offensive-hardware/spi-flash/SKILL.md
In-circuit and out-of-circuit SPI/NAND flash dumping and writing using flashrom and CH341A/FT232H.
npx skillsauth add aeondave/malskill spi-flashInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use when UART is unavailable, or a full firmware extraction/patching loop is required.
W25Q*, Macronix MX25L* or GigaDevice GD25Q*).Rule: Read at least twice, and ensure hashes match before proceeding. Variance indicates bad clip contact or SoC contention.
# Read attempt 1
flashrom -p ch341a_spi -r fw_dump1.bin
# Read attempt 2
flashrom -p ch341a_spi -r fw_dump2.bin
# Verification
md5sum fw_dump1.bin fw_dump2.bin
If hashes differ, reseat the clip, shorten cables, or power the target board VCC slightly if SoC is draining programmer current.
Rule: Always backup original raw dump offline before writing.
# Write modified firmware back
flashrom -p ch341a_spi -w fw_patched.bin
Use binwalk to verify the read was successful and contains expected headers (not just 0xFF or 0x00).
binwalk fw_dump1.bin
# Expect: U-Boot header, Squashfs, JFFS2, TRX, or CramFS
development
Auth/lab ref: Unicorn Engine CPU-only emulation for shellcode, decryptors, custom VM handlers, instruction tracing, memory hooks, and register-level experiments.
development
Auth/lab ref: Renode board and SoC simulation for MCU/RTOS firmware, UART/GPIO/peripheral modeling, GDB remote debugging, REPL platforms, and RESC scripts.
development
Auth/lab ref: Qiling OS-layer binary emulation for PE/ELF/Mach-O/UEFI/shellcode with rootfs, syscall/API hooks, filesystem mapping, and runtime patching.
databases
Auth/lab ref: QEMU user-mode and full-system emulation for cross-arch binaries, firmware, kernels, disks, serial consoles, networking, and GDB stubs.