
Concierge
Concierge Toolkit: Physical Access Control Identification and Exploitation

Concierge Toolkit: Physical Access Control Identification and Exploitation

Let's control Secure Boot Chain ourselves.

Wireless mouse/keyboard attack with replay/transmit poc

asadbg is a framework of tools to aid in automating live debugging of Cisco ASA devices

User-friendly Lightweight TPM Remote Attestation over Bluetooth

sniff HDMI DDC (I2C) traffic

RISC-V emulator in Rust that boots Linux with JIT on ARM64/x86_64 and Sv39 virtual memory

a tool designed to help perform and visualize trace-driven cache attacks against software in the secure world of TrustZone-enabled ARMv8 cores

iPod Nano 7G bootrom exploit a bit too late

Remote video eavesdropping using a software-defined radio platform

Spectre exploit

This tool allows to check speculative execution side-channel attacks that affect many modern processors and operating systems designs. CVE-2017-5754…

Live, system-wide USB transfer sniffer in eBPF — decodes USB traffic inline (control SETUP, SCSI, HID) from two universal URB hooks. No usbmon, no…

Report and exploit of CVE-2023-36427

Personal research into the Xbox Series Architecture

HardeningMeter is an open-source Python tool carefully designed to comprehensively assess the security hardening of binaries and systems.

Executes at the silicon boundary

Automated reasoning tool based on the SMACK verifier that detects SGX enclave bugs from trusted boundary violations, including invalid pointer…