


Open-source hardware and software toolkit for reverse-engineering and communicating with infrared-based electronic shelf labels. Includes custom…

Comprehensive reverse engineering and exploitation of CVE-2019-17147, a stack buffer overflow in TP-Link TL-WR841N routers. Includes firmware…

A Curated list of Security Resources for all connected things

Voltage fault-injection modchip for black-box security evaluation of Starlink terminals, bypassing bootloader signature verification to execute…

First open source and publicly available System Management Mode backdoor for UEFI based platforms. Good as general purpose playground for various SMM…

PoC code of Shade BIOS (stripped) presented at Black Hat USA 2025

unleash the full power of your soundcores! :)

FPGA-based 12-channel AM radio broadcast system with formal verification of a hardware watchdog for fail-safe emergency alert transmission in…

Intel Management Engine JTAG Proof of Concept - 2022 Instructions

Reverse Engineering of the Shining App Mask

Intel Management Engine JTAG Proof of Concept

Unlocking _everything_ on the CPU with DRAM scrambling

Official OpenOCD Read-Only Mirror (no pull requests)

Tools for controlling webcam LED on ThinkPad X230

Proxmark3 Amiibo simulator as shown at Recon Montreal 2018

Exploit and tooling for Amlogic-based Sonos devices: dumps OTP/eFUSE via an EL3 exploit, extracts LUKS decryption keys, and fetches/decrypts OTA…