
efiSeek
Ghidra plugin that automates UEFI firmware analysis by identifying known GUIDs, protocols, SMI handlers, and interrupt functions, with headless…

Ghidra plugin that automates UEFI firmware analysis by identifying known GUIDs, protocols, SMI handlers, and interrupt functions, with headless…

Umap2 is the second revision of NCC Group's python based USB host security assessment tool.

baton drop (CVE-2022-21894): Secure Boot Security Feature Bypass Vulnerability

A Linux framework to enable userspace-defined "Virtual" PCIe card shims to enable in-host PCIe card driver development.

Glasses to detect smart-glasses that have cameras. Ray-BANNED

OWASP IoT Security Verification Standard (ISVS)

Tp-Link Archer AX50 Authenticated RCE (CVE-2022-30075)

CVE-2025-31200 is a zero-day, zero-click RCE in iOS CoreAudio’s AudioConverterService, triggered by a malicious audio file via iMessage/SMS.…

A tool which exploits a backdoor in Hikvision camera firmwares circa 2014-2016 to help the owner change a forgotten password.

Gixy-Next: NGINX Configuration Security Scanner & Performance Checker

A QEMU/KVM-based USB fuzzing framework that finds device-driver bugs via reproducible VM execution, multiprocessing, and XML testcase generation.

ATAboy is a user-friendly bridge that allows legacy CHS only style IDE (PATA) hard drives to be connected to a modern computer as a standard USB Mass…

CVE-2022-31705 (Geekpwn 2022 Vmware EHCI OOB) POC


Generate HDCP source and sink keys from the leaked master key

Go Trusted Execution Environment (TEE)

Set of scripts to deal with Cisco ASA firmware [pack/unpack etc.]

Declarative KVM/QEMU VM orchestration tool using YAML compose files. Manages multi-VM stacks with cloud-init, SSH, PCI passthrough, and image…