awesome-embedded-and-iot-security

IoT security toolkit

A curated collection of resources and tools for analyzing and securing embedded and IoT devices

A curated list of awesome embedded and IoT security resources.

GitHub

2k stars
66 watching
242 forks
last commit: almost 3 years ago
Linked from 5 awesome lists

awesomeawesome-listembeddedfirmwareiotsecurity

Awesome Embedded and IoT Security / Software Tools / Analysis Frameworks

EXPLIoTPentest framework like Metasploit but specialized for IoT
FACT - The Firmware Analysis and Comparison ToolFull-featured static analysis framework including extraction of firmware, analysis utilizing different plug-ins and comparison of different firmware versions

Awesome Embedded and IoT Security / Software Tools / Analysis Frameworks / FACT - The Firmware Analysis and Comparison Tool

Improving your firmware security analysis process with FACTConference talk about FACT

Awesome Embedded and IoT Security / Software Tools / Analysis Frameworks

FwAnalyzer496almost 3 years agoAnalyze security of firmware based on customized rules. Intended as additional step in DevSecOps, similar to CI
HAL – The Hardware Analyzer631almost 2 years agoA comprehensive reverse engineering and manipulation framework for gate-level netlists
HomePWN884over 3 years agoSwiss Army Knife for Pentesting of IoT Devices
IoTSecFuzzFramework for automatisation of IoT layers security analysis: hardware, software and communication
Killerbee767about 3 years agoFramework for Testing & Auditing ZigBee and IEEE 802.15.4 Networks
PRET3,963about 2 years agoPrinter Exploitation Toolkit
Routersploit12,253almost 2 years agoFramework dedicated to exploit embedded devices

Awesome Embedded and IoT Security / Software Tools / Analysis Tools

Binwalk11,530almost 2 years agoSearches a binary for "interesting" stuff, as well as extracts arbitrary files
cwe_checker1,155almost 2 years agoFinds vulnerable patterns in binary executables - ELF support for x86, ARM, and MIPS, experimental bare-metal support
emba2,762almost 2 years agoAnalyze Linux-based firmware of embedded devices
Firmadyne1,842about 2 years agoTries to emulate and pentest a firmware
Firmwalker1,073about 3 years agoSearches extracted firmware images for interesting files and information
Firmware Slap472about 6 years agoDiscovering vulnerabilities in firmware through concolic analysis and function clustering
GhidraSoftware Reverse Engineering suite; handles arbitrary binaries, if you provide CPU architecture and endianness of the binary
Radare220,862almost 2 years agoSoftware Reverse Engineering framework, also handles popular formats and arbitrary binaries, has an extensive command line toolset
Trommel207about 6 years agoSearches extracted firmware images for interesting files and information

Awesome Embedded and IoT Security / Software Tools / Extraction Tools

FACT Extractor84almost 2 years agoDetects container format automatically and executes the corresponding extraction tool
Firmware Mod Kit845about 2 years agoExtraction tools for several container formats
The SRecord packageCollection of tools for manipulating EPROM files (can convert lots of binary formats)

Awesome Embedded and IoT Security / Software Tools / Support Tools

JTAGenum728almost 3 years agoAdd JTAG capabilities to an Arduino
OpenOCDFree and Open On-Chip Debugging, In-System Programming and Boundary-Scan Testing

Awesome Embedded and IoT Security / Software Tools / Misc Tools

Cotopaxi353over 2 years agoSet of tools for security testing of Internet of Things devices using specific network IoT protocols
dumpflash290over 4 years agoLow-level NAND Flash dump and parsing utility
flashrom909almost 2 years agoTool for detecting, reading, writing, verifying and erasing flash chips
Samsung Firmware Magic212over 5 years agoDecrypt Samsung SSD firmware updates

Awesome Embedded and IoT Security / Hardware Tools

Bus BlasterDetects and interacts with hardware debug ports like and
Bus PirateDetects and interacts with hardware debug ports like UART and JTAG
ShikraDetects and interacts with hardware debug ports like UART and JTAG. Among other protocols
JTAGULATORDetects JTAG Pinouts fast
SaleaeEasy to use Logic Analyzer that support many protocols
IkalogicAlternative to Saleae logic analyzers
HydraBusOpen source multi-tool hardware similar to the BusPirate but with NFC capabilities
ChipWhispererDetects Glitch/Side-channel attacks
Glasgow1,929almost 2 years agoTool for exploring and debugging different digital interfaces
J-LinkJ-Link offers USB powered JTAG debug probes for multiple different CPU cores

Awesome Embedded and IoT Security / Hardware Tools / Bluetooth BLE Tools

UberTooth OneOpen source 2.4 GHz wireless development platform suitable for Bluetooth experimentation
Bluefruit LE SnifferEasy to use Bluetooth Low Energy sniffer

Awesome Embedded and IoT Security / Hardware Tools / ZigBee Tools

ApiMoteZigBee security research hardware for learning about and evaluating the security of IEEE 802.15.4/ZigBee systems. Killerbee compatible
FreakduinoLow Cost Battery Operated Wireless Arduino Board that can be turned into a IEEE 802.15.4 protocol sniffer

Awesome Embedded and IoT Security / Hardware Tools / SDR Tools

RTL-SDRCheapest SDR for beginners. It is a computer based radio scanner for receiving live radio signals frequencies from 500 kHz up to 1.75 GHz
HackRF OneSoftware Defined Radio peripheral capable of transmission or reception of radio signals from 1 MHz to 6 GHz (half-duplex)
YardStick OneHalf-duplex sub-1 GHz wireless transceiver
LimeSDRSoftware Defined Radio peripheral capable of transmission or reception of radio signals from 100 KHz to 3.8 GHz (full-duplex)
BladeRF 2.0Software Defined Radio peripheral capable of transmission or reception of radio signals from 47 MHz to 6 GHz (full-duplex)
USRP B SeriesSoftware Defined Radio peripheral capable of transmission or reception of radio signals from 70 MHz to 6 GHz (full-duplex)

Awesome Embedded and IoT Security / Hardware Tools / RFID NFC Tools

Proxmark 3 RDV4Powerful general purpose RFID tool. From Low Frequency (125kHz) to High Frequency (13.56MHz) tags
ChamaleonMiniProgrammable, portable tool for NFC security analysis
HydraNFCPowerful 13.56MHz RFID / NFC platform. Read / write / crack / sniff / emulate

Awesome Embedded and IoT Security / Books

Practical IoT Hacking2020, Fotios Chantzis, Evangel Deirme, Ioannis Stais, Paulino Calderon, Beau Woods:
The Hardware Hacking Handbook: Breaking Embedded Security with Hardware Attacks2020, Jasper van Woudenberg, Colin O'Flynn:
The Hacker's Hardware Toolkit: The best collection of hardware gadgets for Red Team hackers, Pentesters and security researchers2,085about 6 years ago2019, Yago Hansen:
The IoT Hacker's Handbook: A Practical Guide to Hacking the Internet of Things2019, Aditya Gupta:
Hardware Security: A Hands-on Learning Approach2018, Mark Swarup Tehranipoor:
Pentesting Hardware - A Practical Handbook (DRAFT)491over 7 years ago2018, Mark Carney:
Inside Radio: An Attack and Defense Guide2018, Qing Yang, Lin Huang
IoT Penetration Testing Cookbook2017, Aditya Gupta, Aaron Guzman:
The Hardware Hacker: Adventures in Making and Breaking Hardware2017, Andrew Huang:
The Car Hacker's Handbook: A Guide for the Penetration Tester2016, Craig Smith:
The Art of PCB Reverse Engineering2015, Keng Tiong Ng:
Abusing the Internet of Things: Blackouts, Freakouts, and Stakeouts2015, Nitesh Dhanjan:
Hacking Wireless Exposed2015, Joshua Wright , Johnny Cache:
Hardware Security: Design, Threats, and Safeguards2014, Debdeep Mukhopadhyay:
The Firmware Handbook (Embedded Technology)2014, Jack Ganssle:
Hacking the XBOX2013, Andrew Huang:

Awesome Embedded and IoT Security / Research Papers

SAFER: Development and Evaluation of an IoT Device Risk Assessment Framework in a Multinational Organization2020, Oser et al:
Detecting IoT Devices and How They Put Large Heterogeneous Networks at Security Risk2019, Agarwal et al:
BenchIoT: A Security Benchmark for the Internet of Things2019, Almakhdhub et al:
SoK: Security Evaluation of Home-Based IoT Deployments2019, Alrawi et al:
Challenges in Designing Exploit Mitigations for Deeply Embedded Systems2019, Abbasi et al:
PeriScope: An Effective Probing and Fuzzing Framework for the Hardware-OS Boundary2019, Song et al:
What You Corrupt Is Not What You Crash: Challenges in Fuzzing Embedded Devices2018, Muench et al:
Embedded Device Vulnerability Analysis Case Study Using Trommel2017, O'Meara et al:
How to Break Secure Boot on FPGA SoCs through Malicious Hardware2017, Jacob et al:
Towards Automated Classification of Firmware Images and Identification of Embedded Devices2017, Costin et al:
Embedded Security Testing with Peripheral Device Caching and Runtime Program State Approximation2016, Kammerstetter et al:
Towards Automated Dynamic Analysis for Linux-based Embedded Firmware2016, Chen et al:
Automated Dynamic Firmware Analysis at Scale: A Case Study on Embedded Web Interfaces2016, Costin et al:
Firmalice - Automatic Detection of Authentication Bypass Vulnerabilities in Binary Firmware2015, Shoshitaishvili et al:
Embedded Systems Security: Threats, Vulnerabilities, and Attack Taxonomy2015, Papp et al:
Avatar: A Framework to Support Dynamic Security Analysis of Embedded Systems' Firmwares2014, Zaddach et al:
Analysis of embedded applications by evolutionary fuzzing2014, Alimi et al:
A Large-Scale Analysis of the Security of Embedded Firmwares2014, Costin et al:
FIE on Firmware: Finding Vulnerabilities in Embedded Systems using Symbolic Execution2013, Davidson et al:

Awesome Embedded and IoT Security / Case Studies

Binary Hardening in IoT products
Cracking Linksys “Encryption”
Deadly Sins Of DevelopmentConference talk presenting several real world examples on real bad implementations
Dumping firmware from a device's SPI flash with a buspirate
Hacking the DSP-W215, Again
Hacking the PS4Introduction to PS4's security
IoT Security@CERN
Multiple vulnerabilities found in the D-link DWR-932B
Pwning the Dlink 850L routers and abusing the MyDlink Cloud protocol
PWN Xerox Printers (...again)
Reversing Firmware With Radare
Reversing the Huawei HG533

Awesome Embedded and IoT Security / Free Training

CSAW Embedded Security Challenge 201935almost 7 years agoCSAW 2019 Embedded Security Challenge (ESC)
Embedded Security CTFMicrocorruption: Embedded Security CTF
Hardware Hacking 10147over 7 years agoWorkshop @ BSides Munich 2019
IoTGoat181over 6 years agoIoTGoat is a deliberately insecure firmware based on OpenWrt
Rhme-20150about 2 years agoFirst riscure Hack me hardware CTF challenge
Rhme-20162about 2 years agoRiscure Hack me 2 is a low level hardware CTF challenge
Rhme-2017/20180about 2 years agoRiscure Hack Me 3 embedded hardware CTF 2017-2018

Awesome Embedded and IoT Security / Websites

Hacking Printers WikiAll things printer
OWASP Embedded Application Security ProjectDevelopment best practices and list of hardware and software tools
OWASP Internet of Things ProjectIoT common vulnerabilities and attack surfaces
Router PasswordsDefault login credential database sorted by manufacturer
Siliconpr0nA Wiki/Archive of all things IC reversing

Awesome Embedded and IoT Security / Websites / Blogs

RTL-SDR
/dev/ttyS0's Embedded Device Hacking
Exploiteers
Hackaday
jcjc's Hack The World
Quarkslab
wrong baud
Firmware Security
PenTestPartners
Attify
Patayu
GracefulSecurity - Hardware tag
Black Hills - Hardware Hacking tag

Awesome Embedded and IoT Security / Websites / Tutorials and Technical Background

Azeria LabMiscellaneous ARM related Tutorials
JTAG ExplainedA walkthrough covering UART and JTAG bypassing a protected login shell
Reverse Engineering Serial PortsDetailed tutorial about how to spot debug pads on a PCB
UART explainedAn in depth explanation of the UART protocol

Awesome Embedded and IoT Security / Websites / YouTube Channels

Flashback TeamA duo of hackers explaining their step by step approach to finding and exploiting vulnerabilities in embedded devices
StackSmashingReverse engineering and hardware hacking of embedded devices

Awesome Embedded and IoT Security / Conferences

Hardwear.io

Backlinks from these awesome lists:

More related projects: