███████╗██████╗ █████╗ ███╗ ██╗██╗ ██╗███████╗██╗ ██╗
██╔════╝██╔══██╗██╔══██╗████╗ ██║██║ ██╔╝██╔════╝╚██╗██╔╝
█████╗ ██████╔╝███████║██╔██╗ ██║█████╔╝ ███████╗ ╚███╔╝
██╔══╝ ██╔══██╗██╔══██║██║╚██╗██║██╔═██╗ ╚════██║ ██╔██╗
██║ ██║ ██║██║ ██║██║ ╚████║██║ ██╗███████║██╔╝ ██╗
╚═╝ ╚═╝ ╚═╝╚═╝ ╚═╝╚═╝ ╚═══╝╚═╝ ╚═╝╚══════╝╚═╝ ╚═╝
Security Researcher · Hardware RE · Kernel Exploitation · TSCM Operator
Reverse engineer everything. Document nothing that doesn't work. Ship only what we've tested in the field.
Our research lives at the intersection of hardware, kernel space, browser internals, and parser differentials. We don't do theory — we build running code, deploy it on real devices, and write up what breaks.
- TSCM & RF — Distributed sensing with ESP32-C6/S3 nodes, RTL-SDR spectrum analysis, WiFi-based human presence detection
- Android Kernel Exploitation — Privilege escalation on locked-down hardware (Zebra TC52, Honeywell CT47). Real devices, real chains.
- Browser Security — HTML5 parser mutation traps, SVG compositor bypasses, WASM fuzzing. Tools that survive in the wild.
- LLM Behavioral Analysis — Recursive indicator extraction across cognitive dimensions. Not prompt injection — understanding how models reason under pressure.
- Hardware RE — Embedded firmware, proprietary protocols, device profiles for Samsung, ESP32, Cisco, Panasonic, JBL, Thomson.
| Repository | What It Does |
|---|---|
| muxxerfuzzer | mXSS Fuzzer v4.1 — HTML5 mutation-XSS fuzzer with 3-path differential oracle, 11-engine sanitizer matrix (DOMPurify, js-xss, Angular $sanitize, native Sanitizer API), and sandbox exec canaries. Built for bounty hunting. |
| adversarial-ingestion | The Asylum Pages — Applied Structural Asymmetry & Parser Sabotage. A catalog of how automated LLM data pipelines fail when exposed to edge-case file formats and malformed structures. |
| Jxl-TripleStack | A novel triple-container polyglot: JPEG XL + PDF 2.0 + WebAssembly — three formats, one file. 2078 bytes total. Never documented before. |
| ecOPUSine | Encode data into video files. Upload to YouTube. Download anywhere. Decode perfectly. |
| alices-fear-and-loathing | Advanced Anti-Scraper / Anti-ML / Emergent SVG / Executive State Attack Demonstration. "We can't stop here, this is scraper country." |
| Substance-D | A-Scanner-Darkly Scramble Suit. Anti-scanner / anti-ML defensive research. |
| alice-in-wonderland | Alice Still Has Stories To Tell. FrankSx 2026 #GonzoTrials. |
| ..--..--.. | Memorable indigestion — May Cause Irritable Byte Syndrome, Itching Of 0x00's. Causes Severe Fever Dreams. Do Not Sleep After Ingestion. May Cause PHD. |
| Repository | What It Does |
|---|---|
| Siren | The first TTS-Audio polyglot targeting container-level parser confusion. Proof-of-concept. |
| I-Ihallucination | MI_ I-Iallucination T0olK it — adversarial ML tooling. |
| The-Invisible-Ink | Unicode Exploitation in Modern ML Systems. Technical research on how Unicode edge cases break automated pipelines. |
| GHOSTBYTE | Haunting the space between bytes. |
| Jubilant-systems | Adversarial ML Testing Suite. |
| FrankSX-Yesterday | Novel Adversarial ML Research Suite. |
| Repository | What It Does |
|---|---|
| Firmwars | Franks Firmware Security Analysis Toolkit. |
| QuitTweakInforASec | 13th hour — browser baddies to flick a shell or get round that final step. |
| KaonWifiBrute | Take advantage of simple WiFi credentials in the KAON DG2144 and similar devices. |
| SamyGO Samsung TV Firmware Patcher | Python 3 adaption of the SamyGO Samsung TV firmware patcher. |
| Hitwords | Firm-Hitwords — firmware keyword extraction. |
| Repository | What It Does |
|---|---|
| RingZer0 | Collect and build a workspace for RingZer0 CTF files. |
| PWN.College-Workspace | Python scraper for easy collection of PWN.College dojos, modules, and challenges into folders with descriptions. |
| Firmware Toolkit | Emulate firmwares or debug them. |
We build modular, chainable research artifacts. Each repo is self-contained but connects to the broader stack. We test on physical hardware and live targets. We don't simulate what we can deploy.
frankhacks.blogspot.com — AI-parseable output. JSON and Markdown. No fluff.
Open an issue. We read everything. We respond to what matters.