blacktop / yardens-sb-profs
Output from running Yarden's sandblaster on an iPhone15,2's iOS17 kernelcaches
☆17Updated 6 months ago
Alternatives and similar repositories for yardens-sb-profs:
Users that are interested in yardens-sb-profs are comparing it to the libraries listed below
- a7 sep bug☆52Updated last year
- A python lib for manipulating IMG4, IM4M and IM4P files☆12Updated last year
- Private headers & entitlements for daemons, frameworks, applications private frameworks and more for iOS 17.0 21A328☆19Updated last year
- Interact with trustcaches☆39Updated 2 years ago
- IDA loader for SEP firmware with dyld cache support.☆55Updated 6 months ago
- A tool to call CoreTrust evaluation from userland☆16Updated 9 months ago
- Experimentation environment for checkm8-vulnerable devices☆53Updated last year
- Some old unexploited remote kernel memory corruption PoCs☆23Updated 6 months ago
- A library that enables dynamically rebinding symbols in Mach-O binaries running on iOS.☆16Updated 2 months ago
- ☆17Updated 2 years ago
- Mapping physical memory to user space (EL0) on iOS.☆72Updated 2 years ago
- An *OS bootchain patching library.☆16Updated last week
- A custom shellcode hook for checkra1n 0.1337 written in c!☆38Updated last year
- Search running processes on iOS for instances of a given objc class.☆41Updated last month
- App with PoC of CVE-2024-44285☆42Updated 2 months ago
- iOS bootchain patchers in Python☆14Updated last year
- IDA loader to help with SEPROM reverse engineering.☆33Updated 2 months ago
- Plugin for loading MachO kernelcache and dSYM files to Binary Ninja☆34Updated 6 months ago
- ☆69Updated 8 months ago
- Experimenting with the Launch Services system on iOS and macOS☆25Updated 3 months ago
- Log all syscalls executed by a process (iOS / checkra1n / xnuspy)☆64Updated 2 years ago
- Binary Ninja loader for 64 bits Apple SEPROMs☆50Updated 8 months ago
- A Python library for the ipsw daemon API☆23Updated last year
- Translate and patch arm64e binaries or macOS arm64 binaries to run on an arm64 iPhone at runtime.☆50Updated 2 years ago
- iPod nano 6 (S5L8723) implementation of S5Late bootrom exploit. Now also iPod shuffle 4 (S5L8443)☆15Updated 2 months ago
- AEA metadata dumper☆46Updated 7 months ago
- SEP firmware splitter, made in rust.☆38Updated 4 months ago
- xnu_gym is a pongoOS module that patches XNU to reintroduce previously known and patched vulnerabilities. This is an easy way to practice…☆55Updated 3 years ago
- iOS 14 kernel exploit based on PhysPuppet☆58Updated 4 months ago