Awesome Lists

awesome-embedded-and-iot-security

by fkie-cad

awesome listpushed almost 3 years ago

A curated list of awesome embedded and IoT security resources.

AI summary

IoT security toolkit

A curated collection of resources and tools for analyzing and securing embedded and IoT devices

stars
1.9K
forks
242
watching
66
awesome lists
5
entries
130
View on GitHub

Embed the badge

Show how many awesome lists link to your project. The count updates automatically.

Awesome Lists badge
Markdown
[![Awesome Lists Badge](https://awesome.facts.dev/shield/fkie-cad/awesome-embedded-and-iot-security/links.svg)](https://awesome.facts.dev/awesome/fkie-cad/awesome-embedded-and-iot-security)
HTML
<a href="https://awesome.facts.dev/awesome/fkie-cad/awesome-embedded-and-iot-security"><img src="https://awesome.facts.dev/shield/fkie-cad/awesome-embedded-and-iot-security/links.svg" alt="Awesome Lists Badge" /></a>
Image URL
https://awesome.facts.dev/shield/fkie-cad/awesome-embedded-and-iot-security/links.svg

What's in the list

130 links in 21 sections, with live GitHub stats.activeno commit in 2y

Software Tools / Analysis Frameworks

Software Tools / Analysis Frameworks / FACT - The Firmware Analysis and Comparison Tool

Software Tools / Analysis Frameworks

  • FwAnalyzer

    Analyze security of firmware based on customized rules. Intended as additional step in DevSecOps, similar to CI

  • HAL – The Hardware Analyzer

    A comprehensive reverse engineering and manipulation framework for gate-level netlists

  • HomePWN

    Swiss Army Knife for Pentesting of IoT Devices

  • IoTSecFuzz

    Framework for automatisation of IoT layers security analysis: hardware, software and communication

  • Killerbee

    Framework for Testing & Auditing ZigBee and IEEE 802.15.4 Networks

  • PRET

    Printer Exploitation Toolkit

  • Routersploit

    Framework dedicated to exploit embedded devices

Software Tools / Analysis Tools

  • Binwalk

    Searches a binary for "interesting" stuff, as well as extracts arbitrary files

  • cwe_checker

    Finds vulnerable patterns in binary executables - ELF support for x86, ARM, and MIPS, experimental bare-metal support

  • emba

    Analyze Linux-based firmware of embedded devices

  • Firmadyne

    Tries to emulate and pentest a firmware

  • Firmwalker

    Searches extracted firmware images for interesting files and information

  • Firmware Slap

    Discovering vulnerabilities in firmware through concolic analysis and function clustering

  • Ghidra

    Software Reverse Engineering suite; handles arbitrary binaries, if you provide CPU architecture and endianness of the binary

  • Radare2

    Software Reverse Engineering framework, also handles popular formats and arbitrary binaries, has an extensive command line toolset

  • Trommel

    Searches extracted firmware images for interesting files and information

Software Tools / Extraction Tools

  • FACT Extractor

    Detects container format automatically and executes the corresponding extraction tool

  • Firmware Mod Kit

    Extraction tools for several container formats

  • The SRecord package

    Collection of tools for manipulating EPROM files (can convert lots of binary formats)

Software Tools / Support Tools

  • JTAGenum

    Add JTAG capabilities to an Arduino

  • OpenOCD

    Free and Open On-Chip Debugging, In-System Programming and Boundary-Scan Testing

Software Tools / Misc Tools

  • Cotopaxi

    Set of tools for security testing of Internet of Things devices using specific network IoT protocols

  • dumpflash

    Low-level NAND Flash dump and parsing utility

  • flashrom

    Tool for detecting, reading, writing, verifying and erasing flash chips

  • Samsung Firmware Magic

    Decrypt Samsung SSD firmware updates

Hardware Tools

  • Bus Blaster

    Detects and interacts with hardware debug ports like and

  • Bus Pirate

    Detects and interacts with hardware debug ports like UART and JTAG

  • Shikra

    Detects and interacts with hardware debug ports like UART and JTAG. Among other protocols

  • JTAGULATOR

    Detects JTAG Pinouts fast

  • Saleae

    Easy to use Logic Analyzer that support many protocols

  • Ikalogic

    Alternative to Saleae logic analyzers

  • HydraBus

    Open source multi-tool hardware similar to the BusPirate but with NFC capabilities

  • ChipWhisperer

    Detects Glitch/Side-channel attacks

  • Glasgow

    Tool for exploring and debugging different digital interfaces

  • J-Link

    J-Link offers USB powered JTAG debug probes for multiple different CPU cores

Hardware Tools / Bluetooth BLE Tools

Hardware Tools / ZigBee Tools

  • ApiMote

    ZigBee security research hardware for learning about and evaluating the security of IEEE 802.15.4/ZigBee systems. Killerbee compatible

  • Freakduino

    Low Cost Battery Operated Wireless Arduino Board that can be turned into a IEEE 802.15.4 protocol sniffer

Hardware Tools / SDR Tools

  • RTL-SDR

    Cheapest SDR for beginners. It is a computer based radio scanner for receiving live radio signals frequencies from 500 kHz up to 1.75 GHz

  • HackRF One

    Software Defined Radio peripheral capable of transmission or reception of radio signals from 1 MHz to 6 GHz (half-duplex)

  • YardStick One

    Half-duplex sub-1 GHz wireless transceiver

  • LimeSDR

    Software Defined Radio peripheral capable of transmission or reception of radio signals from 100 KHz to 3.8 GHz (full-duplex)

  • BladeRF 2.0

    Software Defined Radio peripheral capable of transmission or reception of radio signals from 47 MHz to 6 GHz (full-duplex)

  • USRP B Series

    Software Defined Radio peripheral capable of transmission or reception of radio signals from 70 MHz to 6 GHz (full-duplex)

Hardware Tools / RFID NFC Tools

  • Proxmark 3 RDV4

    Powerful general purpose RFID tool. From Low Frequency (125kHz) to High Frequency (13.56MHz) tags

  • ChamaleonMini

    Programmable, portable tool for NFC security analysis

  • HydraNFC

    Powerful 13.56MHz RFID / NFC platform. Read / write / crack / sniff / emulate

Books

Research Papers

Case Studies

Free Training

Websites

Websites / Blogs

Websites / Tutorials and Technical Background

Websites / YouTube Channels

  • Flashback Team

    A duo of hackers explaining their step by step approach to finding and exploiting vulnerabilities in embedded devices

  • StackSmashing

    Reverse engineering and hardware hacking of embedded devices

Conferences

More related projects

Add a GitHub project

Missing a project or an awesome list? Paste its GitHub URL and we fetch it right away.