Software and Tools

View all on GitHub

Nexmon

The C-based Firmware Patching Framework for Broadcom/Cypress Wi-Fi Chips that enables Monitor Mode, Frame Injection and much more.

Source Code

OpenDrop

OpenDrop is an open Apple AirDrop implementation written in Python.

Source Code Python Package Project Website

OWL

Open Wireless Link (OWL) is an open implementation of the Apple Wireless Direct Link (AWDL) ad hoc protocol for Linux and macOS written in C.

Source Code Project Website

OpenHaystack

OpenHaystack is a framework for tracking personal Bluetooth devices via Apple's massive Find My network.

Source Code Release

InternalBlue

Bluetooth experimentation framework for Broadcom and Cypress chips.

Source Code

Frankenstein

Broadcom and Cypress firmware emulation for fuzzing and further full-stack debugging.

Source Code

ToothPicker

iOS Bluetooth in-process fuzzing.

ToothPicker

ARIstoteles

Wireshark dissector for the iPhone Intel baseband protocol called Apple Remote Invocation (ARI).

Source Code

ChirpOTLE

A LoRaWAN Security Evaluation Framework for COTS Hardware

Source Code

PairSonic

Helping groups securely exchange contact information

Source Code Project website

pyshimmer

Unofficial Python API for Shimmer sensor devices

Source Code Python Package

Satellite Messenger (Saftellite)

With Saftellite, you can send SMS-like messages using the satellite connectivity of your iPhone 14 or newer on iOS 16. It works in all countries that support satellite connectivity and Find My location sharing over satellite. No iMessage over satellite or iOS 18 is required

Source Code

AirGuard for Android

With AirGuard, you get the anti-stalking protection you deserve! The app scans your surroundings in the background to detect trackers like AirTags, Samsung SmartTags, or Google Find My Device trackers. If a tracker is following you, you will receive an instant notification.

Source Code Google Play Store F-Droid

AirGuard for iOS

With AirGuard you get the anti-tracking protection you deserve! The app periodically scans your surroundings for potential tracking devices. The app detects Bluetooth based trackers, like the Samsung SmartTag. If a devices follows you, you will get a notification in about an hour!

Source Code App Store

CVEs

New vulnerabilities found that circumvent permission dialogues on iOS

Two issues have been patched that circumvent permission dialogues on iOS.

CVE-2025-31184, CVE-2024-44147, CVE-2024-44191

Apple iOS 18.4 Security Content (CVE-2025-31184) Apple iOS 18 Security Content (CVE-2024-44147, CVE-2024-44191)

Vulnerabilities in Linux Wi-Fi

We found five CVEs in the Linux Wi-Fi stack, with some of them dating back to kernel version 5.1 (2019). Our PoCs confirm that they lead to DoS, and might also lead to RCE in rare cases.

CVE-2022-41674, CVE-2022-42719, CVE-2022-42720, CVE-2022-42721, CVE-2022-42722

Read more... seclists.org post Risikozone podcast (German)

Datasets

Talon AD7200 Sector Patterns

Antenna Sector Patterns as obtained by Measurements in our CoNEXT '17 paper.

Sep 18, 2017

Myo Keylogging Dataset

EMG and IMU sensor data while typing on a keyboard from our IMWUT '21 paper.

Nov 24, 2021

FIDO2 Smartphone Lab Study Dataset

Pseudonymous dataset containing 22 variables for each of our 87 participants from our between-groups lab study comparing FIDO2 roaming and platform authentication on smartphones, as described in our CHI '23 paper.

Jan 25, 2023

Contact Exchange in Groups Lab Study Dataset

Pseudonymous dataset containing usability, security, and preference scores, completion times, reported usage of nine types of social and collaborative tools, and seven demographic and control variables, for each of our 45 participants, as described in our CSCW'24 paper.

Aug 14, 2024