quarkslab / titanm
This repository contains the tools we used in our research on the Google Titan M chip
☆185Updated 2 years ago
Alternatives and similar repositories for titanm:
Users that are interested in titanm are comparing it to the libraries listed below
- FitM, the Fuzzer in the Middle, can fuzz client and server binaries at the same time using userspace snapshot-fuzzing and network emulati…☆291Updated 2 years ago
- ☆112Updated last year
- Emulation and Feedback Fuzzing of Firmware with Memory Sanitization☆163Updated 3 years ago
- Frida-based general purpose fuzzer☆215Updated 4 years ago
- PoC 2019-2215 exploit for S8/S8 active with DAC + SELinux + Knox/RKP bypass☆227Updated 4 years ago
- ☆218Updated 2 years ago
- A curated list of awesome baseband research resources☆167Updated 5 years ago
- ☆172Updated 4 years ago
- Reverse-engineering tools and exploits for Samsung's implementation of TrustZone☆150Updated 5 years ago
- A de-socketing library for fuzzing.☆146Updated last month
- Scripts, plugins, and information for working with Samsung's Shannon baseband.☆157Updated 10 months ago
- Binary code coverage visualizer plugin for Ghidra☆290Updated 10 months ago
- fpicker is a Frida-based fuzzing suite supporting various modes (including AFL++ in-process fuzzing)☆276Updated 2 months ago
- A set of tools for fuzzing SecureROM. Managed to find and trigger checkm8.☆160Updated 3 years ago
- Coverage-guided binary fuzzing powered by Frida Stalker☆182Updated 4 years ago
- A python symbolic execution framework using radare2's ESIL (Evaluable String Intermediate Language)☆165Updated 2 years ago
- ☆186Updated last month
- ☆438Updated 7 months ago
- Collection of scripts for reversing Qualcomm Hexagon baseband / modem firmware☆161Updated last year
- Code and exercises for a workshop on z3 and angr☆227Updated 4 years ago
- Debugger for the Shannon Baseband☆58Updated 4 years ago
- Use angr inside GDB. Create an angr state from the current debugger state.☆198Updated 4 years ago
- A thorough library database to assist with binary exploitation tasks.☆198Updated 2 years ago
- DynamoRIO plugin to get ASAN and SanitizerCoverage compatible output for closed-source executables☆207Updated 3 years ago
- FirmWire has replaced ShannonEE. OLD: A dynamic analysis environment for Samsung's Shannon baseband.☆41Updated 3 years ago
- A fuzzing tool for closed-source binaries based on Unicorn and LibFuzzer☆342Updated 5 years ago
- LKRG bypass methods☆72Updated 5 years ago
- A PCode Emulator for Ghidra.☆108Updated 4 years ago
- Kernel Fuzzer for Xen Project (KF/x) - Hypervisor-based fuzzing using Xen VM forking, VMI & AFL☆473Updated 9 months ago
- A WIP "Vulnerable by Design" kext for iOS/macOS to play & learn *OS kernel exploitation☆229Updated 4 years ago