Skip to content
86

Awesome Cybersecurity List

Cybersecurity oriented awesome list

4.2k stars442 forks1,298 entriesLast push Sep 25, 2026 (4 days ago)License CC-BY-SA-4.0

This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.

2026

Part 1

Part 2

Part 3

"A Brief Analysis of a Vulnerability in the Glibc (CVE-2025-4802)"

"A Race Within A Race: Exploiting CVE-2025-38617 in Linux Packet Sockets"

"About PCIe DMA Cheats: Protocol, IOMMU, Hardware, and Detection"

"Achieving remote code execution in LangSmith Playground using unsafe template formatting"

"AI-FI: Reproducing adb to root on Google's TV Streamer using Claude in less than 15 minutes"

"Apache Pony Mail CRLF Injection and SSRF Leading to Full Account Takeover"

"Black Box Probing: a Security Analysis of Xiaomi's MJA1 Secure Chip"

"Break the Trust Chain of the Ethereum Phone"

"BRIDGEROUTER: Automated Capability Upgrading of Out-Of-Bounds Write Vulnerabilities to Arbitrary Memory Write…

"Carbonara: The MediaTek exploit nobody served"

"CHECK Removed, Context Confused, Checkmate Achieved"

"Clang Hardening Cheat Sheet - Ten Years Later"

"CrackArmor: Multiple vulnerabilities in AppArmor"

"Creative approaches to coding FUD Stagers"

"In-the-wild Android Kernel Vulnerability Analysis + PoC"

"Extending The Race Window Without a Kernel Patch"

"Uncovering Chronomaly"

"CVE-2026-0714 TPM-sniffing LUKS Keys on an Embedded Device"

"CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller"

"Damned OOB"

"Defeating Anti-Reverse Engineering: A Deep Dive into the 'Trouble' Binary"

"DiceCTF 2026 Quals - cornelslop: Turning an RCU Double Free into a Cross-Cache Kernel Exploit"

"DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write"

Dirty Frag

In 2 lists

"DIRTYFREE: Simplified Data-Oriented Programming in the Linux Kernel"

"Drone Hacking Part 1: Dumping Firmware and Bruteforcing ECC"

"Exploiting CVE-2024-1065 via the Page Cache"

"Exploiting MediaTek's Download Agent"

"FatGid: A four-byte type, an eight-byte stride, one root shell"

"From DDS Packets to Robot Shells: Two RCEs in Unitree Robots (CVE-2026-27509 & CVE-2026-27510)"

"From KernelSnitch to Practical msg_msg/pipe_buffer Heap KASLR Leaks"

"The Lexer Harness"

"Lessons Learned"

"The Bugs"

"General Graboids: Worms and Remote Code Execution in Command & Conquer"

"Have you patched? Are you sure? The story of the sticky Supermicro BMC bugs"

"Here We Go Again: A Five-Bug Chain to Arbitrary APK Install on Samsung S25"

"HDD Firmware Hacking Part 1"

"Rootkit Taxonomy, Hooking Techniques and Tradecraft"

"Rootkit Detection Engineering"

"How LLMs Actually Work"

"Jenny was a Friend of Mine - MCPs and Friends"

"Intercepting OkHttp at Runtime With Frida - A Practical Guide"

"Leveling Up Secure Code Reviews with Claude Code"

"Living off the Process"

"Make it Blink: Over-the-air Exploitation of the Philips HUE Bridge"

"Mitmproxy for Fun and Profit: Interception and Analysis of Application Traffic"

"N-Day Research with AI: Using Ollama and n8n"

"Needle in the haystack: LLMs for vulnerability research"

"Now You See mi: Now You're Pwned"

"Obfuscation vs the Optimizer: An LLVM Middle-End Arms Race"

"On the Clock: Escaping VMWare Workstation at Pwn2Own Berlin 2025"

"Out-of-Cancel: A Vulnerability Class Rooted in Workqueue Cancellation APIs"

"Page-level UAF exploitation"

"PageJack in Action: CVE-2022-0995 exploit"

"Pwning Supercomputers - A 20yo vulnerability in Munge"

"Reverse Engineering the Tapo C260 and Tapo Discovery Protocol v2"

"Revisiting Two-Shot Kernel Shellcode Execution From Control Flow Hijacking"

"Putting Adaptix to Bed with Crystal Palace"

"CFG, CET, and Stack Spoofing"

"SoK: All You Ever Wanted to Know About Bootloader Security But Were Afraid to Ask"

"Some notes on the security properties of the pipe_buffer kernel object"

"Static Devirtualization of Themida"

"Table Manners: Diving into Linux Pagetables exp techniques"

"TAPOcalypse Now: Exploiting TP-Link Smart Devices From Anywhere"

"The Cost of Understanding: LLM-Driven Reverse Engineering vs Iterative LLM Obfuscation"

"The Hidden Risk of Side-Channel Attacks on Post Quantum Cryptography"

"The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until They Became Pre-Auth RCE in a Security…

"Three Bugs Walk Into a PDF: Prototype Pollution, Served Cold"

"TP-Link ER605 DDNS Pre-Auth RCE: Chaining CVE-2024-5242, CVE-2024-5243, CVE-2024-5244"

"Trailmark turns code into graphs"

"TREVEX: A Black-Box Detection Framework For Data-Flow Transient Execution Vulnerabilities"

"Unauthenticated RCE in NetSupport Manager - A Technical Deep Dive"

"V8 Heap Archaeology: Finding Exploitation Artifacts in Chrome’s Memory"

"A High-Level Look at Binary Vulnerability Detection"

"Detecting a Remote Code Execution Vulnerability in rsync"

"Vulnerability REsearch using VulHunt"

"Inside the Binary Vulnerability Analysis Framework"

"Agentic Vulnerability Research with VulHunt"

"When NAS Vendors Forget How TLS Works"

"Windows ARM64 Internals: Pardon The Interruption! Interrupts on Windows for ARM"

2025

"A File Format Uncracked for 20 Years"

"A First Glimpse of the Starlink User Ternimal"

In 2 lists

"A Fuzzy Escape - A tale of vulnerability research on hypervisors"

"A look at an Android ITW DNG exploit"

"A modern tale of blinkenlights"

"A Quick Dive Into The Linux Kernel Page Allocator"

"A Series of io_uring pbuf Vulnerabilities"

"A Tour of eBPF in the Linux Kernel: Observability, Security and Networking"

"Accidentally Uncovering a Seven Years Old Vulnerability in the Linux Kernel"

"All You Need Is MCP - LLMs Solving a DEF CON CTF Finals Challenge"

"Analysing a 1-day Vulnerability in the Linux Kernel's TLS Subsystem"

"Analyzing IOS Kernel Panic Logs"

"Android: Scudo"

In 2 lists

"Another Crack in the Chain of Trust: Uncovering (Yet Another) Secure Boot Bypass"

"APPROTECT Bypass on NRF52832"

"APT28 Operation Phantom Net Voxel"

"Attacking GenAI applications and LLMs – Sometimes all it takes is to ask nicely!"

"Attention, High Voltage: Exploring the Attack Surface of the Rockwell Automation PowerMonitor 1000"

In 2 lists

"Being Overlord on the Steam Deck with 1 Byte"

In 2 lists

"Part 1 - The Past"

"Part 2 - The Present"

"Beating xloader at Speed: Generative AI as a Force Multiplier for Reverse Engineering"

"Best practices for key derivation"

"Binder Fuzzing"

In 2 lists

"Blasting Past iOS 18"

In 2 lists

"Bluetooth Headphone Jacking: Full Disclosure of Airoha RACE Vulnerabilities"

"Booting into Breaches Hunting Windows SecureBoot's Remote Attack Surfaces"

In 2 lists

"Bootloader to Iris: A Security Teardown of a Hardware Wallet"

"Breaking Disassembly — Abusing symbol resolution in Linux programs to obfuscate library calls"

"Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer"

"Rreaking the Beestation: Inside our Pwn2Own 2025 Exploit Journey"

"Breaking the Sound Barrier Part I: Fuzzing CoreAudio with Mach Messages"

"Broken Trust: Fixed Supermicro BMC Bug Gains a New Life in Two New Vulnerabilities"

"Bug Tamer: Turning Limited Heap Overflow into Full VMware Escape"

"Buried in the Log. Exploiting a 20 years old NTFS Vulnerability"

"Bypassing disk encryption on systems with automatic TPM2 unlock"

"Bypassing MTE with CVE-2025-0072"

In 2 lists

"Callback hell: abusing callbacks, tail-calls, and proxy frames to obfuscate the stack"

"Case Study: Analyzing macOS IONVMeFamily Driver Denial of Service Issue"

"Case Study: IOMobileFramebuffer NULL Pointer Dereference"

"Challenges and Pitfalls while Emulating Six Current Icelandic Household Routers"

In 2 lists

"CimFS: Crashing in memory, Finding SYSTEM (Kernel Edition)"

"Control Flow Hijacking in the Linux Kernel"

"Control Flow Hijacking via Data Pointers"

"corCTF 2025 - corphone"

"Cracking the Pixel 8: Exploiting the Undocumented DSP to Bypass MTE"

"Cross Cache Attack CheetSheet"

In 2 lists

"CVE-2023-52927 - Turning a Forgotten Syzkaller Report into kCTF Exploit"

"CVE-2024-30088 Pwning Windows Kernel @ Pwn2Own Vancouver 2024 (Plus Xbox)"

"CVE-2024-53141: an OOB Write Vulnerability in Netfiler Ipset"

"CVE-2025-23016 - EXPLOITING THE FASTCGI LIBRARY"

"CVE-2025-37752 wo Bytes Of Madness: Pwning The Linux Kernel With A 0x0000 Written 262636 Bytes Out-Of-Bounds"

"CVE-2025-38001 Exploiting All Google kernelCTF Instances And Debian 12 With A 0-Day For $82k: An RBTree Family Drama"

"CVE-2025-6554: The (rabbit) Hole"

"Debugging the Pixel 8 kernel via KGDB"

In 2 lists

"Defeating String Obfuscation in Obfuscated NodeJS Malware using AST"

"Denial of Ruzzing: Rust in the Windows Kernel"

"Dirty Pageflags: Revisiting PTE Exploitation in Linux"

"DirtyPipe-CVE-2022-0847 (0xnull007"

"DirtyPipe-CVE-2022-0847 (stdnoerr"

"Disassembling a binary: linear sweep and recursive traversal"

"Dissecting the macOS 'AppleProcessHub' Stealer: Technical Analysis of a Multi-Stage Attack"

"Don’t Phish-let Me Down: FIDO Authentication Downgrade"

"EL3vated Privileges: Glitching Google WiFi Pro from Root to EL3"

In 2 lists

"Emulating an iPhone in QEMU"

In 2 lists

"Endless Exploits: The Saga of a macOS Vulnerability Struck Nine Times"

"Exploit Development: Investigating Kernel Mode Shadow Stacks on Windows"

"Exploitation of AIxCC Nginx bugs: Part I"

"Exploitation Walkthrough and Techniques - Ivanti Connect Secure RCE (CVE-2025-0282)"

"Exploiting a 13-years old bug on QEMU"

"Exploiting CVE-2024-0582 via the Dirty Pagetable Method"

"Exploiting CVE-2025-21479 on a Samsung S23"

"Exploiting Retbleed in the real world"

"Exploiting the Synology TC500 at Pwn2Own Ireland 2024"

In 2 lists

"Exploiting Zero-Day (CVE-2025–9961) Vulnerability in the TP-Link AX10 Router"

In 2 lists

"Exploiting Heroes of Might and Magic V"

"Exploring Grapheneos Secure Allocator: Hardened Malloc"

"Exploring Heap Exploitation Mechanisms: Understanding the House of Force Technique"

"Eternal-Tux: Crafting a Linux Kernel KSMBD 0-Click RCE Exploit from N-Days"

"Extraction of Synology Encrypted Archives - Pwn2Own Ireland 2024"

"False Injections: Tales of Physics, Misconceptions and Weird Machines"

"Fast & Faulty - A Use After Free in KGSL Fault Handling"

"FiberGateway GR241AG - Full Exploit Chain"

In 2 lists

"First analysis of Apple's USB Restricted Mode bypass (CVE-2025-24200)"

In 2 lists

"FLOP: Breaking the Apple M3 CPU via False Load Output Predictions"

"Fundamental of Virtual Memory"

"From Chrome renderer code exec to kernel with MSG_OOB"

"Game Hacking - Valve Anti-Cheat (VAC)"

"Ghost in the Controller: Abusing Supermicro BMC Firmware Verification"

"Gone in 5 Seconds: How WARN_ON Stole 10 Minutes"

"Google CTF 2025 Quals Writeup"

"Hack The Emulated Planet: Vulnerability Hunting on Planet WGS-804HPT Industrial Switches"

Part 1

In 2 lists

Part 2

"Hacking Sonoff Smart Home IoT Device - Extract, Modify, Boot, Intercept, Clone!"

In 2 lists

"Hacking the Nokia Beacon 1 Router: UART, Command Injection, and Password Generation with Qiling"

"HITCON CTF 2025 -- calc"

"How I ruined my vacation by reverse engineering WSC"

"How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation"

"How Much More Must We Bleed? - Citrix NetScaler Memory Disclosure (CitrixBleed 2 CVE-2025-5777)"

"a trivial SecureBoot bypass for UEFI-compatible firmware based on Insyde H2O"

In 2 lists

"a bit more than just a trivial SecureBoot bypass for UEFI-compatible firmware based on Insyde H2O"

"a fixed SecureBoot bypass for UEFI-compatible firmware based on Insyde H2O"

"Hypervisors for Memory Introspection and Reverse Engineering"

"Kernel Exploitation Techniques: Turning The (Page) Tables"

"Kernel-hack-drill and a new approach to exploiting CVE-2024-50264 in the Linux kernel"

"Inside Riot Vanguard's Dispatch Table Hooks"

"Intercepting HTTPS Communication in Flutter: Going Full Hardcore Mode with Frida"

In 2 lists

Part 1

Part 2

"kASLR Internals and Evolution"

"Kernel-Hack-Drill: Environment For Developing Linux Kernel Exploits"

"KernelSnitch: Side-Channel Attacks on Kernel Data Structures"

"ksmbd vulnerability research"

"Fuzzing Improvements and Vulnerability Discovery"

"Exploiting CVE-2025-37947"

"Laser Fault Injection on a Budget: RP2350 Edition"

"Last barrier destroyed, or compromise of Fuse Encryption Key for Intel Security Fuses"

"Let Me Cook You a Vulnerability: Exploiting the Thermomix TM5"

In 2 lists

"Lifting Binaries, Part 0: Devirtualizing VMProtect and Themida: It's Just Flattening?"

"Linux Kernel Exploitation For Beginners"

"Linux Kernel Hfsplus Slab-out-of-bounds Write"

"Linux kernel Rust module for rootkit detection"

"Llama's Paradox - Delving deep into Llama.cpp and exploiting Llama.cpp's Heap Maze, from Heap-Overflow to Remote-Code…

"LunoBotnet: A Self-Healing Linux Botnet with Modular DDoS and Cryptojacking Capabilities"

"Mali-cious Intent: Exploiting GPU Vulnerabilities (CVE-2022-22706 / CVE-2021-39793)"

"Malware Just Got Its Free Passes Back!"

"MCTF 2025 - Write-up Sec Mem - Pwn"

"mediatek? more like media-rekt, amirite."

"Mindshare: Using Binary Ninja API to Detect Potential Use-after-free Vulnerabilities"

In 2 lists

"Modern (Kernel) Low Fragmentation Heap Exploitation"

"My Emulation Goes to the Moon... Until False Flag"

In 2 lists

"NASA cFS version Aquila Software Vulnerability Assessment"

"nRF51 RBPCONF bypass for firmware dumping"

"One‑Click Memory Corruption in Alibaba’s UC Browser: Exploiting patch-gap V8 vulnerabilities to steal your data"

"Oops! It's a kernel stack use-after-free: Exploiting NVIDIA's GPU Linux drivers"

"Out-of-bound read in ANGLE CopyNativeVertexData from Compromised Renderer"

"Overview of Map Exploitation in v8"

"Paint it Blue: Attacking the Bluetooth Stack"

"Patch-Gapping the Google Container-Optimized OS for $0"

"PatchGuard Internals"

[PatchGuard Internals]

In 2 lists

"PerfektBlue Universal 1-click Exploit to Pwn Automotive Industry"

"Phoenix: Rowhammer Attacks on DDR5 with Self-Correcting Synchronization"

"Print Scan Hacks: Identifying multiple vulnerabilities acro ss multiple Brother devices"

In 2 lists

"Project Rain:L1TF"

"Pwn2Own 2025: Pwning Lexmark’s Postscript Processor"

"Pwn2Own Ireland 2024: Canon imageCLASS MF656Cdw"

In 2 lists

"Pwn2Own Ireland 2024 – Ubiquiti AI Bullet"

In 2 lists

"pyghidra-mcp: Headless Ghidra MCP Server for Project-Wide, Multi-Binary Analysis"

In 2 lists

"Python Dirty Arbitrary File Write to RCE via Writing Shared Object Files Or Overwriting Bytecode Files"

"Qualcomm DSP Kernel Internals"

In 2 lists

"Race Against Time in the Kernel’s Clockwork"

"Recovering Metadata from .NET Native AOT Binaries"

"Reliable system call interception"

"Replacing a Space Heater Firmware Over WiFi"

"Reverse Engineering Hanwha Security Camera Firmware File Decryption with IDA Pro"

"Reverse engineering Realtek RTL8761B* Bluetooth chips, to make better Bluetooth security tools & classes"

"Reversing, Discovering, And Exploiting A TP-Link Router Vulnerability — CVE-2024–54887"

In 2 lists

"Reversing Samsung's H-Arx Hypervisor Framework - Part 1"

In 2 lists

"Reversing the QardioArm"

"Reviving Discarded Vulnerabilities: Exploiting Previously Unexploitable Linux Kernel Bugs Through Control Metadata…

"Reviving the modprobe_path Technique: Overcoming search_binary_handler() Patch"

"Root Shell on Credit Card Terminal"

In 2 lists

"Rooting the TP-Link Tapo C200 Rev.5"

In 2 lists

"ROPing our way to RCE"

In 2 lists

"Running code in a PAX Credit Card Payment Machine"

"RV130X Firmware Analysis"

In 2 lists

"Security through Transparency: Tales from the RP2350 Hacking Challenge"

"smoltalk: RCE in Open Source Agents"

"Solo: A Pixel 6 Pro Story (When one bug is all you need)"

In 2 lists

"SoK: Security of EMV Contactless Payment Systems"

In 2 lists

"Sound and Efficient Generation of Data-Oriented Exploits via Programming Language Synthesis"

"Stack Overflows, Heap Overflows, and Existential Dread"

"State of Linux Snapshot Fuzzing"

In 2 lists

"STM32L05 Voltage Glitching"

In 2 lists

"Streaming Zero-Fi Shells to Your Smart Speaker"

In 2 lists

"Singularity: Deep Dive into a Modern Stealth Linux Kernel Rootkit"

"System Register Hijacking: Compromising Kernel Integrity By Turning System Registers Against the System"

"The Art of Linux Kernel Rootkits"

"The cryptography behind electronic passports"

Part 1

Part 2

"The Journey of Bypassing Ubuntu’s Unprivileged Namespace Restriction"

"TLS NoVerify: Bypass All The Things"

"Tp-Link Router Deep Research"

"Tracing Back to the Source | SPTM Round 3"

"Turning Camera Surveillance on its Axis"

In 2 lists

"Untangling the Knot: Breaking Access Control in Home Wireless Mesh Networks"

In 2 lists

"Use-After-Free Vulnerability in the Can BCM Subsystem Leading to Information Disclosure (CVE-2023-52922)"

"VMware Workstation guest-to-host escape"

"We are ARMed no more ROPpery Here"

In 2 lists

Part 1

In 2 lists

Part 2

In 2 lists

"When Good Kernel Defenses Go Bad: Reliable and Stable Kernel Exploits via Defense-Amplified TLB Side-Channel Leaks"

"Windows arm64 Internals: Deconstructing Pointer Authentication"

"Windows Heap Exploitation - From Heap Overflow to Arbitrary R/W"

Part 1

Part 2

Part 3

Part 4

Part 5

"WireTap: Breaking Server SGX via DRAM Bus Interposition"

"Workshop: Firmware Reverse Engineering"

"Writing a Ghidra processor module"

In 2 lists

"Writing Sync, Popping Cron: DEVCORE's Synology BeeStation RCE & A Novel SQLite Injection RCE Technique…

"yIKEs (WatchGuard Fireware OS IKEv2 Out-of-Bounds Write CVE-2025-9242)"

"You Already Have Our Personal Data, Take Our Phone Calls Too"

"Zen and the Art of Microcode Hacking"

"Zyxel Router Vulnerability Research Zyxel DX3301-T0/EX3301-T0"

2024

"1-click Exploit in South Korea's biggest mobile chat app"

"4 exploits, 1 bug: exploiting cve-2024-20017 4 different ways"

Part 1

Part 2

Part 1

Part 2

"A few notes on AWS Nitro Enclaves: Images and attestation"

In 2 lists

"A first look at Android 14 forensics"

In 2 lists

"A "Gau-Hack" from EuskalHack"

"A Journey From sudo iptables To Local Privilege Escalation"

"A Practical Guide to PrintNightmare in 2024"

"A Technical Deep Dive: Comparing Anti-Cheat Bypass and EDR Bypass "

"A Trip Down Memory Lane"

AArch64 memory and paging

In 2 lists

"An Introduction to Chrome Exploitation - Maglev Edition"

"An unexpected journey into Microsoft Defender's signature World"

"Analysis of CVE-2024-21310 Pool Overflow Windows Cloud Filter Driver"

"Advanced CyberChef Techniques For Malware Analysis - Detailed Walkthrough and Examples"

"AES-GCM and breaking it on nonce reuse"

"Analyzing Mutation-Coded - VM Protect and Alcatraz English"

"ARLO: I'M WATCHING YOU"

In 2 lists

"ASLRn’t: How memory alignment broke library ASLR"

"Attack of the clones: Getting RCE in Chrome’s renderer with duplicate object properties"

"Attacking Android Binder: Analysis and Exploitation of CVE-2023-20938"

In 2 lists

"Automotive Memory Protection Units: Uncovering Hidden Vulnerabilities"

In 2 lists

Part 1

Part 2

"Becoming any Android app via Zygote command injection"

"Beyond Control: Exploring Novel File System Objects for Data-Only Attacks on Linux Systems"

"BGGP4: A 420 Byte Self-Replicating UEFI App For x64"

"Binary type inference in Ghidra"

In 2 lists

"Blackbox-Fuzzing of IoT Devices Using the Router TL-WR902AC as Example"

In 2 lists

"Breaking the Barrier: Post-Barrier Spectre Attacks"

"Breaking Down Adversarial Machine Learning Attacks Through Red Team Challenges"

"Breaking Down Multipart Parsers: File upload validation bypass"

"Breaking the Flash Encryption Feature of Espressif’s Parts"

"Bus Pirate 5: The Swiss ARRRmy Knife of Hardware Hacking"

In 2 lists

"Buying Spying Insights into Commercial Surveillance Vendors"

"Bypassing EDRs With EDR-Preloading"

"Bytecode Breakdown: Unraveling Factorio's Lua Security Flaws"

Part 1

Part 2

Part 3

Part 4

Part 5

"Check Point - Wrong Check Point (CVE-2024-24919)"

"Code injection on Android without ptrace"

"Commonly Abused Linux Initial Access Techniques and Detection Strategies"

"Compiler Options Hardening Guide for C and C++"

In 3 lists

"Continuously fuzzing Python C extensions"

"corCTF 2024: trojan-turtles writeup"

"corMine 1 and 2"

"Cross-Process Spectre Exploitation"

"CVE-2024-20356: Jailbreaking a Cisco appliance to run DOOM"

In 2 lists

"CVE-2022-2586 Writeup"

"CVE-2020-27786 ( Race Condition + Use-After-Free )"

"CVE-2022-4262"

"CVE-2024-5274: A Minor Flaw in V8 Parser Leading to Catastrophes"

"CVE-2023-6246: Heap-based buffer overflow in the glibc's syslog()"

"Declawing PUMAKIT"

Deep Dive into RCU Race Condition: Analysis of TCP-AO UAF (CVE-2024–27394)

"Denial of Pleasure: Attacking Unusual BLE Targets with a Flipper Zero"

In 2 lists

"Deobfuscating Android ARM64 strings with Ghidra: Emulating, Patching, and Automating"

In 2 lists

"Dissecting a complex vulnerability and achieving arbitrary code execution in Ichitaro Word"

"Diving Deep into F5 Secure Vault"

"DJI - The ART of obfuscation"

In 2 lists

"Docker Security – Step-by-Step Hardening (Docker Hardening)"

(2023)

In 3 lists

"Driving forward in Android drivers"

In 2 lists

"Emulating RH850 architecture with Unicorn Engine"

In 2 lists

Part 1

Part 2

"Exploit detail about CVE-2024-26581"

This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.

In 4 lists

"Exploring AMD Platform Secure Boot"

"Exploring GNU extensions in the Linux kernel"

"Exploiting Android’s Hardened Memory Allocator"

In 2 lists

"Exploiting Empire C2 Framework"

Part 1

Part 2

Article 01

Article 02

"Exploiting Steam: Usual and Unusual Ways in the CEF Framework"

"Exploring object file formats"

"Extracting Secure Onboard Communication (SecOC) keys from a 2021 Toyota RAV4 Prime"

In 2 lists

"Fault Injection Attacks against the ESP32-C3 and ESP32-C6"

"Fault Injection – Down the Rabbit Hole"

Part 1

Part 2

"Flatlined: Analyzing Pulse Secure Firmware and Bypassing Integrity Checking"

"Flipping Pages: An analysis of a new Linux vulnerability in nf_tables and hardened exploitation techniques"

"From fault injection to RCE"

"From object transition to RCE in the Chrome renderer"

"Fuzzing between the lines in popular barcode software"

In 2 lists

"Gaining kernel code execution on an MTE-enabled Pixel 8"

In 2 lists

"Ghidra nanoMIPS ISA module"

In 2 lists

"Going Native - Malicious Native Applications"

"Google Chrome V8 CVE-2024-0517 Out-of-Bounds Write Code Execution"

"GhostRace: Exploiting and Mitigating Speculative Race Conditions"

"GPUAF - Two ways of Rooting All Qualcomm based Android phones"

"GraphStrike: Anatomy of Offensive Tool Development"

"Hacking a 2014 tablet... in 2024!"

"Hacking a Smart Home Device"

In 2 lists

"Hacking Android Games"

In 2 lists

"Heap exploitation, glibc internals and nifty tricks"

"HEAP HEAP HOORAY — Unveiling GLIBC heap overflow vulnerability (CVE-2023–6246)"

"Hi, My Name is Keyboard"

In 2 lists

"Hiding Linux Processes with Bind Mounts"

"How I Also Hacked my Car"

In 2 lists

"How to Bypass Golang SSL Verification"

"Hunting Bugs in Linux Kernel With KASAN: How to Use it & What's the Benefit?"

"Hunting down the HVCI bug in UEFI"

"Hunting for Unauthenticated n-days in Asus Routers"

In 2 lists

Part 1

Part 2

"Java Deserialization Tricks"

"JTAG Hacking with a Raspberry Pi"

"Kuiper Ransomware’s Evolution"

"Inside a New OT/IoT Cyberweapon: IOCONTROL"

In 2 lists

"Inside the LogoFAIL PoC: From Integer Overflow to Arbitrary Code Execution"

In 2 lists

"Introduction to Fuzzing Android Native Components"

In 2 lists

Part 1

Part 2

"LeftoverLocals: Listening to LLM responses through leaked GPU local memory"

"Leveraging Binary Ninja il to Reverse a Custom ISA: Cracking the “pot of gold” 37C3"

"Linux Kernel Attack Surface: beyond IOCTL. DMA-BUF"

"Environment"

"ret2usr"

"Listen Up: Sonos Over-The-Air Remote Kernel Exploitation and Covert Wiretap – BlackHat USA 2024 Whitepaper"

In 2 lists

Part 1

Part 2

Part 3

"Mind the Patch Gap: Exploiting an io_uring Vulnerability in Ubuntu"

"Mali GPU Kernel LPE"

[Root for Pixel7/8 Pro with Android 14]

In 2 lists

"MalpediaFLOSSed"

"Microsoft BitLocker Bypasses are Practical"

"Modern implant design: position independent malware development"

"My new superpower"

"Not the Drones You're Looking For"

"Keychain module analysis"

"audio module analysis"

"OtterRoot: Netfilter Universal Root 1-day"

"Out-of-bounds read & write in the glibc's qsort()"

"PageJack: A Powerful Exploit Technique With Page-Level UAF"

"Page-Oriented Programming: Subverting Control-Flow Integrity of Commodity Operating System Kernels with Non-Writable…

"Patch Tuesday Diffing: CVE-2024-20696 - Windows Libarchive RCE"

"Pinning User-space Pages in the Linux Kernel: Exploring get_user_pages, pin_user_pages, and Page Table Walking"

"PixieFail: Nine vulnerabilities in Tianocore's EDK II IPv6 network stack"

In 2 lists

"Playing with libmalloc in 2024"

"Puckungfu 2: Another NETGEAR WAN Command Injection"

In 2 lists

"Pumping Iron on the Musl Heap – Real World CVE-2022-24834 Exploitation on an Alpine mallocng Heap"

"Pwn2Own Automotive 2024: Hacking the ChargePoint Home Flex (and their cloud...)"

In 2 lists

"Pwning browsers like a kernel"

"Pwn2Own: WAN-to-LAN Exploit Showcase, Part 1"

In 2 lists

"Pwn2Own: Pivoting from WAN to LAN to Attack a Synology BC500 IP Camera, Part 2"

In 2 lists

"How it all started"

In 2 lists

"Exploring the Attack Surface"

"Exploration"

"Memory Corruption Analysis"

"The Exploit"

"Pwning a Brother labelmaker, for fun and interop!"

In 2 lists

Part 1

Part 2

Part 3

"Pygmy Goat"

"Recovering an ECU firmware using disassembler and branches"

In 2 lists

"regreSSHion: RCE in OpenSSH's server, on glibc-based Linux systems (CVE-2024-6387)"

"Resolving Stack Strings with Capstone Disassembler & Unicorn in Python"

"Retrofitting encrypted firmware is a Bad Idea"

In 2 lists

"Reverse engineering a car key fob signal "

In 2 lists

"Reverse Engineering and Dismantling Kekz Headphones"

"Reverse Engineering Protobuf Definitions From Compiled Binaries"

"Reverse engineering the 59-pound printer onboard the Space Shuttle"

"Reverse Engineering the AM335x Boot ROM"

"Reverse Engineering The Stream Deck Plus"

Part 1

Part 2

"RISCVuzz: Discovering Architectural CPU Vulnerabilities via Differential Hardware Fuzzing"

"RomCom exploits Firefox and Windows zero days in the wild"

"ROPing Routers from scratch: Step-by-step Tenda Ac8v4 Mips 0day Flow-control ROP -> RCE"

In 2 lists

"Route to Safety: Navigating Router Pitfalls"

"Rooting a Hive Camera"

In 2 lists

"SAME70 Emulator"

In 2 lists

Part 1

Part 2

"Samsung NX related posts"

"Scavy: Automated Discovery of Memory Corruption Targets in Linux Kernel for Privilege Escalation"

"SECGlitcher (Part 1) - Reproducible Voltage Glitching on STM32 Microcontrollers"

In 2 lists

"SELinux bypasses"

[Bypass selinux]

In 2 lists

"SLUB Internals for Exploit Developers"

"SLUBStick: Arbitrary Memory Writes through Practical Software Cross-Cache Attacks within the Linux Kernel"

"Shell We Assemble?"

"Shellcode evasion using WebAssembly and Rust"

"SMI deprivileging (ISRD)"

"Security policy reporting (ISSR)"

"SoK: Where’s the “up”?! A Comprehensive (bottom-up) Study on the Security of Arm Cortex-M Systems"

"Strengthening the Shield: MTE in Heap Allocators"

"Take a Step Further: Understanding Page Spray in Linux Kernel Exploitation"

"The architecture of SAST tools: An explainer for developers"

"The Dark Side of UEFI: A technical Deep-Dive into Cross-Silicon Exploitation"

In 2 lists

"The Definitive Guide to Linux Process Injection"

"The 'Invisibility Cloak' - Slash-Proc Magic"

"The Qualcomm DSP Driver - Unexpectedly Excavating an Exploit"

In 2 lists

"The rev.ng decompiler goes open source + start of the UI closed beta"

In 2 lists

"The tale of a GSM Kernel LP"

"The Wild West of Proof of Concept Exploit Code (PoC)"

Part 1

Part 2

Part 3

"TIKTAG: Breaking ARM’s Memory Tagging Extension with Speculative Execution"

"Tony Hawk’s Pro Strcpy"

"Toolchain Necromancy: Past Mistakes Haunting ASLR"

"TP-Link Firmware Decryption C210 V2 cloud camera bootloaders"

In 2 lists

"TP-Link TDDP Buffer Overflow Vulnerability"

In 2 lists

"Two Bytes is Plenty: FortiGate RCE with CVE-2024-21762"

"Understanding AddressSanitizer: Better memory safety for your code"

"Understanding Unix Garbage Collection and its Interaction with io_uring"

"Understanding Windows x64 Assembly"

by Siew Yi Liang

In 2 lists

"Using Symbolic Execution to Devirtualise a Virtualised Binary"

"Utilizing Cross-CPU Allocation to Exploit Preempt-Disabled Linux Kernel"

"VBA: having fun with macros, overwritten pointers & R/W/X memory"

"Vulnerabilities of Realtek SD card reader driver"

"Why Code Security Matters - Even in Hardened Environments"

"Windows Secure-Launch on Qualcomm devices"

"Windows Sockets: From Registered I/O to SYSTEM Privileges"

"Windows vs Linux Loader Architecture"

"Windows Wi-Fi Driver RCE Vulnerability – CVE-2024-30078"

In 2 lists

"Attaching to a Process"

In 2 lists

"Register State and Stepping"

In 2 lists

"Reading Memory"

In 2 lists

"Exports and Private Symbols"

In 2 lists

"Breakpoints"

In 2 lists

"Stacks"

In 2 lists

"Disassembly"

In 2 lists

"Writing a system call tracer using eBPF"

"Your NVMe Had Been Syz’ed: Fuzzing NVMe-oF/TCP Driver for Linux with Syzkaller"

"x64 Return Address Spoofing"

"x64 Call Stack Spoofing"

2023

"A Deep Dive Into Brute Ratel C4 Payloads"

"A Deep Dive into Penetration Testing of macOS Applications (Part 1)"

"A Deep Dive into TPM-based BitLocker Drive Encryption"

"A Detailed Look at Pwn2own Automotive EV Charger Hardware"

In 2 lists

"A LibAFL Introductory Workshop"

In 2 lists

"A look at CVE-2023-29360, a beautiful logical LPE vuln"

"A Journey Into Hacking Google Search Appliance"

"A new method for container escape using file-based DirtyCred"

"A Pain in the NAS: Exploiting Cloud Connectivity to PWN your NAS: Synology DS920+ Edition"

In 2 lists

"A Potholing Tour in a SoC"

Part 1

In 2 lists

Part 2

In 2 lists

"A Race to Report a TOCTOU: Analysis of a Bug Collision in Intel SMM"

"A Red-Teamer diaries"

"A story about tampering EDRs"

"Abusing Liftoff assembly and efficiently escaping from sbx"

"Abusing RCU callbacks with a Use-After-Free read to defeat KASLR"

"Abusing undocumented features to spoof PE section headers"

"Achieving Remote Code Execution in Steam: a journey into the Remote Play protocol"

"All about LeakSanitizer"

"All cops are broadcasting: TETRA under scrutiny"

In 2 lists

"All my favorite tracing tools: eBPF, QEMU, Perfetto, new ones I built and more"

"An analysis of an in-the-wild iOS Safari WebContent to GPU Process exploit"

"An Introduction into Stack Spoofing"

"Analysis on legit tools abused in human operated ransomware"

Part 1

Part 2

"Analysis of VirtualBox CVE-2023-21987 and CVE-2023-21991"

"Analyzing a Modern In-the-wild Android Exploit"

In 2 lists

"Analyzing an Old Netatalk dsi_writeinit Buffer Overflow Vulnerability in NETGEAR Route"

Part 1

In 2 lists

Part 2

Part 3

Part 4

Part 5

Part 6

Part 7

Part 8

Part 9

Part 10

Part 1

Part 2

"Attacking IoT Devices from Web Perspective"

In 2 lists

"Attacking JS engines: Fundamentals for understanding memory corruption crashes"

"Audio with embedded Linux training"

"Automating C2 Infrastructure with Terraform, Nebula, Caddy and Cobalt Strike"

"b3typer - bi0sCTF 2022"

"Back to the Future with Platform Security"

"Bash Privileged-Mode Vulnerabilities in Parallel Desktop and CDPATH Handling in MacOS"

"Bee-yond Capacity: Unauthenticated RCE in Extreme Networks/Aerohive Wireless APs - CVE-2023-35803"

"Behind the Shield: Unmasking Scudos's Defenses"

In 2 lists

"BlackLotus UEFI bootkit: Myth confirmed"

In 2 lists

"BLUFFS: Bluetooth Forward and Future Secrecy Attacks and Defenses"

"BPF Memory Forensics with Volatility 3"

"Breaking Fortinet Firmware Encryption"

"Breaking the Code - Exploiting and Examining CVE-2023-1829 in cls_tcindex Classifier Vulnerability"

"Breaking Secure Boot on the Silicon Labs Gecko platform"

In 2 lists

"Building a Custom Mach-O Memory Loader for macOS"

"Building an Exploit for FortiGate Vulnerability CVE-2023-27997"

"Bypassing a noexec by elf roping"

"Bypassing PPL in Userland (again)"

"Bypassing SELinux with init_module"

"Remote Code Execution (pre-auth)"

"Unsigned firmware upload lead to persistent backdoor (pre-auth)"

"Memory corruptions lead to Remote Code Execution (pre-auth)"

"CAN Injection: keyless car theft"

In 2 lists

"minidlna 1.3.2 http chunk parsing heap overflow (cve-2023-33476) root cause analysis"

"exploiting cve-2023-33476 for remote code execution"

"Commonly Abused Linux Initial Access Techniques and Detection Strategies"

"Coffee: A COFF loader made in Rust"

"Competing in Pwn2Own ICS 2022 Miami: Exploiting a zero click remote memory corruption in ICONICS Genesis64"

"Chapter 0"

"Chapter 1"

"Chapter 2"

"Chapter 3"

"Chapter 4"

"Cueing up a calculator: an introduction to exploit development on Linux"

Part 1

Part 2

Part 3

"CVE-2022-27666: My file your memory"

"CVE-2023-0179: Linux kernel stack buffer overflow in nftables: PoC and writeup"

"CVE-2023-2008 - Analyzing and exploiting a bug in the udmabuf driver"

"CVE-2023-23504: XNU Heap Underwrite in dlil.c"

"CVE-2023-26258 – Remote Code Execution in ArcServe UDP Backup"

"CVE-2023-36844 And Friends: RCE In Juniper Devices"

"CVE-2023-38408: Remote Code Execution in OpenSSH's forwarded ssh-agent"

"cURL audit: How a joke led to significant findings"

"D^ 3CTF2023 d3kcache: From null-byte cross-cache overflow to infinite arbitrary read & write."

"Debugger Ghidra Class"

A software reverse engineering (SRE) framework created and maintained by the National Security Agency Research Directorate.

In 6 listsDetails

"Debugging D-Link: Emulating firmware and hacking hardware"

In 2 lists

"Decompilation Debugging"

"Deep Lateral Movement in OT Networks: When is a Perimeter not a Perimeter?"

In 2 lists

"Defining the cobalt strike reflective loader"

"Demystifying bitwise operations, a gentle C tutorial"

by Andrei Ciobanu

In 2 lists

"Detecting and decrypting Sliver C2 – a threat hunter’s guide"

"Detecting BPFDoor Backdoor Variants Abusing BPF Filters"

"Dirty Pagetable: A Novel Exploitation Technique To Rule Linux Kernel"

"Dissecting and Exploiting TCP/IP RCE Vulnerability “EvilESP”"

"Diving Into Smart Contract Decompilation"

"Diving into Starlink's User Terminal Firmware"

In 2 lists

"Firmware Analysis"

In 2 lists

"Vulnerability Analysis"

In 2 lists

"Drone Security and Fault Injection Attacks"

Part 1

Part 3

Part 3

"eBPF: A new frontier for malware"

"Emulating IoT Firmware Made Easy: Start Hacking Without the Physical Device"

In 2 lists

"Encrypted Doesn't Mean Authenticated: ShareFile RCE (CVE-2023-24489)"

"ENLBufferPwn (CVE-2022-47949)"

"Escaping the Google kCTF Container with a Data-Only Exploit"

"Exploitation of a kernel pool overflow from a restrictive chunk size (CVE-2021-31969)"

"Exploitation of Openfire CVE-2023-32315"

"Exploiting a Critical Spoofing Vulnerability in Windows CryptoAPI"

"Exploiting a Flaw in Bitmap Handling in Windows User-Mode Printer Drivers"

"Exploiting CVE-2021-3490 for Container Escapes"

"Exploiting null-dereferences in the Linux kernel"

"Exploring UNIX pipes for iOS kernel exploit primitives"

In 2 lists

"EPF: Evil Packet Filter"

"Escaping from Bhyve"

"ESP32-C3 Wireless Adventure A Comprehensive Guide to IoT"

"Espressif ESP32: Breaking HW AES with Electromagnetic Analysis"

"Espressif ESP32: Breaking HW AES with Power Analysis"

"Examining OpenSSH Sandboxing and Privilege Separation – Attack Surface Analysis"

"Executing Arbitrary Code & Executables in Read-Only FileSystems"

"Exploit Engineering – Attacking the Linux Kernel"

"Exploiting a Remote Heap Overflow with a Custom TCP Stack"

"Exploring Hell's Gate"

"Exploiting a bug in the Linux kernel with Zig"

"Exploiting HTTP Parsers Inconsistencies"

"Exploiting MikroTik RouterOS Hardware with CVE-2023-30799"

In 2 lists

"Exploring Android Heap Allocations in Jemalloc 'New'"

"Exploring Linux's New Random Kmalloc Caches"

"Exploring the section layout in linker output"

Part 1

Part 2

Part 3

"Few lesser known tricks, quirks and features of C"

"Finding and exploiting process killer drivers with LOL for 3000$"

"Finding bugs in C code with Multi-Level IR and VAST"

"Exploit detail about CVE-2024-26581"

This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.

In 4 lists

"For Science! - Using an Unimpressive Bug in EDK II to Do Some Fun Exploitation"

In 2 lists

"FortiNAC - Just a few more RCEs"

"Fortinet Series 3 — CVE-2022–42475 SSLVPN exploit strategy"

"Framing Frames: Bypassing Wi-Fi Encryption by Manipulating Transmit Queues"

In 2 lists

"From C, with inline assembly, to shellcode"

"Fuzzing GEGL with fuzzuf"

"Evaluating Performance of Fuzzer"

"Patch Analysis and PoC Development"

"Hunting and Exploiting 0-day [CVE-2022-24834]"

"Fuzzing Golang msgpack for fun and panic"

"Getting RCE in Chrome with incomplete object initialization in the Maglev compiler"

"A Guide to Reversing Shared Objects with Ghidra"

"Reversing a Simple CrackMe with Ghidra Decompiler"

"Vulnerability Hunting with Ghidra"

"Patching a Bug from a Ghidra Listing"

"Vulnerability Analysis with Ghidra Scripting"

"Ghost In The Wire, Sonic In The Wall - Adventures With SonicWall"

"Google Chrome V8 ArrayShift Race Condition Remote Code Execution"

"Hacking a Tapo TC60 Camera"

In 2 lists

"Hacking Amazon's eero 6 (part 1)"

"Hacking Brightway scooters: A case study"

"Hacking ICS Historians: The Pivot Point from IT to OT"

In 2 lists

"Hacking the Nintendo DSi Browser"

In 2 lists

"Hardware Hacking to Bypass BIOS Passwords"

"Heads up! Xdr33, A Variant Of CIA’s HIVE Attack Kit Emerges"

"How a simple K-TypeConfusion took me 3 months long to create a exploit? [HEVD] - Windows 11 (build 22621)"

"How does Linux start a process"

Part 1

Part 2

Part 3

Part 4

Part 1

In 2 lists

Part 2

Part 3

Part 4

Part 5

Part 6

"How I hacked smart lights: the story behind CVE-2022-47758"

In 2 lists

"How to Emulate Android Native Libraries Using Qiling"

In 2 lists

"How to Voltage Fault Injection"

"How To Secure A Linux Server"

An evolving how-to guide for securing a Linux server.

In 7 listsDetails

"Hunting Vulnerable Kernel Drivers"

"Icicle: A Re-designed Emulator for Grey-Box Firmware Fuzzing"

In 2 lists

"In-depth analysis on Valorant’s Guarded Regions"

"In-Memory-Only ELF Execution (Without tmpfs)"

"Intel BIOS Advisory – Memory Corruption in HID Drivers "

"Intercepting Allocations with the Global Allocator"

"Intro to Cutter"

In 2 lists

"Introduction to SELinux"

"Are People Ready to go?"

In 2 lists

"How To Build Kernel Image From Scratch"

"Firmware testing in QEMU"

"Debugging with GDB & GHIDRA + Zero-day"

"JTAG 'Hacking' the Original Xbox in 2023"

"Kernel Exploit Factory"

"Learn Makefiles With the tastiest examples"

by Chase Lambert

In 2 lists

"Let's build a Chrome extension that steals everything"

"Let’s Go into the rabbit hole — the challenges of dynamically hooking Golang programs"

Part 2

Part 3

"Leveraging ssh-keygen for Arbitrary Execution (and Privilege Escalation)"

"lexmark printer haxx"

In 2 lists

linux-re-101

"Linux debugging, profiling and tracing training"

"Getting started & BOF"

"Heap techniques"

"Exploiting race-condition + UAF"

"ret2dir"

"DirtyCred"

"Linux Kernel Unauthenticated Remote Heap Overflow Within KSMBD"

"Linux Kernel Teaching"

In 2 lists

"Linux Malware: Defense Evasion Techniques"

"Exploitation Techniques"

"Privilege Escalation Techniques"

"Persistence Techniques"

List of persistence techniques.

In 2 lists

"Linux Remote Process Injection - (Injecting into a firefox process)"

"Linux rootkits explained – Part 1: Dynamic linker hijacking"

"Linux Shellcode 101: From Hell to Shell"

"Local Privilege Escalation on the DJI RM500 Smart Controller"

In 2 lists

Part 1

Part 2

Part 3

Part 4

Part 5

"Low-Level Software Security for Compiler Developers"

by Bill Wendling, Lucian Popescu, and Anders Waldenborg

In 2 lists

"LPE and RCE in RenderDoc: CVE-2023-33865, CVE-2023-33864, CVE-2023-33863"

"Making TOCTOU Great again – X(R)IP"

Part 1

Part 2

"Man-in-the-Middle Attacks without Rogue AP: When WPAs Meet ICMP Redirects"

In 2 lists

"Introduction – Exploiting the PS4 and PS5 through a game save"

In 2 lists

"Part 1 – Modifying PS2 game save files"

"Part 2 – Arbitrary PS2 code execution"

"Part 3 – Escaping the emulator"

"Mélofée: a new alien malware in the Panda's toolset targeting Linux hosts"

"Meterpreter vs Modern EDR(s)"

Part 1

Part 2

"mTLS: When certificate authentication is done wrong"

"MSMQ QueueJumper (RCE Vulnerability): An in-depth technical analysis"

"Multiple Vulnerabilities in Qualcomm and Lenovo ARM-based Devices"

Part 1

Part 2

"New HiatusRAT Router Malware Covertly Spies On Victims"

"No Alloc, No Problem: Leveraging Program Entry Points for Process Injection"

"NVMe: New Vulnerabilities Made Easy"

"nftables Adventures: Bug Hunting and N-day Exploitation (CVE-2023-31248)"

"Obscure Windows File Types"

"Old Bug, Shallow Bug: Exploiting Ubuntu at Pwn2own Vancouver 2023"

"One shot, Triple kill"

Part 1

In 2 lists

Part 2

Part 3

Part 4

Part 5

"OpenSSH Pre-Auth Double Free CVE-2023-25136 – Writeup and Proof-of-Concept"

"OrBit: advanced analysis of a Linux dedicated malware"

"OrBit: New Undetected Linux Threat Uses Unique Hijack of Execution Flow"

"P2PInfect: The Rusty Peer-to-Peer Self-Replicating Worm"

"P4wnP1-LTE"

"Patches, Collisions, and Root Shells: A Pwn2Own Adventure"

"Patch Tuesday -> exploit Wednesday: Pwning windows ancillary function driver for WinSock (afd.sys) in 24 hours"

"Persistence Techniques That Persist"

"Practical Introduction to BLE GATT Reverse Engineering: Hacking the Domyos EL500"

In 2 lists

"prctl anon_vma_name: An Amusing Linux Kernel Heap Spray"

"Producing a POC for CVE-2022-42475 (Fortinet RCE)"

"Protecting Android clipboard content from unintended exposure"

Part 1

Part 2

Part 3

"Prototype Pollution in Python"

"PSPRAY: Timing Side-Channel based Linux Kernel Heap Exploitation Technique"

"PyLoose: Python-based fileless malware targets cloud workloads to deliver cryptominer"

"PwnAgent: A One-Click WAN-side RCE in Netgear RAX Routers with CVE-2023-24749"

In 2 lists

"Pwnassistant - Controlling /home's via a Home Assistant RCE"

In 2 lists

"Pwning Pixel 6 with a leftover patch"

"Pwning the tp-link ax1800 wifi 6 Router: Uncovered and Exploited a Memory Corruption Vulnerability"

"Racing Against the Lock: Exploiting Spinlock UAF in the Android Kernel"

"Readline crime: exploiting a SUID logic bug"

"Red vs. Blue: Kerberos Ticket Times, Checksums, and You!"

"Reptar"

"Restoring Dyld Memory Loading"

"Retreading The AMLogic A113X TrustZone Exploit Process"

In 2 lists

"Reversing UK mobile rail tickets"

Part 1

Part 2

"RISC-V Bytes: Exploring a Custom ESP32 Bootloader"

"REUnziP: Re-Exploiting Huawei Recovery With FaultyUSB"

"Revisiting CVE-2017-11176"

"Using the "World's Worst Fuzzer" To Find A Kernel Bug"

"Writing an LPE Exploit For Our Overflow Bug"

"Rooting Xiaomi WiFi Routers"

In 2 lists

"Rust Binary Analysis, Feature by Feature"

"Rust to Assembly: Understanding the Inner Workings of Rust"

Part 1

Part 2

Part 3

Part 4

"scudo Hardened Allocator — Unofficial Internals Documentation"

In 2 lists

"Securing our home labs: Frigate code review"

"Securing our home labs: Home Assistant code review"

"SHA-1 gets SHAttered"

"Shambles: The Next-Generation IoT Reverse Engineering Tool to Discover 0-Day Vulnerabilities"

In 2 lists

"Shell in the Ghost: Ghostscript CVE-2023-28879 writeup"

"Shifting boundaries: Exploiting an Integer Overflow in Apple Safari"

"Shooting Yourself in the .flags – Jailbreaking the Sonos Era 100"

"Smart Speaker Shenanigans: Making the Sonos ONE Sing its Secrets"

"Smashing the state machine: the true potential of web race conditions"

"SRE deep dive into Linux Page Cache"

"Sshimpanzee"

"Stepping Insyde System Management Mode"

"Sudoedit bypass in Sudo <= 1.9.12p1 CVE-2023-22809"

"THC's favourite Tips, Tricks & Hacks (Cheat Sheet)"

Various tips & tricks

In 3 lists

"The ARM32 Scheduling and Kernelspace/Userspace Boundary"

"The art of Fuzzing: Introduction"

"The art of fuzzing: Windows Binaries"

"The art of fuzzing-A Step-by-Step Guide to Coverage-Guided Fuzzing with LibFuzzer"

"The Art Of Linux Persistence"

"The Blitz Tutorial Lab on Fuzzing with AFL++"

In 2 lists

"The code that wasn’t there: Reading memory on an Android device by accident"

"The Dragon Who Sold His camaro: Analyzing Custom Router Implant"

"The Importance of Reverse Engineering in Network Analysis"

"The Linux Kernel Module Programming Guide"

by Peter Jay Salzman, Michael Burian, Ori Pomerantz, Bob Mottram, Jim Huang

In 3 lists

"The Most Dangerous Codec in the World: Finding and Exploiting Vulnerabilities in H.264 Decoders"

"The Role of the Control Flow Graph in Static Analysis"

"The Silent Spy Among Us: Smart Intercom Attacks"

In 2 lists

"The Stack Series: The X64 Stack"

"The Untold Story of the BlackLotus UEFI Bootkit"

"Tickling ksmbd: fuzzing SMB in the Linux kernel"

"Tool Release: Cartographer"

"Total Identity Compromise: Microsoft Incident Response lessons on securing Active Directory"

"Xortigate, or CVE-2023-27997 - The Rumoured RCE That Was"

"Ubuntu Shiftfs: Unbalanced Unlock Exploitation Attempt"

"Unauthenticated RCE on a RIGOL oscilloscope"

"UNCONTAINED: Uncovering Container Confusion in the Linux Kernel"

"Uncovering a crazy privilege escalation from Chrome extensions"

"Uncovering HinataBot: A Deep Dive into a Go-Based Threat"

"Under The Hood - Disassembling of IKEA-Sonos Symfonisk Speaker Lamp"

"Understanding a Payload’s Life Featuring Meterpreter & Other Guests "

"Understanding Dirty Pagetable - m0leCon Finals 2023 CTF Writeup"

"Understanding the Heap - a beautiful mess"

"Unleashing ksmbd: crafting remote exploits of the Linux kernel"

"Unlimited Results: Breaking Firmware Encryption of ESP32-V3"

"creating an open-source MAC Layer"

In 2 lists

"reverse engineering RX"

In 2 lists

"Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More"

In 2 lists

"What is Loader Lock?"

"Windows Installer arbitrary content manipulation Elevation of Privilege (CVE-2020-0911)"

"Windows Installer EOP (CVE-2023-21800)"

"Writing your own RDI /sRDI loader using C and ASM"

"Zenbleed"

"Zero Effort Private Key Compromise: Abusing SSH-Agent For Lateral Movement"

2022

"Chip identification, BUSSide, and I2C"

"Discover components and ports"

In 2 lists

"Firmware dump and analysis"

In 2 lists

"Radio communications"

In 2 lists

"Internal communications"

In 2 lists

"A Kernel Hacker Meets Fuchsia OS"

part 1

Part 2

Part 3

"ALL ABOUT USB-C: INTRODUCTION FOR HACKERS"

In 2 lists

"An In-Depth Look at the ICE-V Wireless FPGA Development Board"

In 2 lists

"Basic definitions and registers"

"Offset and Addressing modes"

"Load and Store"

"Branch"

"Data Processing (Part 1)"

"Data Processing (Part 2)"

"selections and loops"

"Subroutines"

"Attacking the Android kernel using the Qualcomm TrustZone"

In 2 lists

"Attacking Titan M with Only One Byte"

"Avoiding Detection with Shellcode Mutator"

"Hardware Analysis / SPI Flash Extraction"

In 2 lists

"Reverse Engineering Firmware / Reflashing SPI Flash"

In 2 lists

"Dumping Parallel Flash via I2C I/O Expanders"

"I2C Sniffing, EEPROM Extraction and Parallel Flash Extraction"

"Basics for Binary Exploitation"

"Breaking Secure Boot on Google Nest Hub (2nd Gen) to run Ubuntu"

In 2 lists

"BrokenPrint: A Netgear stack overflow"

"Extracting the Lexmark MC3224i printer firmware"

"Exploiting the Lexmark MC3224i printer"

"Bypassing vtable Check in glibc File Structures"

"Blind Exploits to Rule Watchguard Firewalls"

"BPFDoor - An Evasive Linux Backdoor Technical Analysis"

"Canary in the Kernel Mine: Exploiting and Defending Against Same-Type Object Reuse"

Part 1

Part 2

Part 3

"Competing in Pwn2Own 2021 Austin: Icarus at the Zenith"

"CoRJail: From Null Byte Overflow To Docker Escape Exploiting poll_list Objects In The Linux Kernel"

"Corrupting memory without memory corruption"

"Creating a Rootkit to Learn C"

"CVE-2022-0435: A Remote Stack Overflow in The Linux Kernel"

"[CVE-2022-1786] A Journey To The Dawn"

"CVE-2022-2602: DirtyCred File Exploitation applied on an io_uring UAF"

"CVE-2022-27666: Exploit esp6 modules in Linux kernel"

"CVE-2022-29582 An io_uring vulnerability"

"Deconstructing and Exploiting CVE-2020-6418"

"DirtyCred Remastered: how to turn an UAF into Privilege Escalation"

"Disclosing information with a side-channel in Django"

"Dumping the Amlogic A113X Bootrom"

In 2 lists

"Dynamic analysis of firmware components in IoT devices"

In 2 lists

"Embedded Systems Security and TrustZone"

In 2 lists

"Emulate Until You Make it"

"EntryBleed: Breaking KASLR under KPTI with Prefetch (CVE-2022-4543)"

"Expanding the Dragon: Adding an ISA to Ghidra"

"Exploiting: Buffer overflow in Xiongmai DVRs"

"Exploiting CSN.1 Bugs in MediaTek Basebands"

In 2 lists

"exploiting CVE-2019-2215"

"Exploiting CVE-2022-42703 - Bringing back the stack attack"

"Exploration of the Dirty Pipe Vulnerability (CVE-2022-0847)"

"Exploring the Hidden Attack Surface of OEM IoT Devices"

"Firmware key extraction by gaining EL3"

"Fortigate - Authentication Bypass Lead to Full Device Takeover"

"Prologue"

"Hole"

"Sandbox"

"Fuzzing ping(8) … and finding a 24 year old bug"

Part 1

In 2 lists

Part 2

In 2 lists

Part 3

In 2 lists

"Hackign More Secure Portable Storage Devices"

"How did I approach making linux LKM rootkit, “reveng_rtkit” ?"

"How The Tables Have Turned: An analysis of two new Linux vulnerabilities in nf_tables"

"Huawei Security Hypervisor Vulnerability"

Part 1

Part 2

Part 3

Part 4

Part 5

Part 1

Part 2

"Learning eBPF exploitation"

"Tools and Series"

In 2 lists

"UART Discovery and Firmware Extraction via UBoot"

In 2 lists

Part 1

Part 2

Part 3

Part 4

Part 5

"io_uring - new code, new bugs, and a new exploit technique"

"Linux Hardening Guide"

In 2 lists

"Linux Kernel: Exploiting a Netfilter Use-after-Free in kmalloc-cg"

"Linux Kernel Exploit (CVE-2022–32250) with mqueue"

Part 1

Part 2

Part 3

Part 4

"Linternals: Introducing Memory Allocators & The Page Allocator"

"Linternals: The Slab Allocator"

"Linux kernel heap feng shui in 2022"

"Looking for Remote Code Execution bugs in the Linux kernel"

"Manipulating AES Traffic using a Chain of Proxies and Hardcoded Keys"

"MeshyJSON: A TP-Link tdpServer JSON Stack Overflow"

"Missing Manuals - io_uring worker pool"

"Modifying Embedded Filesystems in ARM Linux zImages"

"orbi hunting 0x0: introduction, uart access, recon"

"orbi hunting 0x1: crashes in soap-api"

"nday exploit: netgear orbi unauthenticated command injection (cve-2020-27861)"

"nday exploit: libinput format string bug, canary leak exploit (cve-2022-1215)"

"NFC Relay Attack on Tesla Model Y"

In 2 lists

"Nightmare: One Byte to ROP // Deep Dive Edition"

"Overview of GLIBC heap exploitation techniques"

"Parsing TFTP in Rust"

"Patching, Instrumenting & Debugging Linux Kernel Modules"

"PCIe DMA Attack against a secured Jetson Nano (CVE-2022-21819)"

In 2 lists

"pipe_buffer arbitrary read write"

"Booting up"

In 2 lists

"Emulation, ROP"

"Exploitation"

"Port knocking from the scratch"

"Pulling MikroTik into the Limelight"

In 2 lists

"Racing against the clock -- hitting a tiny kernel race window"

"Replicating CVEs with KLEE"

"Reversing C++, Qt based applications using Ghidra"

"Racing Cats to the Exit: A Boring Linux Kernel Use-After-Free"

"Replicant: Reproducing a Fault Injection "

"Researching Xiaomi’s Tee to Get to Chinese Money"

In 2 lists

Part 1

Part 2

"Reverse Engineering a Cobalt Strike Dropper With Binary Ninja"

"Reverse engineering an EV charger"

In 2 lists

"Connection"

"Packets"

"Key Exchange"

"Reliable UDP"

"Reverse engineering integrity checks in Black Ops 3"

"Reverse engineering thermal printers"

"Reviving Exploits Against Cred Structs - Six Byte Cross Cache Overflow to Leakless Data-Oriented Kernel Pwnage"

"SETTLERS OF NETLINK: Exploiting a limited UAF in nf_tables (CVE-2022-32250)"

"Shedding Light on Huawei's Security Hypervisor"

"Shikitega - New stealthy malware targeting Linux"

"side channels: power analysis"

"side channels: using the chipwhisperer"

"SIM Hijacking"

In 2 lists

"Spoofing Call Stacks To Confuse EDRs"

"SROP Exploitation with radare2"

"Stealing the Bitlocker key from a TPM"

"Stranger Strings: An exploitable flaw in SQLite"

"Survey of security mitigations and architectures, December 2022"

"Symbiote Deep-Dive: Analysis of a New, Nearly-Impossible-to-Detect Linux Threat"

"Tetsuji: Remote Code Execution on a GameBoy Colour 22 Years Later"

"The Dirty Pipe Vulnerability"

"The Last Breath of Our Netgear RAX30 Bugs - A Tragic Tale before Pwn2Own Toronto 2022"

In 2 lists

"The Old, The New and The Bypass - One-click/Open-redirect to own Samsung S22 at Pwn2Own 2022"

"Part 1"

"Part 2"

"Overflows"

"Use After Free & Double free"

"FastBin Dup to Stack"

"FastBin Dup Consolidate"

"Unsafe Unlink"

"House of Spirit"

"House of Lore"

"TP-Link Tapo c200 Camera Unauthenticated RCE (CVE-2021-4045)"

In 2 lists

"Tracing and Manipulating with DynamoRIO"

"Trying To Exploit A Windows Kernel Arbitrary Read Vulnerability"

"Turning Google smart speakers into wiretaps for $100k"

In 2 lists

"UWB Real Time Locating Systems: How Secure Radio Communications May Fail in Practice'"

In 2 lists

"Vulnerabilities and Hardware Teardown of GL.iNET GL-MT300N-V2 Router"

Part 1

Part 2

"Vulnerability Details for CVE-2022-41218"

"Vulnerabilities in Tenda's W15Ev2 AC1200 Router"

"When an N-Day turns into a 0day"

"WPAxFuzz: Sniffing Out Vulnerabilities in Wi-Fi Implementations"

In 2 lists

"Write a Linux firewall from scratch based on Netfilter"

"Yet another bug into Netfilter"

"Xiongmai IoT Exploitation"

"Zyxel authentication bypass patch analysis (CVE-2022-0342)"

2021

"Introduction"

"DOS Header, DOS Stub and Rich Header"

"NT Headers"

"Data Directories, Section Headers and Sections"

"Imports (Import Direcory Table, ILT, IAT)"

"PE Base Relocations"

"Writing a PE Parser"

"A Nerve-Racking Bug Collision in Samsung's NPU Driver"

Part 1

Part 2

"Attacking Samsung RKP"

"Automatic unpacking with Qiling framework"

"BRAKTOOTH: Causing Havoc on Bluetooth Link Manager"

In 2 lists

"Breaking 64 bit aslr on Linux x86-64"

"Bypassing GLIBC 2.32’s Safe-Linking Without Leaks into Code Execution: The House of Rust"

"Complete Guide to Stack Buffer Overflow (OSCP Preparation)"

"CVE-2020-3992 & CVE-2021-21974: Rre-auth Remote Code Execution in VMWare esxi"

"CVE-2021–20226 a reference counting bug which leads to local privilege escalation in io_uring."

"CVE-2021-22555: Turning \x00\x00 into 10000$"

"Da Vinci Hits a Nerve: Exploiting Huawei’s NPU Driver"

Part 1

Part 2

"Exploiting crash handlers: LPE on Ubuntu"

"Extending Ghidra Part 1: Setting up a Development Environment"

In 2 lists

"Fire of Salvation Writeup: Utilizing msg_msg Objects for Arbitrary Read and Arbitrary Write in the Linux Kernel"

"Debugging with GDB & GHIDRA + Zero-day"

"Speed Improvements to Part I"

"Fuzzing libexif"

"Getting to know memblock"

"Cursor Text Highlighting"

In 2 lists

"Slice Highlighting"

"Decoding Stack Strings"

In 2 lists

"Loading Windows Symbols (PDB files)"

"Creating Structures in Ghidra"

"Loading Windows Symbols (PDB files) in Ghidra 10.x"

"GRCON 2021 - Capture the Signal"

In 2 lists

Part 1

Part 2

Part 3

"How AUTOSLAB Changes the Memory Unsafety Game"

Part 1

Part 2

Part 3

Part 1

"Linux Internals: How /proc/self/mem writes to unwritable memory"

"Debugging the Kernel with QEMU"

"Smashing Stack Overflows in the Kernel"

"Controlling RIP and Escalating privileges via Stack Overflow"

Part 2

Part 3

Part 1

Part 2

Part 3

Part 4

Part 5

Part 6

Part 7

Part 8

Part 9

"mooosl"

"My RCE PoC walkthrough for (CVE-2021–21974) VMware ESXi OpenSLP heap-overflow vulnerability"

"New Linux Backdoor RedXOR Likely Operated by Chinese Nation-State Actor"

"New Old Bugs in the Linux Kernel"

"Practical Introduction to CodeQL"

"Pwn2Own Tokyo 2020: Defeating the TP-link AC1750"

In 2 lists

"Recovering a Full PEM Private key when Half of it is Redacted"

"Reverse Engineering an Unknown Microcontroller"

In 2 lists

Part 1

Part 3

"Reverse Engineering Yaesu FT-70D Firmware Encryption"

Part 1

Part 2

Part 3

"The Art of Exploiting UAF by Ret2bpf in Android Kernel"

"The Oddest Place You Will Ever Find PAC"

"Unveiling Evasive Techniques Employed by Malicious Linux Shell Scripts"

Part 1

Part 2

"Wall Of Perdition: Utilizing msg_msg Objects For Arbitrary Read And Arbitrary Write In The Linux Kernel"

2020

Part 1

Part 2

Part 3

"An iOS hacker tries Android"

In 2 lists

Part 1

Part 2

"BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution"

In 2 lists

"Building a Basic C2"

"CyRC analysis: CVE-2020-7958 biometric data extraction in Android devices"

"CVE-2020-16040 Analysis & Exploitation"

"Espressif ESP32: Bypassing Encrypted Secure Boot (CVE-2020-13629)"

In 2 lists

"Espressif ESP32: Bypassing Secure Boot using EMFI"

"Espressif ESP32: Bypassing Flash Encryption (CVE-2020-15048)"

"Espressif ESP32: Controlling PC during Secure Boot"

"Detecting Linux memfd_create() Fileless Malware with Command Line Forensics"

"Exception(al) Failure - Breaking the STM32F1 Read-Out Protection"

"Flashback Connects - Cisco RV340 SSL VPN RCE"

In 2 lists

"SWD, OpenOCD and Xbox One Controllers"

"TAG, SSDs and Firmware Extraction"Manipulating AES Traffic

"Hardware Hacking 101: Identifying and Dumping eMMC Flash"

In 2 lists

"House of Muney - Leakless Heap Exploitation Technique"

"Learning to Decapsulate Integrated Circuits Using Acid Deposition"

"Loading Dynamic Libraries on Mac"

"Minesweeper - TP-Link Archer C7 LAN RCE"

"My Methods To Achieve Persistence In Linux Systems"

Part 1

Part 2

"NTLM Relay"

In 2 lists

Part 1

In 2 lists

Part 2

"Norec Attack: Stripping BLE encryption from Nordic’s Library (CVE-2020–15509)"

In 2 lists

"ret2dl_resolve x64: Exploiting Dynamic Linking Procedure In x64 ELF Binaries"

"Safe-linking – Eliminating a 20 Year-old malloc() Exploit Primitive"

"SSHD Injection and Password Harvesting"

"There’s A Hole In Your SoC: Glitching The MediaTek BootROM"

In 2 lists

"Weekend Destroyer - RCE in Western Digital PR4100 NAS"

In 2 lists

"What're you telling me, Ghidra?"

2019

"Breaking out of Docker via runC – Explaining CVE-2019-5736"

"Sections and Segments"

"Symbols"

"Relocations"

"Dynamic Linking"

"Exploiting Qualcomm WLAN and Modem Over the Air"

In 2 lists

"Hacking microcontroller firmware through a USB"

In 2 lists

"Hardening Secure Boot on Embedded Devices for Hostile Environments"

"How to Weaponize the Yubikey"

In 2 lists

"Pew Pew Pew: Designing Secure Boot Securely"

"Pwn the ESP32 crypto-core"

"Pwn the ESP32 Secure Boot"

"Reverse Engineering Architecture And Pinout of Custom Asics"

"Reverse-engineering Broadcom wireless chipsets"

In 2 lists

"Reverse Engineering of a Not-so-Secure IoT Device"

Part 1

Part 2

Part 3

Part 4

2018

"A Deep dive into (implicit) Thread Local Storage"

"A Guide to ARM64 / AArch64 Assembly on Linux with Shellcodes and Cryptography"

"Return oriented Programming"

"Setup and Tools"

"Defeating DEP - execute system()"

"Defeating DEP - executing mprotect()"

Part 1

Part 2

Part 3

Part 4

"eMMC Data Recovery from Damaged Smartphone"

In 2 lists

"Kinibi TEE: Trusted Application Exploitation"

In 2 lists

"My journey towards Reverse Engineering a Smart Band — Bluetooth-LE RE"

In 2 lists

"Reverse Engineering BLE Devices"

In 2 lists

Part 1

In 2 lists

Part 2

Part 3

Part 4

Part 5

Part 6

"Hardware accelerated taint tracking at 2 trillion instructions per second"

"MMU Design"

2017

"Escalating Privileges in Linux using Fault Injection"

"Hardware hacking tutorial: Dumping and reversing firmware"

In 2 lists

"HiSilicon DVR hack"

"How I Reverse Engineered and Exploited a Smart Massager"

In 2 lists

"Linux Heap Exploitation Intro Series: Riding free on the heap – Double free attacks!"

"Linux ptrace introduction AKA injecting into sshd for fun"

"Exploiting Broadcom’s Wi-Fi Stack (Part 1)"

In 2 lists

"Exploiting Broadcom’s Wi-Fi Stack (Part 2)"

In 2 lists

"Exploiting The Wi-Fi Stack on Apple Devices"

In 2 lists

2016

"Bypassing Secure Boot using Fault Injection"

In 2 lists

"munmap madness"

"Implementation of Signal Handling"

"Digging Through the Firmware"

In 2 lists

"Scouting the Firmware"

"Following the Data"

"Dumping the Flash"

"Digging Through the Firmware"

"Understanding and Hardening Linux Containers"

2014

"ret2dir: Rethinking Kernel Isolation"

2011

"Load-time relocation of shared libraries"

"Position Independent Code (PIC) in shared libraries"

Misc

0xtriboulet

In 2 lists

"A Noobs Guide to ARM Exploitation"

In 2 lists

"Advanced binary fuzzing using AFL++-QEMU and libprotobuf: a practical case of grammar-aware in-memory persistent…

"Advanced Compilers: The Self-Guided Online Course"

"Analysis of a LoadLibraryA Stack String Obfuscation Technique with Radare2 & x86dbg"

"Android Kernel Exploitation"

In 2 lists

Anti-Debug Tricks

[Anti Debug]

In 2 lists

"ARM TrustZone: pivoting to the secure world"

In 2 lists

"ARMv8 AArch64/ARM64 Full Beginner's Assembly Tutorial"

In 2 lists

Awesome binary parsing

In 2 lists

Awesome Executable Packing

Resources about executable packing and unpacking

In 2 listsDetails

Awesome Industrial Protocols

In 2 lists

"Brute Ratel - Scandinavian Defence"

Comprehensive Rust

A 3-day course on Rust Fundamentals plus 1-day courses on Android, Bare-metal Rust, and Concurrency. Available in English, Brazilian Portuguese, and Korean.

In 3 lists

cryptopals

.

In 3 lists

CVE North Stars

In 2 lists

"Debugger Ghidra Class"

A software reverse engineering (SRE) framework created and maintained by the National Security Agency Research Directorate.

In 6 listsDetails

DhavalKapil/heap-exploitation

Diffing Portal

exploit_mitigations

"fenrir"

Ghidriff - Ghidra Binary Diffing Engine

[Python Command-Line Ghidra Binary Diffing Engine]

In 3 lists

"Grand Theft Auto A peek of BLE relay attack"

In 2 lists

"Hands-on Firmware Extraction, Exploration, and Emulation"

In 2 lists

ice9-bluetooth-sniffer

In 2 lists

dtls

quic

tls 1.2

In 2 lists

tls 1.3

"Introduction to encryption for embedded Linux developers"

"A hands-on approach to symmetric-key encryption"

"Asymmetric-Key Encryption and Digital Signatures in Practice"

"Introduction to Malware Analysis and Reverse Engineering"

In 2 lists

"Kernel Address Space Layout Derandomization"

"Kernel Exploit Recipes Notebook"

"Laser-Based Audio Injection on Voice-Controllable Systems"

Linux Kernel CVEs

"Linux kernel exploit development"

"Linux Kernel map"

In 2 lists

"Linux Insides"

by Alex Kuleshov

In 4 lists

"Linux Privilege Escalation"

In 2 lists

"Linux Syscalls Reference"

"Lytro Unlock - Making a bad camera slightly better"

"Minimizing Rust Binary Size"

"mjsxj09cm Recovering Firmware And Backdooring"

"Operating System development tutorials in Rust on the Raspberry Pi"

by Andre Richter

In 2 lists

"parking-game-fuzzer"

In 2 lists

"Practical Cryprography for Developers"

Developer-friendly book on modern cryptography (hashes, MAC codes, symmetric and asymmetric ciphers, key exchange, elliptic curves, digital signatures) with lots of code examples.

In 3 lists

Red-Team-Infrastructure-Wiki

Wiki to collect Red Team infrastructure hardening resources.

In 2 lists

"Reverse Engineering For Everyone!"

by Kevin Thomas

In 3 lists

"Reverse Engineering WiFi on RISC-V BL602"

In 2 lists

"Rust Atomics and Locks"

by Mara Bos

In 2 lists

"RustRedOps"

"Satellite Hacking Demystified(RTC0007)"

TEE Reversing

In 2 lists

"THC's favourite Tips, Tricks & Hacks (Cheat Sheet)"

Various tips & tricks

In 3 lists

tmpout.sh

collection of writeups on low-level stuff

"Trail of Bits Testing Handbook"

TripleCross

A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.

In 6 listsDetails

USB-WiFi

"VSS: Beginners Guide to Building a Hardware Hacking Lab"

"WinDBG quick start tutorial"

See category
94

Awesome OpenClaw Skills

VoltAgent/awesome-openclaw-skills

The awesome collection of OpenClaw skills. 5,400+ skills filtered and categorized from the official OpenClaw Skills Registry.🦞

Fresh★ 53k830 entriesPushed today
92

Awesome DeepSeek Harness (DSH) Plugin

awesome-dsh-plugin/awesome-dsh-plugin

A curated list of plugins for DeepSeek Harness (dsh) · DeepSeek Harness 插件精选列表

Fresh★ 17k1654 entriesPushed today
91

Awesome Guidelines

Kristories/awesome-guidelines

Programming style, best practices, and coding conventions.

Fresh★ 11k166 entriesPushed 2 days ago
90

Awesome

sindresorhus/awesome

😎 Awesome lists about all kinds of interesting topics [NOTE: Pull requests are temporarily disabled until I have a chance to catch up with the existing ones]

Fresh★ 513k51 entriesPushed 28 days ago
90

Awesome Prompts

ai-boost/awesome-prompts

Curated list of chatgpt prompts from the top-rated GPTs in the GPTs Store. Prompt Engineering, prompt attack & prompt protect. Advanced Prompt Engineering papers.

Fresh★ 9k288 entriesPushed yesterday
90

Awesome README

matiassingers/awesome-readme

A curated list of awesome READMEs

Fresh★ 22k143 entriesPushed yesterday