Choose your alarm panel to see what tools are available
Step 1: Select Manufacturer
HKC Security
SecureWatch & SecureWave panels
🛡️
Honeywell Galaxy
G2, Dimension series · RS485 bus
📷
Hikvision CCTV
Cameras & NVRs · firmware 5.4.0 and below
HKC Security›Select panel generation
Step 2: Which generation?
Older HKC SecureWatch
8/12 zone panels · green PCB · numeric keypad · manufactured up to ~2010
Newer HKC SecureWave
1070 panel · touchscreen or LED keypad · manufactured 2010 onwards
HKC Security›SecureWatch (8/12)›Choose tool
Step 3: What would you like to do?
Serial
Read All User & Engineer Codes
Connect directly to the panel over its programming port. The tool will log in using the remote code and read out all user codes and the engineer code automatically.
Required equipment
🔌 HKC programming lead (4-pin Molex to USB/RS232)
💻 Chrome or Edge browser
Flash Dump
Read Flash Chip (Offline)
De-power the panel, clip a programmer onto the EEPROM chip, and read the raw flash memory. Upload the resulting file here for full analysis: all user codes, engineer code, zone names and panel configuration.
Required equipment
⚙️ CH341A USB programmer
🪛 SOIC-8 test clip
💻 AsProgrammer software (free)
Bus Monitor
Keypad Bus Diagnostic
Passively listen to the RS-485 keypad bus without interfering with the panel. See live keypad traffic, keypresses, zone states, arm/disarm events and tamper alerts in real time.
Required equipment
🔌 USB to RS-485 adapter
💻 Chrome or Edge browser
HKC Security›SecureWave (1070)›Choose tool
Step 3: What would you like to do?
Flash Dump
Read Flash Chip (Offline)
De-power the panel and clip a programmer onto the external flash chip. Location differs by board revision: V1 is on the front, V2 and V3 are on the back. Upload the resulting 4MB .bin file for full analysis of all codes, zones, and panel config.
Passively listen to the RS-485 keypad bus. See which keypads are registered, live keypresses, zone open/close events, arm and disarm activity, and tamper alerts: all without touching the panel configuration.
Required equipment
🔌 USB to RS-485 adapter
💻 Chrome or Edge browser
🔗 Connect to A/B terminals on panel
Honeywell Galaxy›Choose tool
Step 2: What would you like to do?
Bus Monitor
Keypad Bus Diagnostic
Passively listen to the Galaxy RS-485 keypad bus. See live keypresses, what text is displayed on keypads, arm/disarm events, tamper alerts, and which devices (keypads, RIOs, prox readers) are connected: without touching the panel at all.
Required equipment
🔌 USB to RS-485 adapter
💻 Chrome or Edge browser
🔗 Connect to T+ / T- terminals on panel
Virtual Keypad
Remote Access via Keypad Emulation
Emulate a Galaxy keypad on the RS-485 bus to read user codes and engineer code without needing physical access to the keypad. Requires further development.
Required equipment
🔌 USB to RS-485 adapter
Hikvision CCTV›Choose tool
Step 2: What would you like to do?
Password Extract
Extract Camera / NVR Password
Connects directly to a Hikvision camera or NVR on the local network and extracts the admin password from its configuration file. Works on firmware 5.4.0 and below. No login required: this is a known firmware vulnerability.
Requirements
💻 HKC Local Agent running on this laptop
🌐 Laptop connected to same network as camera
📷 Hikvision firmware version 5.4.0 or below
Network Scan
Find Hikvision Devices on LAN
Scans the local network for any devices with open HTTP/RTSP ports that could be Hikvision cameras or NVRs. Enter the subnet and the agent will probe each address.
Requirements
💻 HKC Local Agent running on this laptop
🌐 Laptop connected to site network
Site Details: Required Before Starting
These details are recorded with every result for audit purposes.
Upload Flash File
Upload a .bin flash dump from an HKC 1070 panel for analysis
Each successful upload (with a valid panel ID) costs 1 credit.
Invalid files (unrecognised flash format) are not charged.
Contact admin to top up credits.
What's Extracted
✓ Panel ID (hex & decimal)
✓ Firmware version
✓ Site name
✓ Partition names
✓ User codes & hashes
✓ Zone names & types
✓ Engineer lock status
✓ Raw XML (all versions)
✓ Hex region viewer
── Analysis Result ──────────────────────
Upload HKC 8/12 Flash File
V1 Casino hardware: nibble-offset encoded codes, no AES
Panel Details
Flash File (.bin)
📁
Drop .bin file here or click to browse
HKC 8/12 Casino EEPROM dump: max 10MB
About HKC 8/12
The HKC 8/12 (Casino hardware) stores codes
in a proprietary binary format.
Codes are extracted directly from the EEPROM
and decoded server-side.
Default codes:
✓ User 1: 1111
✓ Engineer: 4567
✓ Remote default: 1111 or 139008
What's Extracted
✓ All 64 user codes (plain text)
✓ 7 remote user codes
✓ User names
✓ Zone names (up to 70)
✓ Partition names
✓ Site name
✓ Active/inactive user flags
✓ Panel ID (if present)
── Analysis Result ──────────────────────
HKC 8/12 Serial Access
Direct COM port connection: Chrome/Edge only · Requires Web Serial API
⚠ Web Serial API not supported in this browser. Use Chrome or Edge on desktop.
Connection
Panel Details
Remote Code Login
Read Users
After successful login, read all user codes from the panel over serial.
Serial Log
Extracted Codes
#
Name
Code
Raw Bytes
Hikvision Tools
Password extraction & network scan · requires Local Agent
⬤ Agent: checking...
⚠ Local Agent not running. The Hikvision tools require the HKC Local Agent to be running on this laptop.
Start the Local Agent
1. Make sure Node.js is installed on this laptop 2. Download the agent: agent.js 3. Open a terminal and run: node agent.js4. Keep the terminal window open while using these tools
Target Device
How it works
Downloads the configuration file from the device using a known endpoint present in firmware 5.4.0 and below. The file is decrypted locally by the agent and passwords are extracted. No credentials needed.
If the device returns a 404 or authentication error the firmware is likely too new.
Compatible Devices
Cameras: DS-2CD series, DS-2DE series NVRs: DS-7600, DS-7700, DS-7800 series DVRs: DS-7200, DS-7300 series Requirement: Firmware 5.4.0 or below Default port: 80 (try 8080 if 80 fails)
If it fails
404 error: Firmware too new, endpoint removed Auth error: Device has custom auth enabled Timeout: Wrong IP, wrong port, or firewall blocking No passwords: Different encryption in this firmware build
Extracted Credentials
Enter an IP address and click Extract to begin
Scan Subnet
Probes .1 through .254 for open HTTP/RTSP ports.
Takes 1–3 minutes depending on network size.
Devices Found
Enter subnet and click Scan
Keypad Bus Monitor
Passive RS-485 listener: SecureWatch (9600) and SecureWave (19200) · Chrome/Edge only
⚠ Web Serial API not supported. Use Chrome or Edge on desktop.