Research & Tooling We Learn From
Physical Security Atlas exists because access-control credentials can be read and reproduced using hardware that is inexpensive, openly documented, and widely available. That is not a theoretical claim, and the work below is a large part of the evidence for it. Each project listed here is public, independently maintained, and well documented; together they explain why the exposures we catalog are a practical problem today rather than an academic one for later.
We list them for a second reason as well. This field advances because researchers publish what they find instead of sitting on it, and a database of compromised credentials would not be possible — or particularly useful — without that tradition.
Open-source research tooling
-
RFID Research Group — Proxmark3 and Chameleon Ultra
Maintains the community firmware for the Proxmark3, the reference instrument for reading, analyzing, and emulating both LF (125 kHz) and HF (13.56 MHz) credentials, and for the Chameleon Ultra emulator. The same project maintains the public MIFARE Classic key dictionary cited on our About page — the clearest single illustration of how many deployments never changed the keys they shipped with.
-
Momentum firmware — Flipper Zero
Open-source firmware for the Flipper Zero. Tooling of this kind is why LF credential cloning is a consumer-priced problem rather than a laboratory exercise, and it is the practical reason a 125 kHz badge should no longer be treated as an access-control mechanism.
-
iCopy-X Open — Lab401
An open-source rebuild of the iCopy-X's interface and middleware, written from scratch by quantum-x of Lab401 after the commercial device stopped receiving updates in 2022. Two things make it instructive. It is a case study in reviving working security hardware that a vendor abandoned; and the device itself shows how little expertise credential cloning now demands, since common LF and MIFARE Classic cards can be read and written back at the press of a button with no knowledge of the underlying protocol. Released under a noncommercial licence, explicitly to avoid enabling commercial cloners.
-
ESPKey
An inline implant that taps the Wiegand D0/D1 data lines between a reader and its controller. Its manual is a concise, practical demonstration of the interface weakness described on our About page: because Wiegand is unencrypted and unauthenticated in one direction, anything on the wire can be recorded and replayed. It is also a useful reminder that upgrading the credential alone does not fix the reader-to-controller link.
Reference and analysis
-
RFID Attack Matrix
Maps credential technologies to the attacks that actually work against them. A practical starting point for anyone who needs to translate “our site uses HID Prox” into a concrete, defensible statement of risk.
-
Proxmark3.app
A browser-based Proxmark3 client: it connects to the device over USB and reads, writes, and analyzes tags without a local toolchain. Notable for how far it lowers the barrier to entry — and correspondingly useful for defenders who want to audit their own badges without first standing up a development environment.
No affiliation. Every project listed on this page is independent of Physical Security Atlas. They appear here because their published work informs ours; inclusion does not imply that they endorse, sponsor, review, or are affiliated with this project, and no relationship should be inferred in either direction. All links point to publicly available material, and each project is governed by its own licence and terms. Nothing here is an invitation to use these tools against systems you are not authorized to assess — see our Code of Ethics.
Think something belongs on this list? Signed-in members can tell us through Support; everyone else is welcome to contact the team directly.