
SindriKit
A foundational C library for building operationally credible offensive capabilities

A foundational C library for building operationally credible offensive capabilities

External read-only game overlay for Linux. Derived offsets, composed skeletons, optional kernel module for ptrace-independent memory reads and…

pefile is a Python module to read and work with PE (Portable Executable) files

GhostLock One-Tap Execution App (CVE-2026-43499)

SM-F9360 (Galaxy Z Fold4, q4q) locked-bootloader KernelSU root — CVE-2026-43499 temp root → LD_PRELOAD DEFEX bypass → no-LTO clang-12 kernelsu.ko.…

Research on CVE-2025-3052, an Insyde firmware vulnerability that exposes an arbitrary write primitive capable of modifying security-critical pointers.

An IDAPython module for enhancing c++ support on top of ida_kernelcache

A Magisk module that simplifies running the Frida server on Android, with easy management commands to download specific versions, enable or disable…

"In-depth reverse engineering analysis of an advanced multi-phase loader targeting Shellhost.exe, amsi.dll, mstscax.dll, and clbcatq.dll using module…

GNU Radio out-of-tree (OOT) module for QRadioLink blocks.

Parse BIOS/Intel ME/UEFI firmware related structures: Volumes, FileSystems, Files, etc

Magisk module that auto-packages renef_server (dynamic instrumentation for Android)

Ghidra processor description module for NEC/Renesas v810 and v830 families

Automatically exported from code.google.com/p/firmware-mod-kit

machofile is a module to parse Mach-O binary files

WinDbg plugin to trace module transitions from a debugged driver.

nanoMIPS module for Ghidra

PoC code of Shade BIOS (stripped) presented at Black Hat USA 2025