
radio-hackbox
PoC tool to demonstrate vulnerabilities in wireless input devices

PoC tool to demonstrate vulnerabilities in wireless input devices

Flipper Zero firmware source code

ESP32DIV is a multi-purpose wireless offensive and defensive toolkit powered by an ESP32

BLESuite is a Python package that provides an easier way to test Bluetooth Low Energy (BLE) device

Exploitation Framework for Embedded Devices

Firmware repository for CatSniffer, a multi-protocol IoT security research board supporting BLE, Zigbee, Sub-1 GHz, and more, with version-specific…

Bluetooth 5 and 4.x LE sniffer for TI CC1352/CC26x2 hardware with support for extended advertising, all PHY modes, MAC/RSSI filtering, and PCAP…

Reverse-engineered BLE protocol for the CMF Watch Pro 2, documenting GATT layout, AES-128-CBC encrypted command frames, authentication handshake, and…

Passive wireless OSINT platform that detects and maps Wi-Fi, Bluetooth, CCTV, IoT devices, and cell towers using radio signal intelligence for…

Hardware tool for RFID analysis, emulation, and penetration testing. Supports 125kHz, 13.56MHz protocols (MIFARE, iClass, ISO14443/15693) with key…

iNTERCEPT, a free and open-source platform that unites the best signal intelligence tools into a single, accessible interface.

Improper Access Control in Tata Sonata Smartband

Protocol client and CLI framework for interacting with wireless hacking devices, enabling security researchers to explore, test, and automate…

BLE-based C2 server for Hak5 Bash Bunny enabling wireless command injection, payload delivery, and remote control over Bluetooth Low Energy.

Simulated BLE peripheral exposing an unauthenticated GATT firmware-update characteristic; demonstrates critical CVE-2026-22017 device-takeover…

A denial-of-service vulnerability in the AuntyFey BLE smart padlock allows unauthenticated connection floods to lock out legitimate users. …

HomePwn - Swiss Army Knife for Pentesting of IoT Devices

BLE-based Fitbit research tool for authentication replay, encrypted activity dump decryption, memory/firmware extraction, and custom firmware…