
umbra
External read-only game overlay for Linux. Derived offsets, composed skeletons, optional kernel module for ptrace-independent memory reads and…

External read-only game overlay for Linux. Derived offsets, composed skeletons, optional kernel module for ptrace-independent memory reads and…

Ghidra plugin that automates UEFI firmware analysis by identifying known GUIDs, protocols, SMI handlers, and interrupt functions, with headless…

GhostLock One-Tap Execution App (CVE-2026-43499)

SM-F9360 (Galaxy Z Fold4, q4q) locked-bootloader KernelSU root — CVE-2026-43499 temp root → LD_PRELOAD DEFEX bypass → no-LTO clang-12 kernelsu.ko.…

Tutorial and source code for building a custom YARA module in C to extract malware configurations, with a practical Danabot example and reusable…

machofile is a module to parse Mach-O binary files

Research on CVE-2025-3052, an Insyde firmware vulnerability that exposes an arbitrary write primitive capable of modifying security-critical pointers.

An IDAPython module for enhancing c++ support on top of ida_kernelcache

nanoMIPS module for Ghidra

Abstracts and expedites the process of backdooring stock firmware images for consumer/SOHO routers

Android Malware Tracker

This is part of a module for the framework that i'm constantly developing. Currently only information of the C2 are disclosed here.

PoC code of Shade BIOS (stripped) presented at Black Hat USA 2025

Technical analysis and proof-of-concept bypass for CVE-2023-33668 in DigiExam proctoring software, demonstrating weak VM detection and native module…

Android Ransomware Development - AES256 encryption + CVE-2019-2215 (reverse root shell) + Data Exfiltration

WinDbg plugin to trace module transitions from a debugged driver.

Ghidra processor description module for NEC/Renesas v810 and v830 families

pefile is a Python module to read and work with PE (Portable Executable) files