
RTCore64-probe
A tiny cpp program to test reading memory using a vulnerable RTCore64.sys driver/device (CVE-2019-16098). It tries to read a "secret" from its own…

A tiny cpp program to test reading memory using a vulnerable RTCore64.sys driver/device (CVE-2019-16098). It tries to read a "secret" from its own…

NVIDIA's GPU drivers have a temporal coherence flaw in their memory management. At 587 kHz resonance, the driver's memory pages experience α-decay…

ELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple manufacturers, allows local users to cause a system…

Telenet Enable for Netgear routers from svn checkout http://netgear-telnetenable.googlecode.com/svn/trunk/ netgear-telnetenable-read-only

baton drop (CVE-2022-21894): Secure Boot Security Feature Bypass Vulnerability



Example of using revealed "Spectre" exploit (CVE-2017-5753 and CVE-2017-5715)

Expose USB activity on the fly


Hardware hacker’s flying probe automation stack for agent-driven target discovery, microscope mapping, safety-monitored CNC motion, probe review,…

Reverse engineering NVIDIA SASS instruction dictionary, kernel audits and pattern recognition across GPU architectures.

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

sniff HDMI DDC (I2C) traffic

Report and exploit of CVE-2023-36427

PoC code of Shade BIOS (stripped) presented at Black Hat USA 2025

Linux desktop fingerprint login using a Grow R503 sensor + Arduino + a Rust fprintd-replacement daemon