for CatSniffer, a multi-protocol IoT security research board supporting BLE, Zigbee, Sub-1 GHz, and more, with version-specific…

A ESP32-S3–based usb keylogger with wifi, easy DIY-able with widely available hardware.

Curated guide to IoT penetration testing hardware and software tools for 2025, covering Bluetooth, Zigbee, Z-Wave, WiFi, RFID, automotive, and…

Exploit and tooling for Amlogic-based Sonos devices: dumps OTP/eFUSE via an EL3 exploit, extracts LUKS decryption keys, and fetches/decrypts OTA…

Long Range Pager Systems pagers and coasters URH and YS1 (yardstick one / cc11xx) information and brute force tool

Cisco RV110w UPnP stack overflow

A yet non-offical neighbor for the GreatFet One targeting the 433/868/915MHz bands

Card calculator and Proxmark3 Plugin for writing and/or simulating every card type that Doppelgänger Community, Pro, Stealth, and MFAS support.

A coordinated disclosure and security advisory on Fermax Intercom DTML Injection vulneraiblity. Special thanks to Fermax International for prompt…

Independent IoT security research, vulnerability disclosures, and PoCs focusing on firmware analysis, hardware interfaces, and cryptographic flaws.

No-open firmware exploit for the Wyze WLPA19CV2 color bulb

From UART to Root: Breaking Into the Xiaomi C200 via U-Boot

A tool for performing MouseJack keystrokes injection attack.

BLE-based tool that automatically discovers and exploits Shining LED Masks by uploading a custom image without user interaction, proving security…

From a bare PCB to root: hardware-hacking a ZyXEL P-870HN (BCM6368) over UART — CVE-2025-0890 + CVE-2024-40891, on my own hardware.