Research Projects · Featured Projects · All Project Cards · Project Constellation · Complete Atlas
GainSec is the personal handle/brand of Jon “GainSec” Gaines—an offensive security leader, engineer, and independent researcher. The public archive spans vulnerability research and disclosure; offensive-security tooling; web, software, thick-client, macOS, mobile, and cloud security; hardware, embedded/IoT, RF/wireless, cellular/V2X, physical-security, and surveillance systems; reverse engineering, OSINT, and LLM/ML/AI/agent systems. It also includes open-source applications and utilities, robotics, data visualization, technical walkthroughs, publications, leadership writing, and experimental engineering.
Further research, technical write-ups, commentary, and other posts can be found at GainSec.com.
This page was last updated 08/2026.
- Flock Safety Security Vulnerabilities: Examining the Security Posture of an Anti-Crime Ecosystem is a versioned whitepaper and disclosure archive covering >50 vulnerabilities I found in Flock Safety's gunshot detection, license-plate reader, and compute hardware, with defender guidance and repository-maintained finding/CVE accounting.
- Flock Safety Offensive Security Tooling: BirdShot is an offline-first offensive framework for authorized Flock Safety security assessments and penetration testing; Trap Shooter / Sniffer / Alarm detects nearby Flock-related Wi-Fi activity; and the Falcon/Sparrow EDL firehose provides EDL-mode interaction tooling for researched ALPR hardware.
- Digital Ally / Uniview: the ThermoVu / Uniview security research is accompanied by the Uniview LAPI Research Toolkit, ONVIF enumeration, and the TensorFlow generic harness used for OEM-style model-pipeline replay.
- Connected infrastructure: Tridium Niagara CVE PoCs preserve proofs of concept for CVE-2017-16744 and CVE-2017-16748.
- Vehicle and V2X material: Phrack 72 V2X companion artifacts preserve raw output and logs accompanying my paper that was published in Phrack 72.
- macOS Printer Simulator Security Research — Public disclosure documenting three validated technical weaknesses with reproduction source, evidence, current Low/Low/Informational ratings, and Apple’s recorded disposition.
- AutoPro / Mayton CarPlay adapter research — Public wireless CarPlay adapter analysis, findings, evidence, source tools, and the first C2 for aftermarket Android Auto / Apple CarPlay dongles.
- AOL Desktop Gold Security Research — Independent group security research release covering a handful of vulnerabilities found in AOL Desktop Gold.
- Little Tikes Dream Machine reverse engineering — Notes and material from reverse engineering the Little Tikes Dream Machine.
The following incomplete list extends the GitHub record with security research, vulnerability disclosures, technical walkthroughs, leadership writing, papers, talks, and media published on GainSec.com or in external publications.
Flock Safety Research · 11 publications
- 2026-08-09 — Bird Hunting Season at Def Con 34 — Companion PDF for my DEF CON 34 Main Stage talk, covering 55 vulnerabilities I found in Flock Safety’s hardware ecosystem.
- 2026-01-09 — Finding 67 Flock Safety Live PTZ Camera/LPR Feeds and Debug Web Interfaces accidentally exposed without authentication to the internet
- 2025-11-12 — BirdEye
- 2025-11-05 — Formalizing my Flock Safety Security Research.
- 2025-09-27 — Button Presses to Wireless RCE: Shell on Flock Safety’s License Plate Cameras Over Wi-Fi
- 2025-09-27 — Fly-By – Device 2: The Falcon/Sparrow – Gated Wireless RCE, Camera Feed, DoS, Information Disclosure and More
- 2025-09-19 — Root from the Coop – Device 3: Root Shell on Flock Safety’s Picard/Bravo Compute Box
- 2025-06-30 — Trap Shooter – Flock Safety Sniffer & Alarm
- 2025-06-19 — Grounded Flight – Device 2: Root Shell on Flock Safety’s Falcon/Sparrow Automated License Plate Reader
- 2025-06-19 — Plucked and Rooted – Device 1: Debug Shell on Flock Safety’s Raven Gunshot Detection System
- 2025-06-19 — Bird Hunting Season – Security Research on Flock Safety’s Anti-Crime Systems
Other Connected Public Safety + Surveillance Research · 1 publication
Automotive, V2X + Connected Infrastructure · 3 publications
Hardware + Embedded Security · 4 publications
- 2025-05-25 — Reverse Engineering the Little Tikes Dream Machine Projector – Part 1
- 2025-04-01 — Reverse engineering the MISIRUN Instant Print Kids Camera
- 2025-02-27 — CVE-2025-25727,CVE-2025-25728,CVE-2025-25729 Multiple Vulnerabilities found in BossComm OBD2 Tablet
- 2025-02-27 — CVE-2025-25730 Developer Options and USB Debugging Authorization Bypass in Motorola Droid Razr HD (XT926)
Software Vulnerability Disclosures · 9 publications
- 2026-07-14 — AOL Desktop Gold Security Research Public Release
- 2024-04-28 — CVE-2024-32210, CVE-2024-32211, CVE-2024-32212, CVE-2024-32213 LoMag (Integrator/CE) WareHouse Management
- 2022-08-26 — CVE-2022-34108, CVE-2022-34109, CVE-2022-34110 DoS + Arbitrary file Download/Copy in MSI Feature Navigator
- 2022-08-19 — CVE-2022-34615, CVE-2022-34621, CVE-2022-34623, CVE-2022-34624 – IDOR, User Enum and More (In Mealie)
- 2022-08-07 — CVE-2022-37857, CVE-2022-37163, CVE-2022-37164 Hardcoded Credentials/Weak Password Policies
- 2022-08-04 — CVE-2022-35142, CVE-2022-35143, CVE-2022-35144 – DoS, XSS and Weak Password Policy in Renato a Markdown powered knowledge base
- 2022-08-02 — CVE-2022-34613, CVE-2022-34618, CVE-2022-34619 – Multiple XSS (And more) in Mealie
- 2022-08-02 — CVE-2022-34625 – Server-Side Template Injection to Remote Code Execution (SSTI) to (RCE) in Mealie – A lesson in patience
- 2022-07-27 — CVE-2022-34009
OSINT Research · 3 publications
Technical Walkthroughs · 45 publications
- 2025-10-18 — Addition to the $150 Private LTE Network
- 2025-10-08 — Setting up your own 4G LTE Network (<$150) for your Embedded System & IoT Hacking Lab via Open5GS + CBRS eNodeB on Ubuntu 24.04
- 2025-06-26 — Unbricking and Flashing the Yardstick One
- 2025-06-09 — The quickest and simplest guide to spinning up a powerful local AI stack. Part 7 – Current Stack – Docker Deploy
- 2025-06-08 — The quickest and simplest guide to spinning up a powerful local AI stack. Part 6 – Open-WebUI To Crawl4AI – Chat
- 2025-06-07 — The quickest and simplest guide to spinning up a powerful local AI stack. Part 5 – Open-WebUI To Crawl4AI – Local Files
- 2025-06-04 — The quickest and simplest guide to spinning up a powerful local AI stack. Part 4 – Transcription via Whisper
- 2025-06-03 — The quickest and simplest guide to spinning up a powerful local AI stack. Part 3 – Image Generation via Stable Diffusion
- 2025-06-02 — The quickest and simplest guide to spinning up a powerful local AI stack. Part 2 – SearXNG
- 2025-06-01 — The quickest and simplest guide to spinning up a powerful local AI stack. Part 1
- 2025-05-31 — How to generate VALID TLS Certificates that are NOT self-signed for internal only services.
- 2025-05-31 — Complete Install Guide of Kali NetHunter on Nexus 6P – 2025
- 2025-05-28 — Using a Nexus 6P and QCSuper to Sniff LTE.
- 2025-04-28 — Unbricking and Reflashing the Ubertooth One Clones
- 2025-04-17 — PaxCounter (WiFi & Bluetooth Device Counter) For the M5Stack Core2
- 2025-03-13 — Dumping Firmware from ESP8684
- 2025-01-25 — Sniffing V2X/DSRC with LibreSDR B210/B220 AD9361 on Linux
- 2025-01-23 — Setting up and configuring LibreSDR B210/B220 AD9361 on Windows and Linux
- 2025-01-23 — ConfiguringWindows Subsystem Linux (WSL) to access USB devices.
- 2024-08-13 — Sniffing Zigbee Traffic Easily with the M5NanoC6 2024
- 2023-12-21 — New Project: The Hackers Lunch Box
- 2022-05-02 — How to Find the next BIG Data Leak in under 20 minutes or less! – LeakLooker-X – Updated 2022
- 2022-03-11 — How to install Veracrypt on Kali Linux
- 2022-03-07 — Using the WayBack Machine to create parameter wordlists
- 2022-02-23 — Check Host Information such as open ports from Shodan WITHOUT an API key!
- 2022-02-17 — How to pipe terminal output to your clipboard! (And Vice Versa)
- 2022-02-01 — Change Virtualbox settings without booting and install Guest additions Kali Linux 2022
- 2022-01-30 — Install and access Cassandra DB on Kali Linux with CLI client
- 2022-01-28 — Install MongoDB CLI Client on Kali Linux
- 2022-01-26 — Install ProtonVPN on Kali Linux
- 2022-01-02 — Top 5 ways to harden the security and privacy of your online accounts in 2022
- 2021-11-06 — Install Kali NetHunter Nexus 6p Android 8.1 2021
- 2021-09-14 — How to install Objection and bypass SSL pinning on an iOS App
- 2021-04-18 — Top 5 ways to harden the security and privacy of your online accounts in 2021
- 2021-04-01 — How to install NetHunter on Any Android Phone (Nexus 6p) 2021
- 2020-12-06 — Create your own Amiibo
- 2020-11-20 — 5 More Internet Hygiene Tips
- 2020-09-24 — 5 Internet Hygiene Tips
- 2020-09-16 — Hide Command from Bash_History Kali Tips #11
- 2020-09-04 — OSINT Escapades #0
- 2020-08-03 — Complete CloudGoat Setup Guide
- 2020-08-01 — How Install CloudGoat on Ubuntu Server
- 2020-07-28 — Upgrade RAM MSI GS65 Stealth Thin (0050-US)
- 2019-11-16 — Reinstall Grub Bootloader on a Dual boot laptop Kali Tips #1
- 2019-10-23 — How to install NetHunter on Any Android Phone (Nexus 6p)
Technical Leadership · 3 publications
Lectures, Papers + Media · 8 publications
- 2025-05-26 — NTLM and SMB: File Sharing is Caring
- 2023-02-11 — Cheap ‘n’ Easy Phishing (That Actually Works)
- 2020-11-18 — The importance of Operation’s Security 2020
- 2020-11-16 — Saturday Chat 13
- 2020-11-04 — Saturday Chat 12 Halloween Edition!
- 2020-11-02 — Youtube Shoutout!
- 2020-08-25 — GainSec on Saturday Chat
- 2020-08-13 — Swiping Sunday Podcast Featuring GainSec
| Agent-driven target discovery, microscope mapping, safety-monitored CNC motion, operator review, and controlled PCB pin probing—with source, dashboard, CAD, and safety documentation. | A self-hosted 3D RF-awareness and presence-intelligence platform joining local Wi-Fi, BLE, ADS-B, rail, IoT, infrastructure, and authorized LTE-lab observations. |
| An AI-augmented security assessment framework built around operator authority, scope controls, anonymization, explicit approvals, evidence, and governed reporting. | A public preview of an agent runtime substrate focused on capability containment, evidence provenance, and auditable operator control. |
| A self-hosted workbench for agent approvals, runbooks, files, review artifacts, task state, and auditable out-of-band collaboration. | An offline-first offensive framework for authorized Flock Safety security assessments and penetration testing. |
| Cardano and Amaru fuzzing and adversarial testing across serialization, mini-protocol, runtime, resource, and consensus surfaces, with replayable evidence and deterministic-simulation integration. | A reverse-engineered camera-car dashboard and agent API that gives a human or authorized agent live video, two-way audio, and motion control. |
Vulnerability / Security Research · 14 projects
Technical Walkthroughs · 5 projects
Offensive Tooling · 16 projects
Open / Public Source Projects · 17 projects
flowchart TB
J["Jon ‘GainSec’ Gaines"]
J --> C0["Vulnerability / Security Research"]
J --> C1["Technical Walkthroughs"]
J --> C2["Offensive Tooling"]
J --> C3["Open / Public Source Projects"]
J --> C4["Everything Else"]
Vulnerability / Security Research · 14 projects
flowchart TB
ROOT["Vulnerability / Security Research"]
ROOT --> S0_0["Connected Public Safety and Anti-Crime Technology"]
S0_0 --> P0_0["anti-crime-ecosystem-research"]
S0_0 --> P0_1["BirdShot"]
S0_0 --> P0_2["Flock-Safety-Trap-Shooter-Sniffer-Alarm"]
S0_0 --> P0_3["onvif-enum"]
S0_0 --> P0_4["Uniview-LAPI-Research-Toolkit"]
S0_0 --> P0_5["DigitalAlly-ThermoVu-Uniview-Security-Research"]
S0_0 --> P0_6["CVE-2017-16744-and-CVE-2017-16748-Tridium-Niagara"]
S0_0 --> P0_7["flock-safety-falcon-sparrow-alpr-edl-firehose"]
ROOT --> S0_1["Vulnerability Disclosures"]
S0_1 --> P0_8["macos-printer-simulator-security-research"]
S0_1 --> P0_9["AOL-Desktop-Gold-Security-Research"]
ROOT --> S0_2["Automotive + V2X Security"]
S0_2 --> P0_10["3rdParty-Carplay-AndroidAuto-Dongle-Security-Research"]
S0_2 --> P0_11["Wireless-Attack-Vectors-Against-Automobiles"]
ROOT --> S0_3["Hardware + Embedded Security"]
S0_3 --> P0_12["Little-Tikes-DreamProjector-Reverse-Engineering"]
ROOT --> S0_4["Research Companion Material"]
S0_4 --> P0_13["Phrack-72-Raw-Output-V2X"]
Technical Walkthroughs · 5 projects
flowchart TB
ROOT["Technical Walkthroughs"]
ROOT --> S1_0["Tutorials + Build Guides"]
S1_0 --> P1_0["Qwen 3.6 Tool-Call Fix"]
S1_0 --> P1_1["M5NanoC6-Zigbee-Sniffer"]
S1_0 --> P1_2["CloudGoatTutorial"]
ROOT --> S1_1["Lectures + Educational Material"]
S1_1 --> P1_3["Silk-Road-Lecture"]
ROOT --> S1_2["Workflow Guides"]
S1_2 --> P1_4["n8n-workflow-whisper-server"]
Offensive Tooling · 16 projects
flowchart TB
ROOT["Offensive Tooling"]
ROOT --> S2_0["Fuzzing + Adversarial Testing"]
S2_0 --> P2_0["DWARF"]
ROOT --> S2_1["Reconnaissance + Enumeration"]
S2_1 --> P2_1["crt.sh-OSX"]
ROOT --> S2_2["OSINT"]
S2_2 --> P2_2["LeakScope"]
S2_2 --> P2_3["Dorker"]
S2_2 --> P2_4["FOSINT"]
S2_2 --> P2_5["Base-Google-Dorks"]
ROOT --> S2_3["Assessment Workflow"]
S2_3 --> P2_6["GoldenNuggets-1"]
S2_3 --> P2_7["TreeHouse-Wordlists"]
S2_3 --> P2_8["Hackers-LunchBox"]
S2_3 --> P2_9["Mac-OSX-Application-Fingerprint-And-Security-Tool"]
S2_3 --> P2_10["Quick-Engagement-Directory-Maker"]
ROOT --> S2_4["Wireless + Device Tooling"]
S2_4 --> P2_11["gainsec-in-the-middle"]
S2_4 --> P2_12["Weaponized-Mousejack-Keysniff"]
ROOT --> S2_5["Payload + Bypass Research"]
S2_5 --> P2_13["RTLOify"]
ROOT --> S2_6["Legacy Tooling"]
S2_6 --> P2_14["vncpwn"]
S2_6 --> P2_15["LeakLooker-X---2022"]
Open / Public Source Projects · 17 projects
flowchart TB
ROOT["Open / Public Source Projects"]
ROOT --> S3_0["Hardware + Embedded"]
S3_0 --> P3_0["AutoProber"]
S3_0 --> P3_1["RapidPower-RoboDog"]
S3_0 --> P3_2["Super-Awesome-AI-Driver"]
ROOT --> S3_1["RF + Wireless"]
S3_1 --> P3_3["Tree-House-Defense-System-TDS"]
S3_1 --> P3_4["M5Stack-Core2-PaxCounter-WiFi-Bluetooth-Monitor"]
ROOT --> S3_3["LLM / ML / AI / Agents"]
S3_3 --> P3_5["ArcticBase"]
S3_3 --> P3_6["BattleReadyArmor-Slim"]
S3_3 --> P3_7["battlereadyarmor-pilot"]
S3_3 --> P3_8["MacOS-ImagePlayground-Improved"]
S3_3 --> P3_9["AgentReadyArmor-Teaser"]
S3_3 --> P3_10["tensorflow-generic-harness"]
S3_3 --> P3_11["BattleReadyArmor-PublicPreview"]
S3_3 --> P3_12["GainSec-Local-AI-Stack"]
S3_3 --> P3_13["MacOS-AppleIntelligence-Harness"]
ROOT --> S3_4["Applications + Utilities"]
S3_4 --> P3_14["PineapplePager-Themer"]
S3_4 --> P3_15["unicode-secret-message"]
ROOT --> S3_5["Data + Visualization"]
S3_5 --> P3_16["SectorMap"]
Everything Else · 1 project
flowchart TB
ROOT["Everything Else"]
ROOT --> S4_0["Experiments"]
S4_0 --> P4_0["IG-Clone-Tracker"]
Open the text index of every original GainSec repository
- anti-crime-ecosystem-research — Formal whitepaper, defender material, and disclosure archive for Flock Safety's hardware ecosystem.
- BirdShot — An offline-first offensive framework for authorized Flock Safety security assessments and penetration testing.
- Flock-Safety-Trap-Shooter-Sniffer-Alarm — ESP32-C6 firmware that detects and alerts on nearby Flock-related Wi-Fi activity.
- onvif-enum — Read-focused ONVIF enumeration for cameras, NVRs, and OEM physical-security devices.
- Uniview-LAPI-Research-Toolkit — Conservative Uniview/OEM LAPI client with profiles and explicit write controls.
- DigitalAlly-ThermoVu-Uniview-Security-Research — Research archive for a facial-recognition and thermal access-control terminal.
- CVE-2017-16744-and-CVE-2017-16748-Tridium-Niagara — Proofs of concept for CVE-2017-16744 and CVE-2017-16748 in Tridium Niagara.
- flock-safety-falcon-sparrow-alpr-edl-firehose — EDL-mode interaction tooling for Flock Safety Falcon/Sparrow ALPR hardware.
- macos-printer-simulator-security-research — Full disclosure and reproduction archive documenting three technical weaknesses in Apple's Printer Simulator.
- AOL-Desktop-Gold-Security-Research — Independent group security research release covering a handful of vulnerabilities found in AOL Desktop Gold.
- 3rdParty-Carplay-AndroidAuto-Dongle-Security-Research — Public Mayton/AutoPro wireless CarPlay adapter analysis, findings, evidence, source tools, and the first C2 for aftermarket Android Auto / Apple CarPlay dongles.
- Wireless-Attack-Vectors-Against-Automobiles — Published whitepaper surveying wireless attack vectors against automobiles.
- Little-Tikes-DreamProjector-Reverse-Engineering — Notes and material from reverse engineering the Little Tikes Dream Machine.
- Phrack-72-Raw-Output-V2X — Raw output, logs, and companion artifacts for GainSec's V2X paper in Phrack 72.
- Qwen 3.6 Tool-Call Fix — Configuration fix for Qwen 3.6 tool calls on DGX Spark with LM Studio and OpenClaw.
- M5NanoC6-Zigbee-Sniffer — M5Stack M5NanoC6 Zigbee sniffer build instructions.
- CloudGoatTutorial — CloudGoat lab setup tutorial using Windows, VirtualBox, and Ubuntu Server.
- Silk-Road-Lecture — Lecture material preserved in the GainSec project archive.
- n8n-workflow-whisper-server — n8n workflow connecting uploaded audio to a Whisper transcription server.
- DWARF — Cardano and Amaru fuzzing and adversarial-testing framework for serialization, protocol, runtime, resource, and consensus surfaces.
- crt.sh-OSX — macOS-compatible passive certificate transparency enumeration script.
- LeakScope — Provider-aware Shodan and ZoomEye workbench for finding and triaging exposed data across 20+ services.
- Dorker — CLI and web app for formatting search-engine dorks.
- FOSINT — Free and open-source intelligence resource index.
- Base-Google-Dorks — A basic, explicitly incomplete collection of Google dorks.
- GoldenNuggets-1 — Burp Suite extension for creating wordlists from site-map paths and parameters.
- TreeHouse-Wordlists — Wordlists for authorized penetration testing and vulnerability assessment.
- Hackers-LunchBox — Attack and finding maps for penetration tests, bug bounties, and red-team work.
- Mac-OSX-Application-Fingerprint-And-Security-Tool — Automates baseline checks for macOS application security assessments.
- Quick-Engagement-Directory-Maker — Creates repeatable engagement directory structures for security assessments.
- gainsec-in-the-middle — On-demand MiTM router/access point for authorized embedded and IoT assessments.
- Weaponized-Mousejack-Keysniff — Research tooling built around the MouseJack and KeySniffer vulnerabilities.
- RTLOify — Creates RTLO strings and filenames for controlled bypass testing.
- vncpwn — Legacy Python security tool retained in the public archive.
- LeakLooker-X---2022 — Archived 2022 working snapshot of LeakLooker-X.
- AutoProber — Agent-driven flying-probe automation with microscope mapping, CNC motion, review gates, and independent safety monitoring.
- RapidPower-RoboDog — Clean-room Python BLE control library and local web dashboard for a consumer robot dog.
- Super-Awesome-AI-Driver — Reverse-engineered camera-car dashboard and agent API with video, audio, and motion control.
- Tree-House-Defense-System-TDS — Self-hosted 3D RF awareness and presence intelligence across Wi-Fi, BLE, ADS-B, rail, IoT, and LTE lab data.
- M5Stack-Core2-PaxCounter-WiFi-Bluetooth-Monitor — Nearby Wi-Fi and Bluetooth population monitor for M5Stack Core2.
- ArcticBase — Self-hosted, auditable workbench for agent approvals, runbooks, files, and review artifacts.
- BattleReadyArmor-Slim — Governed AI-augmented security assessment framework where the operator retains authority.
- battlereadyarmor-pilot — Controlled command interface for directing offensive-security workflows.
- MacOS-ImagePlayground-Improved — macOS experimentation app for Apple's Image Playground API.
- AgentReadyArmor-Teaser — Preview of a control-in-depth runtime substrate for autonomous agents.
- tensorflow-generic-harness — Replay harness for OEM-style YOLO/SSD TensorFlow Lite model pipelines.
- BattleReadyArmor-PublicPreview — Public architecture preview for governed, privacy-preserving agentic assessments.
- GainSec-Local-AI-Stack — Scripts, workflows, and notes from local AI-stack prototyping.
- MacOS-AppleIntelligence-Harness — Local macOS harness for prompts, pipelines, and consistency experiments with Apple Foundation Models.
- PineapplePager-Themer — Visual theme editor and exporter for the Hak5 WiFi Pineapple Pager.
- unicode-secret-message — Small interface built during research into RTLO, PDF, and other Unicode characters.
- SectorMap — Offline-first self-hosted dataset browser with a galaxy-style archive interface.
- IG-Clone-Tracker — Instagram clone for lab research, prototyping, and tracking experiments.
Caution
This archive contains dual-use security research and tools. Use them only in owned or explicitly authorized environments, and follow each project’s safety and disclosure boundaries.







