research · open source · disclosure

The proof is public.

Part of my work is open.
It’s what lets me show what I can do without breaking my clients’ confidentiality.

repositories

Projects

Wireless security, embedded hardware

Evil-M5Project

Wi-Fi exploration and audit tool for M5Stack and ESP32 hardware, built for ethical use: research, demonstrations and training.

Over 2 700 stars on GitHub

Network audit, embedded hardware

RaspyJack

Compact network toolkit for Raspberry Pi with a small screen, designed for on-site audits and teaching, with its own community.

Over 1 200 stars on GitHub

All my repositories are on GitHub, and I write on my technical blog. Need a test on your system? See the services.

3 published · 2 reserved

Reported vulnerabilities

Each entry links to the corresponding advisory. "Reserved" marks an assigned ID whose publication in the MITRE registry is pending. As a matter of principle, no detail is given here on a disclosure still in progress.

publications & talks

Publications & talks

Technical write-ups and public appearances. Talks and CTFs: LeHack 2025 · 404CTF · BreizhCTF (details on the blog).

ethics

Responsible disclosure

When I find a vulnerability, I first report it to the vendor or manufacturer and give them a reasonable time to fix it before any publication. I never disclose details of an unfixed flaw.

A coordinated disclosure is under way with a manufacturer. As a matter of principle, I won’t say anything about it until it is closed.

The same logic applies in reverse: if you find a flaw on this site, see the responsible disclosure policy.

A shared research project?

A topic, a bug, a collaboration? Write to me.

Reply within a few business days, no commitment.