
Phoenix-Rowhammer-Attack-CVE-2025-6202
Phoenix Rowhammer Attack: Systemic Risk of Bitcoin Wallet Private Key Compromise in Global Blockchain Infrastructure Due to a Critical SK Hynix DDR5…

Phoenix Rowhammer Attack: Systemic Risk of Bitcoin Wallet Private Key Compromise in Global Blockchain Infrastructure Due to a Critical SK Hynix DDR5…

Custom firmware for Flipper Zero enabling Sub-GHz radio, NFC/RFID emulation, infrared, and BadUSB attack features for hardware security testing.

Direct Memory Access (DMA) Attack Software

Exploring possibilities of ESP32 platform to attack on nearby Wi-Fi networks.

Inception is a physical memory manipulation and hacking tool exploiting PCI-based DMA. The tool can attack over FireWire, Thunderbolt, ExpressCard,…

Offline nested attack tool that recovers MIFARE Classic authentication keys using known default or user-supplied keys for assessing NFC/RFID card…

Proof-of-concept demonstrating RF replay attack on Honda's remote keyless entry system (CVE-2022-27254) using HackRF One and GNU Radio for signal…

A practical attack framework for precise enclave execution control

Downgrade attack for CVE-2025-48804

Wireless mouse/keyboard attack with replay/transmit poc

OSDP attack tool (and the Elvish word for friend)

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

Proof-of-concept exploit that bypasses ASLR on Intel CPUs by abusing branch target buffer and speculative execution to leak randomized addresses via…

SPI flash read MitM attack PoC

This repository contains the sources and documentation for the LVI-LFB Control Flow Hijacking attack PoC (CVE-2020-0551)

Curated reading list and taxonomy of attack and defense research for mobile on-device AI systems, covering adversarial, backdoor, model stealing, and…

Research repository detailing exploitation techniques against Apple's Display Co-Processor (DCP), including firmware analysis and hardware-level…

Proof-of-concept demonstrating bypass of TPM-bound LUKS disk encryption on Linux systems, extracting volume keys via custom root filesystem attack.