
holos
Declarative KVM/QEMU VM orchestration tool using YAML compose files. Manages multi-VM stacks with cloud-init, SSH, PCI passthrough, and image…

Declarative KVM/QEMU VM orchestration tool using YAML compose files. Manages multi-VM stacks with cloud-init, SSH, PCI passthrough, and image…

Proof-of-concept exploit for CVE-2026-85769, a heap out-of-bounds read in libtpms TPM 2.0 state deserialization, demonstrating denial of service via…

Minimal machine architecture with LLVM compiler backend, Linux port, and virtual machine for creating self-contained software capsules that remain…

A security assessment of the Beat XP VEGA Smartwatch (Firmware RB303ATV006229) focused on Bluetooth Low Energy (BLE) connectivity revealed a design…

Legion is a Zero-Knowledge Authentication Fabric built for privacy

From UART to Root: Breaking Into the Xiaomi C200 via U-Boot

DeadManSwitch in rust with several triggers (remote local and network)

Documentation of CVE-2025-51643: physical SPI flash extraction on Meitrack T366G-L GPS tracker enabling firmware dump, plaintext credential…

Let's control Secure Boot Chain ourselves.

Reverse Shell CVE for iDRAC 7 & 8 with firmware 2.52.52.52 and below.

baton drop (CVE-2022-21894): Secure Boot Security Feature Bypass Vulnerability

Simple Process Dumper using DMA over a PCIe FPGA device

Proof-of-concept demos and libkdump library demonstrating the Meltdown microarchitectural attack, leaking kernel and physical memory on vulnerable…

Super UEFIinSecureBoot Disk: Boot any OS or .efi file without disabling UEFI Secure Boot

Etherify - bringing the ether back to ethernet

Automated reasoning tool based on the SMACK verifier that detects SGX enclave bugs from trusted boundary violations, including invalid pointer…

A low pin count sniffer for ICEStick - targeting TPM chips

Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking