
nixos-config
Lan Tian's NixOS Configuration

Lan Tian's NixOS Configuration

An embeddable, portable, branchable virtual machine to safely run Agents locally.

Comprehensive set of over 1500 AppArmor profiles to confine Linux system processes, desktops, and services, with support for multiple distributions…

ON NO! Someone put an RPG in a packet sniffer

Immutable Linux OS image optimized for running Incus containers and virtual machines, with UEFI Secure Boot, TPM 2.0 disk encryption, and automated…

Exploit Development and Reverse Engineering with GDB & LLDB Made Easy

Direct Memory Access (DMA) Attack Software

EMBA - The firmware security analyzer

Centralized, TPM 2.0 hardware-backed cryptographic identity enclave and multi-protocol bridge for Linux (FIDO2/CTAP2 WebAuthn Passkeys, OpenSSH…

A serverless networking protocol designed for resilient state synchronization between autonomous agents in fragmented, low-bandwidth networks

SSH agent that creates and manages TPM-sealed keys for hardware-bound authentication, supporting key generation, import, wrapping, PIN protection,…

PS5 exploit chain for firmware 7.00-13.60 combining a WebKit JSC info leak and typedarray corruption with an aio_multi_wait UAF race for kernel…

OWASP framework cataloging the top 10 security risks in neocloud and AI data center infrastructure, covering hardware, networking, isolation,…

Artifacts for the Branch Target Reuse (BTR) Spectre-v2 attack research, including microarchitecture experiments, attack-surface analysis of JIT…

Declarative KVM/QEMU VM orchestration tool using YAML compose files. Manages multi-VM stacks with cloud-init, SSH, PCI passthrough, and image…

Proof-of-concept exploit for Gigabyte's GVCIDrv64.sys kernel driver, achieving local privilege escalation via arbitrary physical memory and I/O port…

GoTEE - example application