
sonos
Exploit and tooling for Amlogic-based Sonos devices: dumps OTP/eFUSE via an EL3 exploit, extracts LUKS decryption keys, and fetches/decrypts OTA…

Exploit and tooling for Amlogic-based Sonos devices: dumps OTP/eFUSE via an EL3 exploit, extracts LUKS decryption keys, and fetches/decrypts OTA…


sniff HDMI DDC (I2C) traffic

Exploit Development and Reverse Engineering with GDB & LLDB Made Easy

The C-based Firmware Patching Framework for Broadcom/Cypress WiFi Chips that enables Monitor Mode, Frame Injection and much more

Firmware Analysis and Comparison Tool

Multi-protocol firmware for a hardware hacking tool supporting SPI, I2C, JTAG, UART, 1-Wire, bus sniffing, logic analysis, and microcontroller…

This repository houses the work that ive put into reversing the various encoders and protocols used for customer service buttons in retail shops such…

RP2040 firmware that bridges a Toshiba MK4001MTD 0.85" SDIO microdrive as a USB mass storage device, implementing the full SDIO-ATA protocol stack…

A game modding utility that makes injecting C/C++ code easier.

Tool for reconstructing SPI flash images via logic analyzer captures

Open hardware and software tools for communicating with Miele appliances via their optical diagnostic interface

Tools for controlling webcam LED on ThinkPad X230

Turns any rooted phone into the legendary USB Rubber Ducky. Android USB HID Keystroke Injector

PoC code of Shade BIOS (stripped) presented at Black Hat USA 2025

Proxmark3 Amiibo simulator as shown at Recon Montreal 2018

Exploit writeups I've authored