| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Original HTTPS Page] |
Research Projects · Featured Projects · All Project Cards · Project Constellation · Complete Atlas
GainSec is the personal handle/brand of Jon “GainSec” Gaines—an offensive security leader, engineer, and independent researcher. The public archive spans vulnerability research and disclosure; offensive-security tooling; web, software, thick-client, macOS, mobile, and cloud security; hardware, embedded/IoT, RF/wireless, cellular/V2X, physical-security, and surveillance systems; reverse engineering, OSINT, and LLM/ML/AI/agent systems. It also includes open-source applications and utilities, robotics, data visualization, technical walkthroughs, publications, leadership writing, and experimental engineering.
Further research, technical write-ups, commentary, and other posts can be found at GainSec.com.
This page was last updated 09/2026.
The following incomplete list extends the GitHub record with security research, vulnerability disclosures, technical walkthroughs, leadership writing, papers, talks, and media published on GainSec.com or in external publications.
Flock Safety Research · 12 publications| Agent-driven target discovery, microscope mapping, safety-monitored CNC motion, operator review, and controlled PCB pin probing—with source, dashboard, CAD, and safety documentation. | A self-hosted 3D RF-awareness and presence-intelligence platform joining local Wi-Fi, BLE, ADS-B, rail, IoT, infrastructure, and authorized LTE-lab observations. |
| An AI-augmented security assessment framework built around operator authority, scope controls, anonymization, explicit approvals, evidence, and governed reporting. | A public preview of an agent runtime substrate focused on capability containment, evidence provenance, and auditable operator control. |
| A self-hosted workbench for agent approvals, runbooks, files, review artifacts, task state, and auditable out-of-band collaboration. | An offline-first offensive framework for authorized Flock Safety security assessments and penetration testing. |
| Cardano and Amaru fuzzing and adversarial testing across serialization, mini-protocol, runtime, resource, and consensus surfaces, with replayable evidence and deterministic-simulation integration. | A reverse-engineered camera-car dashboard and agent API that gives a human or authorized agent live video, two-way audio, and motion control. |
flowchart TB
J["Jon ‘GainSec’ Gaines"]
J --> C0["Vulnerability / Security Research"]
J --> C1["Technical Walkthroughs"]
J --> C2["Offensive Tooling"]
J --> C3["Open / Public Source Projects"]
J --> C4["Everything Else"]
flowchart TB
ROOT["Vulnerability / Security Research"]
ROOT --> S0_0["Connected Public Safety and Anti-Crime Technology"]
S0_0 --> P0_0["anti-crime-ecosystem-research"]
S0_0 --> P0_1["BirdShot"]
S0_0 --> P0_2["Flock-Safety-Trap-Shooter-Sniffer-Alarm"]
S0_0 --> P0_3["onvif-enum"]
S0_0 --> P0_4["Uniview-LAPI-Research-Toolkit"]
S0_0 --> P0_5["DigitalAlly-ThermoVu-Uniview-Security-Research"]
S0_0 --> P0_6["verkada-verkracked-alarm-hub-local-framework"]
S0_0 --> P0_7["verkada-verkracked-subghz-framework"]
S0_0 --> P0_8["CVE-2017-16744-and-CVE-2017-16748-Tridium-Niagara"]
S0_0 --> P0_9["flock-safety-falcon-sparrow-alpr-edl-firehose"]
ROOT --> S0_1["Vulnerability Disclosures"]
S0_1 --> P0_10["macos-printer-simulator-security-research"]
S0_1 --> P0_11["AOL-Desktop-Gold-Security-Research"]
ROOT --> S0_2["Automotive + V2X Security"]
S0_2 --> P0_12["3rdParty-Carplay-AndroidAuto-Dongle-Security-Research"]
S0_2 --> P0_13["Wireless-Attack-Vectors-Against-Automobiles"]
ROOT --> S0_3["Hardware + Embedded Security"]
S0_3 --> P0_14["Little-Tikes-DreamProjector-Reverse-Engineering"]
ROOT --> S0_4["Research Companion Material"]
S0_4 --> P0_15["Phrack-72-Raw-Output-V2X"]
flowchart TB
ROOT["Technical Walkthroughs"]
ROOT --> S1_0["Tutorials + Build Guides"]
S1_0 --> P1_0["Qwen 3.6 Tool-Call Fix"]
S1_0 --> P1_1["M5NanoC6-Zigbee-Sniffer"]
S1_0 --> P1_2["CloudGoatTutorial"]
ROOT --> S1_1["Lectures + Educational Material"]
S1_1 --> P1_3["Silk-Road-Lecture"]
ROOT --> S1_2["Workflow Guides"]
S1_2 --> P1_4["n8n-workflow-whisper-server"]
flowchart TB
ROOT["Offensive Tooling"]
ROOT --> S2_0["Fuzzing + Adversarial Testing"]
S2_0 --> P2_0["DWARF"]
ROOT --> S2_1["Reconnaissance + Enumeration"]
S2_1 --> P2_1["crt.sh-OSX"]
ROOT --> S2_2["OSINT"]
S2_2 --> P2_2["LeakScope"]
S2_2 --> P2_3["Dorker"]
S2_2 --> P2_4["FOSINT"]
S2_2 --> P2_5["Base-Google-Dorks"]
ROOT --> S2_3["Assessment Workflow"]
S2_3 --> P2_6["GoldenNuggets-1"]
S2_3 --> P2_7["TreeHouse-Wordlists"]
S2_3 --> P2_8["Hackers-LunchBox"]
S2_3 --> P2_9["Mac-OSX-Application-Fingerprint-And-Security-Tool"]
S2_3 --> P2_10["Quick-Engagement-Directory-Maker"]
ROOT --> S2_4["Wireless + Device Tooling"]
S2_4 --> P2_11["gainsec-in-the-middle"]
S2_4 --> P2_12["Weaponized-Mousejack-Keysniff"]
ROOT --> S2_5["Payload + Bypass Research"]
S2_5 --> P2_13["RTLOify"]
ROOT --> S2_6["Legacy Tooling"]
S2_6 --> P2_14["vncpwn"]
S2_6 --> P2_15["LeakLooker-X---2022"]
flowchart TB
ROOT["Open / Public Source Projects"]
ROOT --> S3_0["Hardware + Embedded"]
S3_0 --> P3_0["AutoProber"]
S3_0 --> P3_1["RapidPower-RoboDog"]
S3_0 --> P3_2["Super-Awesome-AI-Driver"]
ROOT --> S3_1["RF + Wireless"]
S3_1 --> P3_3["Tree-House-Defense-System-TDS"]
S3_1 --> P3_4["M5Stack-Core2-PaxCounter-WiFi-Bluetooth-Monitor"]
ROOT --> S3_3["LLM / ML / AI / Agents"]
S3_3 --> P3_5["ArcticBase"]
S3_3 --> P3_6["BattleReadyArmor-Slim"]
S3_3 --> P3_7["battlereadyarmor-pilot"]
S3_3 --> P3_8["MacOS-ImagePlayground-Improved"]
S3_3 --> P3_9["AgentReadyArmor-Teaser"]
S3_3 --> P3_10["tensorflow-generic-harness"]
S3_3 --> P3_11["BattleReadyArmor-PublicPreview"]
S3_3 --> P3_12["GainSec-Local-AI-Stack"]
S3_3 --> P3_13["MacOS-AppleIntelligence-Harness"]
ROOT --> S3_4["Applications + Utilities"]
S3_4 --> P3_14["PineapplePager-Themer"]
S3_4 --> P3_15["unicode-secret-message"]
ROOT --> S3_5["Data + Visualization"]
S3_5 --> P3_16["SectorMap"]
flowchart TB
ROOT["Everything Else"]
ROOT --> S4_0["Experiments"]
S4_0 --> P4_0["IG-Clone-Tracker"]
Caution
This archive contains dual-use security research and tools. Use them only in owned or explicitly authorized environments, and follow each project’s safety and disclosure boundaries.
Hardware hacker’s flying probe automation stack for agent-driven target discovery, microscope mapping, safety-monitored CNC motion, probe review, and controlled pin probing.
Independent research white paper by Jon “GainSec” Gaines examining the security posture of a connected public safety technology ecosystem.
Custom firmware for the M5NanoC6 (ESP32-C6) meant to sniff and alert you of nearby Flock Safety devices. Will be integrated into a exploit tool releasing on 09/27/25 for Flock Safety devices!
Wordlist for Hacking, Penetration Testing, Vulnerability Assessments and More
Wordlist for Hacking, Penetration Testing, Vulnerability Assessments and More
The personal security research and engineering brand of Jon “GainSec” Gaines—offensive security, hardware, RF, OSINT, Penetration Testing, Red Teaming, embedded systems, AI/agent systems, and more.
Independent research white paper by Jon “GainSec” Gaines examining the security posture of a connected public safety technology ecosystem.
This implementation enables the use of the Verkada SubGhz wireless protocol to be used locally. It is part of the "Verkracked" independent Securtity Research project by Jon "GainSec" Gaines.
This framework enables the use of the Verkada BH Wireless Alarm Hubs to be used locally. It is part of the "Verkracked" independent Securtity Research project by Jon "GainSec" Gaines.
GainSec's MacOS Printer Simualtor Security Research Publication. Covers 3 issues found in current MacOS Versions.
The all-in-one offensive tool suite for all things Flock Safety. Built from the 55 vulnerabilities Jon 'GainSec' Gaines found across Flock Safety's Raven (Gunshot Detection), Picard/Bravo (Edge Compute Device for PTZ/LPR), and Falcon/Sparrow (LPR) devices.
TDS is a self-hosted RF awareness dashboard for visualizing WiFi, BLE, ADS-B, rail, IoT, LTE lab data, and infrastructure alerts in 3D. It normalizes local sensor data into searchable presence intelligence.
Self-hosted workbench host for AI coding agents. Each project gets a themed dashboard where the agent drops approval forms, runbooks, files, and review docs — out-of-band from chat, persistent, auditable. FastAPI + Svelte 5, single static binary or Docker, single-user.
Toy project made during extensive security research into RTLO, PDF and other unicode characters
Loading…
| Back | FazBrowse Home | New Git URL |