Tool for getting and setting nonce without triggering KPP/KTRR/PAC.
☆113Apr 22, 2023Updated 2 years ago
Alternatives and similar repositories for dimentio
Users that are interested in dimentio are comparing it to the libraries listed below
Sorting:
- Mapping physical memory to user space (EL0) on iOS.☆75Jan 3, 2023Updated 3 years ago
- Lib kernel r/w☆190Nov 1, 2021Updated 4 years ago
- Accessing physical memory on iOS.☆52Sep 21, 2020Updated 5 years ago
- Give me tfp0, I give you jelbrek☆260Oct 28, 2020Updated 5 years ago
- iOS 10.0-12.2 tfp0☆132Sep 3, 2019Updated 6 years ago
- powerd exploit : Sandbox escape to root for Apple iOS < 12.2 on A11 devices☆110Mar 28, 2019Updated 6 years ago
- untethered+unsandboxed code execution in iOS 11☆189Feb 16, 2020Updated 6 years ago
- 64-bit iOS boot image patcher written in C☆146Sep 18, 2022Updated 3 years ago
- Plugin for loading MachO kernelcache and dSYM files to Binary Ninja☆40Mar 23, 2025Updated 11 months ago
- Proof-of-concept and write-up for the CVE-2022-32832 vulnerability patched in iOS 15.6☆96Jul 21, 2022Updated 3 years ago
- A arm offsetfinder. It finds offsets, patches, parses Mach-O and even supports IMG4/IMG3☆149Feb 21, 2026Updated last month
- a Ghidra framework for iOS kernelcache reverse engineering☆364Nov 6, 2022Updated 3 years ago
- iOS 15.0 - 15.3.1 sandbox escape technique using kernel read/write primitives☆132Jun 10, 2022Updated 3 years ago
- An iOS kernel debugger based on a KTRR bypass for A11 iPhones; works with LLDB and IDA Pro.☆690Oct 22, 2022Updated 3 years ago
- Binary Format of iOS 13 Sandbox Profile Collection☆52Oct 30, 2019Updated 6 years ago
- See https://github.com/0x7ff/iBootMaybeDumper/issues/1#issuecomment-426731516 for more info.☆21Sep 6, 2018Updated 7 years ago
- An old, ugly and deprecated script to download, decrypt and upload .ipa files to appdb. Check out the new one: https://github.com/n3d1117…☆15Mar 5, 2018Updated 8 years ago
- kernel exploit for Apple iOS 13.X☆184Nov 27, 2020Updated 5 years ago
- iOS 12.0-13.3 tfp0☆153Nov 16, 2020Updated 5 years ago
- kernel r/w exploit for iOS 15.0 - 15.1.1☆262Apr 27, 2022Updated 3 years ago
- Find some iBoot functions in an iBoot64.☆40Feb 10, 2021Updated 5 years ago
- A tool to parse Apple's binary device tree format.☆57Apr 19, 2020Updated 5 years ago
- iOS firmware key decrypter☆45Aug 17, 2023Updated 2 years ago
- ☆32Apr 22, 2019Updated 6 years ago
- use https://github.com/argp/iBoot64helper which is the orginal repo and far more advanced☆33Sep 2, 2019Updated 6 years ago
- iBoot-1145.3 Image3/heap stack RE (+unholy tools)☆83Feb 10, 2024Updated 2 years ago
- Automating research with scripts☆11Mar 30, 2020Updated 5 years ago
- macOS kext with kernel R/W, kalloc and kcall☆108Jun 21, 2025Updated 9 months ago
- JB ETA????☆28Feb 4, 2021Updated 5 years ago
- An IDA Toolkit for analyzing iOS kernelcaches.☆301Jul 24, 2020Updated 5 years ago
- A tool for listing/reversing XPC services inside container sandbox. Reference: https://www.blackhat.com/docs/us-15/materials/us-15-Wang-R…☆22Sep 6, 2018Updated 7 years ago
- ANE kernel r/w exploit for iOS 15 and macOS 12☆303Nov 20, 2022Updated 3 years ago
- Checkm8 experiment to understand AP/SEP internals.☆200Feb 2, 2023Updated 3 years ago
- Automatically download and decrypt SecureRom stuff (iBSS, iBEC, iBoot, etc.) for all iOS versions available.☆52Dec 4, 2019Updated 6 years ago
- File detection bypass for iOS☆19Feb 28, 2021Updated 5 years ago
- Research on Apple's USB protocols☆30Nov 13, 2019Updated 6 years ago
- Obtains the kernel task port and establishes a kernel function calling primitive on the iPhone XS, iPhone XR, and iPhone 8 running iOS 12…☆30Jan 29, 2019Updated 7 years ago
- iOS automated SDK builder☆18Feb 26, 2024Updated 2 years ago
- Lockdown related research, tools and POCs.☆90May 18, 2019Updated 6 years ago