
Concierge
Concierge Toolkit: Physical Access Control Identification and Exploitation

Concierge Toolkit: Physical Access Control Identification and Exploitation

sniff HDMI DDC (I2C) traffic

Keystroke injection vulnerabilities in wireless presentation clickers

Build repo from Universal Wifi pineapple hardware cloner

Exploit and tooling for Amlogic-based Sonos devices: dumps OTP/eFUSE via an EL3 exploit, extracts LUKS decryption keys, and fetches/decrypts OTA…

Long Range Pager Systems pagers and coasters URH and YS1 (yardstick one / cc11xx) information and brute force tool

Python-Based Pentesting Framework

A yet non-offical neighbor for the GreatFet One targeting the 433/868/915MHz bands

Card calculator and Proxmark3 Plugin for writing and/or simulating every card type that Doppelgänger Community, Pro, Stealth, and MFAS support.

No-open firmware exploit for the Wyze WLPA19CV2 color bulb

From UART to Root: Breaking Into the Xiaomi C200 via U-Boot

A tool for performing MouseJack keystrokes injection attack.

Make the miko robot a free one

Syma X5SW Telemetry and Transmissor

Reverse Engineering of the Shining App Mask

🛡️ AI-powered portable cybersecurity & pentesting assistant built on ESP32-S3 (LilyGO T-Embed CC1101 & T-Watch S3). Features voice-controlled RF…

Comprehensive reverse engineering and exploitation of CVE-2019-17147, a stack buffer overflow in TP-Link TL-WR841N routers. Includes firmware…

From a bare PCB to root: hardware-hacking a ZyXEL P-870HN (BCM6368) over UART — CVE-2025-0890 + CVE-2024-40891, on my own hardware.