
TempestSDR
Remote video eavesdropping using a software-defined radio platform

Remote video eavesdropping using a software-defined radio platform

Spectre exploit

Live, system-wide USB transfer sniffer in eBPF — decodes USB traffic inline (control SETUP, SCSI, HID) from two universal URB hooks. No usbmon, no…

Security issue in the hypervisor firmware of some older Qualcomm chipsets

DeadManSwitch in rust with several triggers (remote local and network)

Talk to your Intel Management Engine directly — zero-dependency Python tool. Finds memory leaks, partition manifest, live MKHI probing. First public…

From UART to Root: Breaking Into the Xiaomi C200 via U-Boot

A security research tool that identifies and demonstrates the CVE-2025-36911: Fast Pair Pairing Mode Bypass vulnerability

YellowKey BitLocker recovery audits CVE-2026-45585: yellowkey github, TPM, recovery key backup. Windows 10/11 CLI GUI, portable audit tool for…

Tools for reverse engineering and interacting with the PowerG radio protocol

Anviz M3 RFID CVE-2019-11523 PoC

Documentation and reproduction steps for CVE-2022-24693: hardcoded credentials in Baicells Nova436Q and Neutrino 430 firmware, enabling remote SSH…

Extracts hardware random keys from NEC Aterm router firmware images and QR codes to generate valid passwords for gaining shell access.

Osqery extension HP BIOS WMI

Proof-of-concept exploit for CVE-2025-45467, demonstrating remote code execution on Unitree Go1 robotic dogs via insecure MD5-based firmware…

An implementation of the Fusee Gelee exploit (CVE-2018-6242) for the Nintendo Switch, along with a custom payload.

Offensive security tool for printer pentesting

Comprehensive research on security vulnerabilities in autonomous maritime vessels and defense recommendations