Experimentation environment for checkm8-vulnerable devices
☆57Dec 30, 2023Updated 2 years ago
Alternatives and similar repositories for respawn
Users that are interested in respawn are comparing it to the libraries listed below
Sorting:
- iOS bootchain patchers in Python☆13Jan 23, 2024Updated 2 years ago
- Plugin for loading MachO kernelcache and dSYM files to Binary Ninja☆40Mar 23, 2025Updated 11 months ago
- Python adaptation for pelara1n☆38Dec 25, 2022Updated 3 years ago
- LZVN compression/decompression tool☆18Feb 9, 2021Updated 5 years ago
- Output from running Yarden's sandblaster on an iPhone15,2's iOS17 kernelcaches☆18Aug 7, 2024Updated last year
- iBoot/SecureROM Loader☆35Feb 24, 2023Updated 3 years ago
- some research results of sep☆20Apr 9, 2021Updated 4 years ago
- HomeDepot patcher script to jailbreak A5(X) iOS 8.x☆11Dec 29, 2024Updated last year
- Apple Silicon NOR dumper☆49Nov 8, 2023Updated 2 years ago
- xnu_gym is a pongoOS module that patches XNU to reintroduce previously known and patched vulnerabilities. This is an easy way to practice…☆57Jun 17, 2021Updated 4 years ago
- ☆15Oct 27, 2022Updated 3 years ago
- Checkm8 experiment to understand AP/SEP internals.☆200Feb 2, 2023Updated 3 years ago
- IDA plugin that resolves PPL calls to the actual underlying PPL function.☆56Feb 28, 2023Updated 3 years ago
- First pongoOS game #pongoOSMasterRace☆46Jun 29, 2023Updated 2 years ago
- SEP firmware splitter, made in rust.☆45Oct 11, 2024Updated last year
- Some old unexploited remote kernel memory corruption PoCs☆25Aug 19, 2024Updated last year
- A Python library for the ipsw daemon API☆27Aug 14, 2023Updated 2 years ago
- CLI frontend for com.apple.decmpfs / AppleFSCompression.framework☆33Oct 18, 2022Updated 3 years ago
- Boot arbitrary iBoot via ipwndfu's custom protocol on 32-bit platforms (and more)☆65Dec 21, 2025Updated 3 months ago
- xnu build script☆71Aug 31, 2023Updated 2 years ago
- sock_port_2 but legacy☆10Oct 29, 2023Updated 2 years ago
- Host your own *OS Entitlement Database☆56Oct 23, 2025Updated 4 months ago
- A set of tools for fuzzing SecureROM. Managed to find and trigger checkm8.☆165Sep 18, 2021Updated 4 years ago
- Binary Ninja loader for 64 bits Apple SEPROMs☆59Sep 7, 2025Updated 6 months ago
- a patcher for making downgradable iOS 14 firmware☆39Aug 24, 2022Updated 3 years ago
- Insecurity as an IOService☆96Mar 25, 2025Updated 11 months ago
- a7 sep bug☆55Sep 26, 2023Updated 2 years ago
- Reversing the Apple sandbox☆175Dec 7, 2025Updated 3 months ago
- Lib kernel r/w☆190Nov 1, 2021Updated 4 years ago
- A tool to call CoreTrust evaluation from userland☆22Apr 30, 2024Updated last year
- A6 checkm8 exploit with checkra1n 0.1337 method.☆26Jan 14, 2024Updated 2 years ago
- 32/64 bit SecureROM/iBoot loader for IDA Pro. Also supports loading and decrypting encrypted .im4ps within IDA.☆73Mar 2, 2022Updated 4 years ago
- iOS 15.0 - 15.3.1 sandbox escape technique using kernel read/write primitives☆132Jun 10, 2022Updated 3 years ago
- a Ghidra framework for iOS kernelcache reverse engineering☆364Nov 6, 2022Updated 3 years ago
- ☆140Feb 17, 2024Updated 2 years ago
- Mapping physical memory to user space (EL0) on iOS.☆75Jan 3, 2023Updated 3 years ago
- A tool to parse Apple's binary device tree format.☆57Apr 19, 2020Updated 5 years ago
- A checkm8 utility for A7-A11 devices☆77Mar 24, 2025Updated 11 months ago
- IDA loader for Apple's 64 bits iBoot, SecureROM and AVPBooter☆164Nov 2, 2024Updated last year