{"id":51818577,"url":"https://github.com/at0m-b0mb/glitchtrigger-flipperzero","last_synced_at":"2026-07-24T05:01:02.032Z","repository":{"id":372349000,"uuid":"1304563892","full_name":"at0m-b0mb/GlitchTrigger-FlipperZero","owner":"at0m-b0mb","description":"Precise, configurable GPIO pulse generator for voltage-glitch / fault-injection study on your own dev boards — Flipper Zero FAP (GPIO).","archived":false,"fork":false,"pushed_at":"2026-07-22T01:26:54.000Z","size":417,"stargazers_count":4,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"main","last_synced_at":"2026-07-22T03:00:16.291Z","etag":null,"topics":["embedded-security","fap","fault-injection","flipper-zero","flipperzero","glitching","gpio","hardware-security","voltage-glitching"],"latest_commit_sha":null,"homepage":null,"language":"C","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/at0m-b0mb.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-07-18T03:25:15.000Z","updated_at":"2026-07-22T01:26:58.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/at0m-b0mb/GlitchTrigger-FlipperZero","commit_stats":null,"previous_names":["at0m-b0mb/glitchtrigger-flipperzero"],"tags_count":3,"template":false,"template_full_name":null,"purl":"pkg:github/at0m-b0mb/GlitchTrigger-FlipperZero","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/at0m-b0mb%2FGlitchTrigger-FlipperZero","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/at0m-b0mb%2FGlitchTrigger-FlipperZero/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/at0m-b0mb%2FGlitchTrigger-FlipperZero/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/at0m-b0mb%2FGlitchTrigger-FlipperZero/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/at0m-b0mb","download_url":"https://codeload.github.com/at0m-b0mb/GlitchTrigger-FlipperZero/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/at0m-b0mb%2FGlitchTrigger-FlipperZero/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":35744650,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-07-20T02:08:10.276Z","status":"online","status_checked_at":"2026-07-22T02:00:06.236Z","response_time":124,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["embedded-security","fap","fault-injection","flipper-zero","flipperzero","glitching","gpio","hardware-security","voltage-glitching"],"created_at":"2026-07-22T03:00:20.761Z","updated_at":"2026-07-23T04:00:55.217Z","avatar_url":"https://github.com/at0m-b0mb.png","language":"C","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003c!-- banner --\u003e\n\u003cp align=\"center\"\u003e\n  \u003cimg src=\"images/banner.png\" alt=\"Glitch Trigger — Flipper Zero fault-injection pulse generator\" width=\"100%\"\u003e\n\u003c/p\u003e\n\n\u003ch1 align=\"center\"\u003eGlitch Trigger\u003c/h1\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003cb\u003eDrop the rail. Catch the fault.\u003c/b\u003e\u003cbr\u003e\n  A precise, configurable GPIO pulse generator for voltage-glitch / fault-injection\n  study on your own dev boards — for the \u003ca href=\"https://flipperzero.one\"\u003eFlipper Zero\u003c/a\u003e.\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"https://github.com/at0m-b0mb/GlitchTrigger-FlipperZero/actions/workflows/build.yml\"\u003e\u003cimg src=\"https://github.com/at0m-b0mb/GlitchTrigger-FlipperZero/actions/workflows/build.yml/badge.svg\" alt=\"Build FAP\"\u003e\u003c/a\u003e\n  \u003cimg src=\"https://img.shields.io/badge/firmware-fw%207%20%2F%20API%2087.1-orange\" alt=\"Firmware\"\u003e\n  \u003cimg src=\"https://img.shields.io/badge/category-GPIO-ff5244\" alt=\"Category\"\u003e\n  \u003cimg src=\"https://img.shields.io/badge/license-MIT-blue\" alt=\"License\"\u003e\n  \u003cimg src=\"https://img.shields.io/badge/built%20with-ufbt-8a2be2\" alt=\"ufbt\"\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003cimg src=\"images/screens.png\" alt=\"Glitch Trigger screens\" width=\"100%\"\u003e\n\u003c/p\u003e\n\n---\n\n## What it is\n\n**Glitch Trigger** turns your Flipper into a tiny, precise pulse generator for\n**hardware fault injection** — the family of attacks where you inject a brief,\ncarefully-timed disturbance into a chip's power rail (a *voltage glitch*) to make\nit skip an instruction, mis-read a fuse, or fall out of a protected state. It's\nhow people study secure-boot bypasses, PIN-retry counters, and readout\nprotection on **their own** development boards.\n\nThe Flipper can't glitch a target on its own — a 3.3 V GPIO can't crowbar a power\nrail. What it *is* good at is producing the **trigger pulse** with tight, jitter-\ncontrolled timing. Glitch Trigger drives a GPIO pin that switches an external\nMOSFET / gate-driver crowbar; you dial in the shape of the pulse and how it's\ntriggered, and the Flipper does the timing.\n\n\u003e **Educational hardware-security tool.** Fault injection can corrupt data and\n\u003e permanently damage hardware. Use it only on boards you own and are authorised\n\u003e to test. See [Safety \u0026 scope](#safety--scope).\n\n---\n\n## Features\n\n- **The shot model** — every trigger produces one *shot*:\n  `trigger → delay → pulse(s)`. You set the **delay** (trigger-to-glitch offset),\n  the **width** (the glitch itself), the number of **pulses** and the **gap**\n  between them, and the **polarity** (active-high or active-low).\n- **Cycle-accurate timing** — pulses are shaped by busy-waiting on the Cortex-M4\n  **DWT cycle counter** inside a critical section (interrupts masked), so nothing\n  else on the MCU can jitter the edge. Resolution ≈ **15.6 ns** (one 64 MHz cycle).\n- **Three trigger modes**\n  - **Manual** — press **OK** to fire.\n  - **External** — an edge on the trigger-in pin fires a shot from a GPIO\n    **interrupt**, for lowest latency (arm it to a target's reset/UART/GPIO).\n  - **Repeat** — free-running, one shot every interval.\n- **Sweep the fault window** — walk the pulse **width** across a range\n  (`from … to`, `step`), or turn on **2D** to sweep a **delay × width grid** — the\n  real parameter search space. **Dwell** fires *N* shots at each point for\n  statistics, and a progress bar tracks position across the grid.\n- **Auto-hit detection** — wire a target **feedback pin** (a success/status line)\n  and the sweep marks a hit *automatically* the moment it reaches the success\n  level, turning a sweep into a hands-off campaign. Or just press **OK** to mark\n  the point in play yourself.\n- **Live fault map** — every hit is plotted on a **delay × width heatmap** you can\n  scroll a cursor across to read any cell's parameters, then **export to CSV** —\n  watch the fault window take shape and take the grid with you.\n- **Linear or Random search** — step the grid in order, or sample it at random to\n  dodge periodic aliasing with the target's own timing.\n- **Profiles** — save, load and delete named parameter sets on the SD card, with\n  on-device name entry. Recall your `stm32-vcc` or `rp2040-drop` setup instantly.\n- **CSV hit log** — every hit (manual or auto) is appended to\n  `apps_data/glitch_trigger/hits.csv` with its delay, width, pulses and timestamp,\n  ready to graph off-device.\n- **Remembers your setup** — the last-used config and feedback settings are\n  restored automatically on the next launch.\n- **On-device Wiring diagram** — a labelled hook-up sketch (Flipper → MOSFET\n  crowbar → target) with rotating safety reminders, so you don't need the README\n  on the bench.\n- **Live feedback** — an animated pulse timeline, an ARM/FIRE state badge, a shot\n  counter, and gated LED / sound / vibro on every shot.\n- **Selectable pins** — pick the glitch-out, trigger-in and feedback header pins.\n\n---\n\n## Screens\n\n| Menu | Trigger | Sweep | Fault Map | Profiles | Wiring | Configure |\n|---|---|---|---|---|---|---|\n| Pick a mode | Fire screen with a live pulse timeline | Hunt the fault window (2D + auto-hit) | Heatmap of hits + CSV export | Save / load setups | Hook-up + safety | Every parameter |\n\n\u003cp align=\"center\"\u003e\u003cimg src=\"images/screen_trigger.png\" width=\"360\" alt=\"Trigger screen\"\u003e\u003c/p\u003e\n\nThe **Trigger** screen is the centrepiece: a schematic timeline shows the trigger\ntick, the dashed **delay**, and the glitch **pulse(s)** (drawn up for active-high,\ndown for active-low). A one-line readout under it echoes the live parameters, and\nthe badge tracks **IDLE → ARMED → FIRE**.\n\n---\n\n## Safety \u0026 scope\n\nFault injection is genuinely capable of damaging hardware. Read this before you\nwire anything.\n\n- **3.3 V logic only.** The Flipper GPIO is a 3.3 V push-pull output. **Never**\n  connect a GPIO pin directly to a target power rail or to any voltage outside\n  0–3.3 V. The pin *switches* a crowbar; it is not the crowbar.\n- **Switch the rail with a MOSFET / gate driver**, not the pin. A logic-level\n  N-channel MOSFET (or a dedicated crowbar / glitcher board such as a\n  ChipWhisperer target) is the device that actually shorts/drops the rail.\n- **Common ground.** The Flipper and the target must share a ground reference.\n- **Keep leads short**, add a series gate resistor, and expect to blow up a board\n  or two while learning — that's the hobby.\n- **Only your own hardware.** Only glitch boards you own and are explicitly\n  authorised to test. This tool is for education and defensive research.\n\n---\n\n## Hardware \u0026 wiring\n\n```\n Flipper GPIO (3V3)          gate driver / MOSFET             Target board\n ┌───────────────┐          ┌────────────────────┐          ┌───────────┐\n │  pin 2  GLITCH ├──────────┤ gate           drain├──────────┤ VCC / rail│\n │  pin 6  TRIG-IN│◄──edge── │  (logic-level NMOS  │          │           │\n │  pin 8  GND    ├──────────┤  source → GND)      ├──────────┤ GND       │\n └───────────────┘          └────────────────────┘          └───────────┘\n                         common ground everywhere\n```\n\n**Default pins** (both selectable in *Settings*):\n\n| Signal | Default | Flipper header pin | Notes |\n|---|---|---|---|\n| Glitch out | `PA7` | **2** | drives the crowbar gate |\n| Trigger in | `PB2` | **6** | external-trigger edge input |\n| Ground | `GND` | **8 / 11 / 18** | shared with the target |\n\nSelectable output/input pins: `PA7` (2), `PA6` (3), `PA4` (4), `PB3` (5),\n`PB2` (6), `PC3` (7). These avoid the SPI / UART / I²C lines so they're safe to\nbit-bang.\n\nThe in-app **Wiring** screen redraws this with your currently-selected pins.\n\n---\n\n## How the timing works\n\nA shot runs as:\n\n```\ndrive idle level\ncoarse-delay (interrupts ON)     // bulk of a long arm delay\n\nFURI_CRITICAL_ENTER();           // masked → no jitter on the glitch edge\n  busy-wait  fine delay  (DWT cycles)\n  drive active\n  busy-wait  width       (DWT cycles)\n  drive idle\nFURI_CRITICAL_EXIT();\n\nrepeat for remaining burst pulses:\n  gap (interrupts ON)\n  FURI_CRITICAL_ENTER(); pulse (DWT cycles); FURI_CRITICAL_EXIT();\n```\n\nDelays are converted straight to CPU cycles from `SystemCoreClock` (64 MHz) and\ntimed against `DWT-\u003eCYCCNT`, giving **~15.6 ns** granularity. For long arm delays\nthe coarse part runs with interrupts enabled so the system isn't frozen, and only\nthe final, precision-critical slice (the fine delay + the glitch edge) is masked —\neach masked window is bounded to **~1 ms**. In a burst, the inter-pulse gaps run\nwith interrupts on and only each short pulse is masked. In **External** mode the\nshot is fired directly from the GPIO interrupt for the lowest possible\ntrigger-to-pulse latency.\n\n\u003e The shortest realisable pulse is bounded by the GPIO write + loop overhead\n\u003e (tens of ns). Widths below a few hundred ns are approximate — read them as\n\u003e \"as short as possible\", not exact.\n\n---\n\n## Parameters\n\n| Parameter | Range (ladder) | Meaning |\n|---|---|---|\n| **Delay** | 0 – 100 ms | trigger → first pulse offset |\n| **Width** | 62 ns – 500 µs | the glitch pulse width |\n| **Pulses** | 1 – 64 | pulses per shot (bursts) |\n| **Gap** | 1 µs – 10 ms | spacing between pulses in a burst |\n| **Polarity** | Active-High / Active-Low | idle low + pulse high, or idle high + pulse low |\n| **Trigger** | Manual / External / Repeat | how a shot is fired |\n| **Ext Edge** | Rising / Falling | which edge fires in External mode |\n| **Repeat** | 10 ms – 5 s | interval in Repeat mode |\n| **Sweep from / to / step** | 62 ns – 500 µs | width range for the sweep hunter |\n| **Sweep 2D** | On / Off | also sweep delay → a delay × width grid |\n| **Search** | Linear / Random | step the grid in order, or sample it at random |\n| **Dwell** | 1 – 100 | shots fired at each sweep point |\n| **2D delay from / to / step** | 0 – 100 ms | delay range for a 2D sweep |\n| **Feedback pin / Success lvl** | pin · HIGH/LOW | target line + level that counts as a hit |\n| **Auto-hit / Log hits** | On / Off | auto-mark from feedback · append hits to CSV |\n\nAll values move along 1-2-5 \"nice number\" ladders, so one knob spans the whole\nrange and the readout is always in friendly units.\n\n### Sweep campaigns\n\nA single `width` sweep is the quick hunt; **2D** is the real one. Turn on\n**Sweep 2D** and set the delay range, and the runner walks a full **delay × width**\ngrid, firing **Dwell** shots at each cell. Wire the target's success line to the\n**Feedback pin**, set the **Success level**, enable **Auto-hit**, and the sweep\nrecords — and (with **Log hits**) logs — every cell that faults, unattended. Set\n**Search** to *Random* to sample the grid out of order.\n\nEvery hit also lands on the **Fault Map** — a live delay × width heatmap. Open it\nfrom the menu, scroll the cursor to read any cell's exact width/delay, and press\n**OK** to write the whole grid to `faultmap.csv`. Pull `hits.csv` / `faultmap.csv`\noff the SD card afterwards to plot the fault window.\n\n---\n\n## Build \u0026 install\n\nBuilt with **[ufbt](https://pypi.org/project/ufbt/)** against official firmware\n(**fw 7 / API 87.1**).\n\n```bash\n# one-time\npython3 -m pip install --upgrade ufbt\nufbt update            # pull the SDK (release channel)\n\n# in the repo\nufbt                   # build  -\u003e dist/glitch_trigger.fap\nufbt launch            # build + install + run on a connected Flipper\n```\n\nOr grab `glitch_trigger.fap` from the [latest release](../../releases) and drop\nit into `apps/GPIO/` on your Flipper's SD card.\n\nCI builds every push on both the **release** and **dev** SDK channels.\n\n---\n\n## Project layout\n\n```\nglitch_trigger.c / _i.h      app lifecycle, view dispatcher, notifications\napplication.fam              FAP manifest (category: GPIO)\nhelpers/\n  glitch_config.c/.h         parameter model, value ladders, formatters, pin table\n  glitch_engine.c/.h         the pulse engine — DWT timing, GPIO, external-trigger ISR, feedback read\n  glitch_storage.c/.h        SD profiles, CSV hit log, last-config persistence\n  glitch_map.c/.h            the fault-map grid + CSV export\nviews/\n  trigger_view.c/.h          the fire screen (pulse timeline + state machine)\n  sweep_view.c/.h            the sweep hunter (1D/2D, progress, auto-hit)\n  faultmap_view.c/.h         the delay × width heatmap + cursor\n  wiring_view.c/.h           the hook-up diagram + safety tips\nscenes/                      start · params · trigger · sweep · faultmap · profiles(+name/act) · wiring · settings · about\nicons/  images/              app icon, banner, social card, screen mockups\ntools_gen_*.py               regenerate the icon / banner / mockups\n```\n\n---\n\n## Ethics \u0026 legal\n\nThis is an **educational hardware-security** project. Fault injection is a\nlegitimate and widely-taught technique for understanding — and defending against\n— attacks on embedded devices. Use Glitch Trigger only on hardware you own or are\nexplicitly authorised to test. You are responsible for what you connect it to.\n\n---\n\n## License\n\n[MIT](LICENSE) © 2026 [at0m-b0mb](https://github.com/at0m-b0mb)\n\n\u003cp align=\"center\"\u003e\u003csub\u003ePart of the at0m-b0mb Flipper Zero toolset · built with ufbt\u003c/sub\u003e\u003c/p\u003e\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fat0m-b0mb%2Fglitchtrigger-flipperzero","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fat0m-b0mb%2Fglitchtrigger-flipperzero","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fat0m-b0mb%2Fglitchtrigger-flipperzero/lists"}