Awesome Connected Things Sec
A Curated list of Security Resources for all connected things
IoT Hardware GuideIntro to Hardware Hacking - Dumping Your First FirmwareAn Introduction to Hardware HackingHardware Toolkits for IoT Security AnalysisHardware Hacking for IoT Devices - Offensive IoT ExploitationIdentifying UART InterfaceAn in depth explanation of the UART protocol.
Serial Terminal BasicsReverse Engineering Serial PortsIntro to Embedded RE: UART Discovery and Firmware Extraction via UBootUsing UART to Connect to a Chinese IP CamA Journey into IoT Hardware Hacking: UARTAccessing and Dumping Firmware Through UARTUART Connections and Dynamic Analysis on Linksys e1000Hardware Hacking 101: Introduction to JTAGHow to Find the JTAG InterfaceAnalyzing JTAGBus Pirate JTAG Connections with OpenOCDExtracting Firmware from External Memory via JTAGThe Hitchhacker's Guide to iPhone Lightning and JTAG HackingDebugging AVR Microcontrollers Through JTAGSWD Protocol Overview - HardBreak WikiUnveiling Vulnerabilities: Exploring SWD Attack Surface in HardwareIntroduction to ARM Serial Wire Debug ProtocolSerial Wire Debug and CoreSight ArchitectureLibSWD - Serial Wire Debug Open LibraryHardware Hacking and Exploitation Bootcamp - SWDHardware Hacking 101: Identifying and Dumping eMMC FlashDumping Firmware from Router Using Bus Pirate - SPIExtracting Flash Memory over SPIExtracting Firmware from Embedded Devices (SPI NOR Flash)How to Flash Chip of a Router with a ProgrammerTPM 2.0: Extracting Bitlocker Keys Through SPIIoT Security Part 16: Hardware Attack Surface I2CI2C Exploitation - HackTricksNon-invasive I2C Hardware Trojan Attack Vector (PDF)Hardware Hacking: I2C Injection with Bus PirateSafeguarding SPI, I2C, and I3C ProtocolsIntroduction to TPM (Trusted Platform Module)Trusted Platform Module Security Defeated in 30 MinuteseMMC ProtocolRPMB: A Secret Place Inside the eMMCeMMC Data Recovery from Damaged SmartphoneUnleash Your Smart-Home Devices: Vacuum Cleaning Robot HackingHands-On IoT Hacking: Rapid7 at DEF CON 30Side Channel Attacks - Yifan LuAttacks on Implementations of Secure SystemsFuzzing, Binary Analysis, IoT Security CollectionNAND Glitching Attack on Wink HubVoltage Glitching with Crowbars TutorialVoltage Glitching Attack using iCEstick GlitcherFPGA Glitching and Side Channel Attacks - Samy KamkarHardware Power Glitch Attack - rhme2Keys in Flash - Glitching AES Keys from ArduinoImplementing Practical Electrical Glitching AttacksHow to Voltage Fault InjectionGlitcher Part 1 - Reproducible Voltage Glitching on STM32 MicrocontrollersSTM32L05 Voltage GlitchingBreaking AES with ChipWhispererChipWhisperer WikiRowhammer Bit Flips to Steal Crypto KeysDumping the Amlogic A113X BootromRetreading The AMLogic A113X TrustZone Exploit ProcessReverse Engineering an Unknown MicrocontrollerHacking Microcontroller Firmware Through a USBThere's A Hole In Your SoC: Glitching The MediaTek BootROMA Practical Tutorial on PCIe for Total Beginners on Windows - Part 1A Practical Tutorial on PCIe for Total Beginners on Windows - Part 2PCIe DMA Attack against a Secured Jetson Nano (CVE-2022-21819)Complete Course in Software Defined Radio - Michael OssmannUnderstanding RadioIntroduction to Software Defined RadioIntroduction to GNU Radio CompanionCreating a Flow Graph in GNU Radio CompanionAnalyzing Radio Signals 433MHzRecording Specific Radio SignalsReplay Attacks with Raspberry Pi and rpitxReverse Engineering a Car Key Fob SignalGRCON 2021 - Capture the SignalAwesome Bluetooth SecurityTraffic Engineering in a Bluetooth PiconetBLE Characteristics: A Beginner's TutorialIntro to Bluetooth Low Energy (PDF)Bluetooth LE Security Study GuideReverse Engineering BLE DevicesMy Journey Towards Reverse Engineering a Smart Band - Bluetooth-LE REIntel Edison as Bluetooth LE Exploit BoxReverse Engineering and Exploiting a Smart MassagerI Hacked MiBand 3GATTacking Bluetooth Smart DevicesExamining the August Smart LockPractical Introduction to BLE GATT Reverse EngineeringMojoBox - Yet Another Not So SmartlockBluetooth SmartlocksBluetooth Beacon VulnerabilityDenial of Pleasure: Attacking Unusual BLE Targets with a Flipper ZeroGrand Theft Auto: A peek of BLE relay attackHow I Hacked Smart Lights: CVE-2022-47758Finding Bugs in BluetoothSweyntooth VulnerabilitiesBrakTooth: Causing Havoc on Bluetooth Link ManagerBLUFFS: Bluetooth Forward and Future Secrecy Attacks (CVE-2023-24023)AirDrop Leak - Sniffing BLE Traffic from Apple DevicesBleedingTooth: Linux Bluetooth Zero-Click Remote Code ExecutionBRAKTOOTH: Causing Havoc on Bluetooth Link Manager (PDF)Norec Attack: Stripping BLE encryption from Nordic's Library (CVE-2020-15509)BlueDucky - HID Injection on Unpatched Android (CVE-2023-45866)Microsoft Bluetooth Driver Spoofing - CVE-2024-21306Bluetooth Auracast / LE Audio Security AnalysisBlue2thprinting: WTF Am I Even Looking At?Open Wounds: Last 5 Years Have Left Bluetooth to BleedSniffing Bluetooth Through My Mask During the PandemicBluing - Intelligence Gathering for BluetoothBlueToolkit - Bluetooth Classic Vulnerability Testingbtproxyhcitool and bluezTesting with GATT Toolcrackle - Cracking BLE EncryptionCrack and decrypt BLE encryption.
bettercapThe Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.
GATTackerBTLEjack - BLE Swiss Army KnifeBased on the micro:bit, it provides everything you need to sniff, jam and hijack Bluetooth Low Energy devices.
DEDSEC Bluetooth ExploitBrakTooth ESP32 PoCSweynTooth BLE AttacksESP32 Bluetooth Classic SnifferBluetooth Hacking CollectionnRF52840 DongleUbertooth OneCSR 4.0 Bluetooth DongleESP32Sena UD100ESP-WROVER-KITice9-bluetooth-snifferInternalBlue - Bluetooth Experimentation FrameworkBluetooth experimentation framework based on the Reverse Engineering of Broadcom Bluetooth Controllers
Hacking Bluetooth to Brew Coffee from GitHub Actions - Part 1Hacking Bluetooth to Brew Coffee from GitHub Actions - Part 2Hacking Bluetooth to Brew Coffee from GitHub Actions - Part 3Introduction and Protocol OverviewZigBee and Z-Wave Security BriefHacking ZigBee NetworksHacking IoT Devices with Attify Zigbee FrameworkZigator: Analyzing Security of Zigbee-Enabled Smart HomesSecurity Analysis of Zigbee with Zigator and GNU RadioLow-Cost ZigBee Selective JammingKillerbeeFramework for Testing & Auditing ZigBee and IEEE 802.15.4 Networks.
ZigDiggityZigatorZ3seczigbearApiMoteRaspBeeATUSB IEEE 802.15.4 AdapterUSRPLoRaWAN Security Overview - TektelicSecurity Vulnerabilities in LoRaWANLow Powered and High Risk: Attacks on LoRaWAN DevicesLAF - LoRaWAN Auditing FrameworkChirpOTLE - LoRaWAN Security FrameworkLoRaWAN Security Survey - ScienceDirectLoRaWAN - WikipediaMillions of Devices Using LoRaWAN Exposed - SecurityWeekDo You Blindly Trust LoRaWAN Networks? - IOActiveLoRaWAN Encryption Keys Easy to Crack - ThreatpostLoPT: LoRa Penetration Testing Tool (PDF)LoRa Craft - Packet InterceptionOpen Source LoRaWAN Hacking ToolLoRaWAN Hackaday ProjectsMatter Standard - CSA-IoTMatter Protocol WikipediaMatter Protocol Complete Guide 2025How to Secure Smart Home Devices with MatterSmart Home Device Solutions for Matter - DigiCertSecurity Vulnerabilities and Attack Scenarios in Smart Home with MatterTrust Matters: Uncovering Vulnerabilities in Matter Protocol - NozomiMatter over Thread SecurityState-of-the-Art Review on IoT Wireless PAN Protocol SecurityMatter Smart Home - KrasamoThreadbare: Practical Attacks on Thread Networks (Black Hat USA 2024)Matter Specification 1.3 - Connectivity Standards AllianceThread Group Security AnalysisAwesome Cellular HackingIntroduction to GSM SecurityBreaking LTE on Layer Two5Ghoul - 5G NR Attacks and FuzzingExploiting CSN.1 Bugs in MediaTek BasebandsSIM HijackingSigPloit - Telecom Signaling Exploitation FrameworkSignaling security testing framework dedicated to telecom security for researching vulnerabilites in the signaling…
LTE Sniffer5G NR Jamming, Spoofing and SniffingLTrack: Stealthy Tracking of Mobile Phones in LTEOpen5GS - Open Source 5G/4G CoreOpen5GS is a C-language Open Source implementation for 5G Core and EPC, i.e. the core network of LTE/NR network…
SCAT - Signaling Collection and Analysis Tool for CellularGSM Security Part 2What is Base Transceiver StationIntroduction to SS7 SignalingSS7 Network ArchitectureIntroduction to SIGTRANHow to Build Your Own Rogue GSM BTSGSM Vulnerabilities with USRP B200Security Testing 4G (LTE) NetworksCase Study of SS7/SIGTRAN Assessmentss7MAPer - SS7 Pentesting ToolkitFake BTS Detector (SCL-8521)Awesome RFID/NFC Security TalksRFID Discord GroupSoK: Security of EMV Contactless Payment SystemsNFC Relay Attack on Tesla Model YReal Time Interception of DECT Cordless TelephoneEavesdropping on Unencrypted DECT Voice TrafficDecoding DECT Voice Traffic: In-depth ExplanationFraming Frames: Bypassing Wi-Fi Encryption by Manipulating Transmit QueuesMan-in-the-Middle Attacks without Rogue AP: When WPAs Meet ICMP RedirectsWPAxFuzz: Sniffing Out Vulnerabilities in Wi-Fi ImplementationsUntangling the Knot: Breaking Access Control in Home Wireless Mesh NetworksOver The Air: Exploiting Broadcom's Wi-Fi Stack (Part 1)Over The Air: Exploiting Broadcom's Wi-Fi Stack (Part 2)Over The Air: Exploiting The Wi-Fi Stack on Apple DevicesReverse-engineering Broadcom wireless chipsetsExploiting Qualcomm WLAN and Modem Over the AirWindows Wi-Fi Driver RCE Vulnerability - CVE-2024-30078When a Wi-Fi SSID Gives You Root on an MT02 Repeater - Part 1When a Wi-Fi SSID Gives You Root on an MT02 Repeater - Part 2Reverse Engineering WiFi on RISC-V BL602Unveiling secrets of the ESP32: creating an open-source MAC LayerUnveiling secrets of the ESP32: reverse engineering RXALL ABOUT USB-C: INTRODUCTION FOR HACKERSHi, My Name is KeyboardHow to Weaponize the YubikeyUWB Real Time Locating Systems: How Secure Radio Communications May Fail in PracticeAll cops are broadcasting: TETRA under scrutinyTETRA:BURST - Five Vulnerabilities in TETRA Standard (Midnight Blue)TETRA:BURST 2:ELECTRIC BOOGALOO - End-to-End Encryption Broken (BlackHat USA 2025)TETRA Decoder - Open Source TETRA ReceiverPractical TETRA Sniffing with SDRIntroduction to Firmware Analysis - OWASPOWASP Firmware Security Testing MethodologyIoT Security Verification Standard (ISVS)Reversing 101by Kevin Thomas
Hands-on Firmware Extraction, Exploration, and EmulationRouter Analysis Part 1: UART Discovery and SPI Flash ExtractionHardware Hacking Tutorial: Dumping and Reversing FirmwareFirmware Samples - firmware.centerBasicFUN Series: Hardware Analysis / SPI Flash ExtractionBasicFUN Series: Reverse Engineering Firmware / Reflashing SPI FlashRetrofitting encrypted firmware is a Bad IdeaEMBA - Embedded Linux Firmware AnalyzerFACT - Firmware Analysis and Comparison ToolBinwalk v3Binwalk is a fast, easy to use tool for analyzing, reverse engineering, and extracting firmware images.
FirmwalkerSearches extracted firmware images for interesting files and information.
fwanalyzerAnalyze security of firmware based on customized rules. Intended as additional step in DevSecOps, similar to CI.
fwhunt-scan - UEFI Firmware AnalysisByteSweepBINSECunblob - Extraction FrameworkChecksec.shbash script to check the properties of executables (like PIE, RELRO, PaX, Canaries, ASLR, Fortify Source)
Firmware Modification KitFirmadyne - Automated Firmware EmulationTries to emulate and pentest a firmware.
FirmAE - Firmware Analysis and EmulationQEMUis a fast processor emulator using a portable dynamic translator. QEMU emulates a full system, including a processor…
PANDA - Architecture-Neutral Dynamic Analysis[Platform for Architecture-Neutral Dynamic Analysis]
Avatar2 - Dynamic Firmware AnalysisRenode - Embedded Systems Emulatora virtual development tool for multinode embedded networks.
Unicorn Engine - CPU EmulatorUnicorn CPU emulator framework (ARM, AArch64, M68K, Mips, Sparc, PowerPC, RiscV, S390x, TriCore, X86)
Qiling FrameworkHALucinatorFirmWire - Baseband Firmware EmulationSymQEMUS2E - Selective Symbolic ExecutionBochs - x86 EmulatorSAME70 EmulatorEmulate Until You Make itFirmware Emulation with QEMUEmulating ARM Router Firmware - Azeria LabsEmulating IoT Firmware Made EasyIoT Binary Analysis and Emulation Part 1Cross Debugging for ARM/MIPS with QEMUQEMU + Buildroot 101Simulating and Hunting Firmware Vulnerabilities with QilingQiling and Binary Emulation for Automatic UnpackingDebugging D-Link: Emulating Firmware and Hacking HardwareAdaptive Emulation Framework for Multi-Architecture IoTAutomatic Firmware Emulation through Invalidity-guided Knowledge InferenceEmulating RH850 architecture with Unicorn EngineIcicle: A Re-designed Emulator for Grey-Box Firmware FuzzingChallenges and Pitfalls while Emulating Six Current Icelandic Household RoutersMy Emulation Goes to the Moon... Until False FlagHow to Emulate Android Native Libraries Using QilingIoT Firmware Security and Update MechanismsImplementing OTA Updates for IoT DevicesSecure OTA Boot Chains and Firmware VerificationThe Key to Firmware Security in Connected IoT DevicesSecurity Considerations for OTA Updates - Stack OverflowTop 10 IoT Vulnerabilities - OTA Update AttacksUpdating IoT Devices 2025: Best PracticesReview of IoT Firmware Vulnerabilities and Auditing TechniquesZephyr RTOS GitHubPrimary Git Repository for the Zephyr Project. Zephyr is a new generation, scalable, optimized, secure RTOS for…
Zephyr Vulnerabilities ListNCC Group Zephyr and MCUboot Security Assessment26 Flaws in Zephyr and MCUbootTackling Security in Zephyr RTOSEnhancing Security with Zephyr RTOSFreeRTOS 13 Vulnerabilities in TCP/IP StackExploiting Memory Corruption in FreeRTOS - ShmooConRTOS Security Analysis - USENIXDynamic Vulnerability Patching for RTOSAWS FreeRTOS VulnerabilitiesGhidraA software reverse engineering (SRE) framework created and maintained by the National Security Agency Research…
IDA ProProprietary multi-processor disassembler and debugger for Windows, GNU/Linux, or macOS; also has a free version, IDA…
Radare2Cutter - GUI for Radare2Free and Open Source Reverse Engineering Platform powered by rizin.
Binary NinjaA reversing engineering platform that is an alternative to IDA.
GDBGNU Project debugger. GPL-3.0-or-later
RetDec - DecompilerRetDec is a retargetable machine-code decompiler based on LLVM.
Diaphora - Binary Diffing[diff]
Angr - Binary AnalysisPlatform-agnostic binary analysis framework developed at UCSB's Seclab.
Frida - Dynamic InstrumentationDynamic instrumentation toolkit for developers, reverse-engineers, and security researchers.
Ret-syncret-sync is a set of plugins that helps to synchronize a debugging session (WinDbg/GDB/LLDB/OllyDbg2/x64dbg) with…
OllyDbgx86 debugger for Windows binaries that emphasizes binary code analysis.
x64dbgAn open-source x64/x32 debugger for windows.
Hoppercopyright: — macOS and Linux reverse engineering tool that lets you disassemble, decompile and debug applications.…
Immunity DebuggerPEiDGhidriff - Ghidra Binary Diffing Engine[Python Command-Line Ghidra Binary Diffing Engine]
The rev.ng decompiler goes open sourceIntro to Cutterpyghidra-mcp: Headless Ghidra MCP ServerMindshare: Using Binary Ninja API to Detect Potential Use-after-free VulnerabilitiesReverse Engineering and Patching with GhidraReverse Engineering with Ghidra: Breaking Firmware EncryptionReversing Firmware with RadareReversing ESP8266 FirmwareAutomating Binary Vulnerability Discovery with Ghidra and SemgrepFinding Bugs in Netgear RouterGhidra 101: Cursor Text HighlightingGhidra 101: Decoding Stack StringsExtending Ghidra Part 1: Setting up a Development EnvironmentExpanding the Dragon: Adding an ISA to GhidraGhidra nanoMIPS ISA moduleBinary type inference in GhidraWriting a Ghidra processor moduleAZM Online ARM Assembler - Azeria LabsOnline DisassemblerCompiler ExplorerRun GNAT FSF compilers interactively from your web browser and interact with the assembly.
Azeria Labs ARM TutorialsMiscellaneous ARM related Tutorials.
ARM Exploitation for IoTDamn Vulnerable ARM Router (DVAR)Exploit EducationA Guide to ARM64 / AArch64 Assembly on LinuxARMv8 AArch64/ARM64 Full Beginner's Assembly TutorialA Noobs Guide to ARM ExploitationARM64 Reversing And Exploitation Series (8ksec) - Parts 1-10AArch64 memory and pagingWe are ARMed no more ROPpery HerePractical Binary AnalysisWriting a BootloaderPwn the ESP32 Secure BootPwn ESP32 Forever: Flash Encryption and Secure Boot Keys ExtractionESP32 Secure Boot Bypass (CVE-2020-13629)Amlogic S905 SoC: Bypassing Secure BootDefeating Secure Boot with Symlink AttacksPS4 Secure Boot Hacking - Fail0verflowDell BIOS Vulnerabilities - BIOSDisconnectU-Boot USB DFU Vulnerability (CVE-2022-2347)Breaking Secure Boot on Silicon Labs GeckoUsing Symbolic Execution to Detect UEFI VulnerabilitiesHP Enterprise UEFI VulnerabilitiesEmulating and Exploiting UEFI FirmwareThe Dark Side of UEFI: A technical Deep-Dive into Cross-Silicon ExploitationInside the LogoFAIL PoC: From Integer Overflow to Arbitrary Code ExecutionPixieFail: Nine vulnerabilities in Tianocore's EDK II IPv6 network stackFor Science! - Using an Unimpressive Bug in EDK IIHydroph0bia: SecureBoot bypass for Insyde H2OPKfail: Untrusted Platform Keys in UEFI Firmware (Binarly, 2024)LogoFAIL: Image Parsing Vulnerabilities in System Firmware (Binarly)BlackLotus UEFI Bootkit Analysis - ESETBootkitty: First UEFI Bootkit for Linux (ESET, 2024)Threadbare: Practical Attacks on Thread Networks (Black Hat USA 2024)CVE-2024-0762 - PixieFail Followup TPM BypassZip Slip VulnerabilityA Journey into IoT: Discover Components and PortsA Journey into IoT: Firmware Dump and AnalysisA Journey into IoT: Radio CommunicationsA Journey into IoT: Internal CommunicationsDynamic Analysis of Firmware Components in IoT DevicesRV130X Firmware AnalysisTP-Link Firmware Decryption C210 V2 cloud camera bootloadersHunting for Unauthenticated n-days in Asus RoutersPulling MikroTik into the LimelightExploiting MikroTik RouterOS Hardware with CVE-2023-30799Rooting Xiaomi WiFi RoutersRoute to Safety: Navigating Router PitfallsROPing our way to RCEROPing Routers from scratch: Tenda Ac8v4PwnAgent: A One-Click WAN-side RCE in Netgear RAX RoutersPuckungfu 2: Another NETGEAR WAN Command InjectionReversing, Discovering, And Exploiting A TP-Link Router Vulnerability - CVE-2024-54887Exploiting Zero-Day (CVE-2025-9961) Vulnerability in the TP-Link AX10 RouterFiberGateway GR241AG - Full Exploit ChainBlackbox-Fuzzing of IoT Devices Using the Router TL-WR902ACRooting the TP-Link Tapo C200 Rev.5Netgear Orbi: Introduction, UART Access, ReconNetgear Orbi: Crashes in SOAP-APINetgear Orbi: NDay Exploit CVE-2020-27861The Last Breath of Our Netgear RAX30 BugsTP-Link TDDP Buffer Overflow VulnerabilityPwn2Own Tokyo 2020: Defeating the TP-Link AC1750TP-Link Tapo c200 Camera Unauthenticated RCE (CVE-2021-4045)Patch Diffing a Cisco RV110W Firmware Update - Part 1CVE-2024-20356: Jailbreaking a Cisco appliance to run DOOMFlashback Connects - Cisco RV340 SSL VPN RCEBypassing Secure Boot using Fault InjectionBreaking Secure Boot on Google Nest Hub (2nd Gen)Booting into Breaches: Hunting Windows SecureBoot's Remote Attack SurfacesIntroduction to MQTTMQTT Broker Security 101Hacking the IoT with MQTTIoT Security: RCE in MQTT ProtocolIoXY - MQTT Intercepting ProxyMQTT-PWNUnderstanding the MQTT Protocol Packet StructureAre Smart Homes Vulnerable to Hacking?Penetration Testing Sesame Smart Door LockServisnet Tessa - MQTT Credentials Dump (Metasploit)Eclipse Mosquitto Unquoted Service PathCVE-2020-13849DoS vulnerability (CVSS 7.5)
CVE-2023-3028Insufficient authentication (CVSS 9.8)
CVE-2021-0229Resource consumption (CVSS 5.3)
CVE-2019-5432Malformed packet crash (CVSS 7.5)
Mosquitto - Open Source MQTT Broker"The" Open Source MQTT Broker.
HiveMQJava MQTT Broker that supports MQTT 3.1, 3.1.1 and 5.0. Commercial and open source editions available.
MQTT ExplorerTool to visualize your MQTT topics in a topic hierarchy, a MQTT swiss-army knife.
MQTT Topic ACL LinterLocal-only static analysis for invalid, broad, duplicate, and overlapping MQTT topic-filter ACL rules; does not…
Nmap MQTT LibrarySeven Best MQTT Client ToolsUsing IoT MQTT for V2V and Connected CarsMQTT Hardware Development Projects100,000 Connected Cars with Kubernetes, Kafka, MQTT, TensorFlowAuthenticating Devices Using MQTT with Auth0Deep Learning UDF for MQTT IoT Anomaly DetectionGuide to MQTT: Hacking a DoorbellWailingCrab Malware Using MQTT for C2Alert: New WailingCrab Malware LoaderMQTT on SnapcraftIETF Security Protocol ComparisonRFC 8613 - OSCORERadware - CoAP Protocol OverviewEMQX on CoAP and IoT Security (2024)RFC 8323 - CoAP over TCPRFC 8824 - SCHC Header CompressionCoAP NSE (Nmap)Copper4Cr - CoAP User-Agent for Chromelibcoap CLI ToolsC implementation of a lightweight application-protocol for devices that are constrained their resources such as…
Scapy CoAP PluginPython-based interactive packet manipulation program & library. Supports CAN/ISOTP/UDS/GMLAN plus many other protocols.
Eclipse Californium (Java)Peach FuzzerRaspberry Pi / Arduino + 6LoWPANContiki-NG: The OS for Next Generation IoT Devices
ZolertiaOpenMoteNordic BoardsOfficial Website
SpectralOps - Top IoT Protocol Security IssuesCoAP Exposure Study (2024)mTLS: When Certificate Authentication is Done WrongmTLS Authentication in IoT: Enhancing Security for Connected DevicesHands On IoT MitM Part 1 - AWS IoT MQTT + mTLS InterceptionOWASP MASTG-TECH-0012: Bypassing Certificate Pinning in Android IoT Companion AppsTheory to Practice: mTLS in Action Part 1Configuring mTLS on Mosquitto MQTT BrokerAWS IoT Docs: X.509 Client Certificates and Fleet ProvisioningAzure IoT Hub: mTLS X.509 CA Authentication ConceptEvaluation of TLS and mTLS in Internet of Things Systems - MIUN DiVA, 2024Atlas: Enabling Cross-Vendor mTLS Authentication for IoT - arXiv 2025Lightweight mTLS Authentication for Industrial IoT - PMC/NIH 2023Quantum-Enhanced mTLS for IoT Battlefield Networks - IJPSATAI vs. IoT Security: Fingerprinting and Defenses Against TLS Attacks - IEEE Xplore 2025Intercepting IoT Device Traffic with ARP Poisoning + mitmproxy TLS InterceptUsing Linux to Intercept IoT Device Traffic with mitmrouterMutual TLS - The Backend Engineering Show Deep DiveIntercepting SSL/TLS - Fiddler and MITMProxy Decrypt WalkthroughDecrypting Kubernetes mTLS Traffic - eCapture, Custom CA, eBPF MethodsMastering mTLS: Stop MITM Attacks and Boost API/IoT SecurityIntroduction to IoT Penetration Testing Webinar - CyberWarFare LabsIoT Protocols OverviewIoT ArchitectureAttacking IoT Devices from Web PerspectiveAwesome Industrial ProtocolsAWS Penetration Testing PolicyAWS Pentesting Guide - HackerOneA few notes on AWS Nitro EnclavesComprehensive AWS Pentesting Guide - BreachLockAWS Pentest Methodology - MorattiSecAWS Penetration Testing Methodology - RootshellAWS Penetration Testing Techniques 2025CloudFox - Cloud Attack PathsAutomating situational awareness for cloud penetration tests
S3Scanner - Leaky Bucket DiscoveryScan for misconfigured S3 buckets across S3-compatible APIs!
Cloudfoxable LabsAWS Security Pentesting ResourcesPacu - AWS Exploitation FrameworkThe AWS exploitation framework, designed for testing the security of Amazon Web Services environments. By…
ScoutSuite - Multi-cloud Security AuditingOpen source multi-cloud security-auditing tool, which enables security posture assessment of cloud environments.
Prowler - Cloud Security AssessmentProwler is the world’s most widely used open-source cloud security platform that automates security and compliance…
7 Best AWS Pentesting Tools 2026PayloadsAllTheThings - AWS PentestAn API key is a unique identifier that is used to authenticate requests associated with your project. Some developers…
Firebase Security Rules TestingMisconfigured Firebase DatabasesAndroid App Reverse Engineering 101Android Application Pentesting BookAndroid Pentest Video Course - TutorialsPointAndroid TamerAndroid Hacker's HandbookA first look at Android 14 forensicsDeobfuscating Android ARM64 strings with GhidraIntroduction to Fuzzing Android Native ComponentsHacking Android GamesIntercepting HTTPS Communication in FlutterAndroid Kernel ExploitationAttacking Android Binder: Analysis and Exploitation of CVE-2023-20938Attacking the Android kernel using the Qualcomm TrustZoneDriving forward in Android driversAnalyzing a Modern In-the-wild Android ExploitExploiting Android's Hardened Memory AllocatorGPUAF - Two ways of Rooting All Qualcomm based Android phonesThe Qualcomm DSP Driver - Unexpectedly Excavating an ExploitQualcomm DSP Kernel InternalsBinder FuzzingAndroid: ScudoBehind the Shield: Unmasking Scudo's Defensesscudo Hardened Allocator - Unofficial Internals DocumentationiOS Pentesting GuideOWASP Mobile Security Testing GuideAn iOS hacker tries AndroidAnalyzing iOS Kernel Panic LogsBlasting Past iOS 18Emulating an iPhone in QEMUFirst analysis of Apple's USB Restricted Mode bypass (CVE-2025-24200)Exploring UNIX pipes for iOS kernel exploit primitivesICS VillageICS Discord GroupControlthings.io PlatformApplied Cyber Security and the Smart GridDeep Lateral Movement in OT NetworksHacking ICS Historians: The Pivot Point from IT to OTOPC UA Deep Dive Series - Parts 1-5Inside a New OT/IoT Cyberweapon: IOCONTROLAttention, High Voltage: Exploring the Attack Surface of the Rockwell Automation PowerMonitor 1000Awesome Vehicle SecurityBooks, hardware, software, applications, car hacking and more.
Car Hacking VillageJeep HackSubaru Head Unit JailbreakCar Hacking Practical Guide 101CAN Injection: keyless car theftHow I Hacked my Car Series - Parts 1-6How I Also Hacked my CarExtracting Secure Onboard Communication (SecOC) keys from a 2021 Toyota RAV4 PrimeRecovering an ECU firmware using disassembler and branchesAutomotive Memory Protection Units: Uncovering Hidden VulnerabilitiesWeb Hackers vs The Auto Industry: Critical Vulnerabilities in Cars (Sam Curry, 2023)Hacking Kia: Remotely Controlling Cars With Just a License Plate (Sam Curry, 2024)Hacking Subaru: Tracking and Controlling Cars via the STARLINK Admin Panel (Sam Curry, 2025)Pwn2Own Automotive (ZDI Blog Category - 2024 & 2025 Tokyo)Synacktiv Publications - Pwn2Own Automotive WriteupsAwesome CAN Bus - Curated ResourcesA curated list of awesome CAN bus tools, hardware and resources.
A Detailed Look at Pwn2own Automotive EV Charger HardwarePwn2Own Automotive 2024: Hacking the ChargePoint Home FlexReverse engineering an EV chargerPwn2Own Automotive 2024: Autel MaxiCharger Analysis (Computest Sector7)SaiFlow Blog - OCPP/EV Charging Protocol VulnerabilitiesIntroduction to ATM Penetration TestingPwning ATMs for Fun and ProfitJackpotting ATMs Redux - Barnaby JackRoot Shell on Credit Card TerminalPayment VillageBus PirateBus Pirate 5: The Swiss ARRRmy Knife of Hardware HackingThe ShikraDetects and interacts with hardware debug ports like UART and JTAG. Among other protocols.
Attify BadgeFlipper ZeroHackRFA Software Defined Radio peripheral capable of transmission or reception of radio signals from 1 MHz to 6 GHz.…
RTL-SDRAn In-Depth Look at the ICE-V Wireless FPGA Development BoardLogic Analyzer - SaleaeEasy to use Logic Analyzer that support many protocols :euro:.
JTAGulatorEEPROM Reader/SOIC CableST-LinkSegger J-LinkFTDI-based AdaptersBlack Magic ProbeFaceDancer21RfCatNullSec Ducky PayloadsRubber Ducky BadUSB payload collection for Windows, macOS and Linux.
NullSec Flipper SuiteFlipper Zero payload collection for RF, RFID/NFC, BadUSB, infrared and wireless pentesting.
PineFlipFlipper Zero companion app for Linux with screen mirroring, file manager and firmware management.
Hak5 Field KitsNullSec Pineapple SuiteWiFi Pineapple payload collection for deauth, evil twin, handshake capture and network recon.
BlueSploitIoTSecFuzzFramework for automatisation of IoT layers security analysis: hardware, software and communication.
PENIOTISF - Industrial Security FrameworkHAL - Hardware AnalyzerA comprehensive reverse engineering and manipulation framework for gate-level netlists.
PRET - Printer Exploitation ToolkitTool for printer security testing capable of IP and USB connectivity, fuzzing, and exploitation of PostScript, PJL,…
Expliot FrameworkPentest framework like Metasploit but specialized for IoT.
RouterSploitFramework dedicated to exploit embedded devices.
HomePwnSwiss Army Knife for Pentesting of IoT Devices.
Firmware Analysis Toolkit (FAT)Shambles: The Next-Generation IoT Reverse Engineering ToolSamsung Firmware MagicDecrypt Samsung SSD firmware updates.
The art of Fuzzing: IntroductionA LibAFL Introductory WorkshopThe Blitz Tutorial Lab on Fuzzing with AFL++State of Linux Snapshot FuzzingFuzzing between the lines in popular barcode softwareBoofuzzFuzzing engine and fuzz testing framework.
Syzkaller - Kernel Fuzzer(2015) - An unsupervised coverage-guided kernel fuzzer supporting FreeBSD, Fuchsia, gVisor, Linux, NetBSD, OpenBSD,…
parking-game-fuzzerOWASP Fuzzing InfoFuzz Testing of Application ReliabilityFuzzingPaper CollectionFuzzing ICS ProtocolsFuzzowski - Network Protocol FuzzerFIRM-AFL: High-Throughput IoT Firmware FuzzingSnipuzz: Black-box Fuzzing of IoT FirmwareFuzzing IoT Binaries Part 1Fuzzing IoT Binaries Part 2Awesome Embedded FuzzingAFL Training ExercisesFrankenstein - Broadcom/Cypress Firmware Emulation for FuzzingDr. MemoryMemory Debugger for Windows, Linux, Mac, and Android
AttifyOSGNU/Linux distribution focused on tools useful during Internet of Things (IoT) security assessments.
IoT Penetration Testing OS v1EmbedOSSigint OS - LTE IMSI CatcherInstant GNU Radio OSDragon OS - SDR SoftwareSkywave Linux - SDRZephyr RTOSLinux Foundation Projects RTOS aiming at beeing secure and safe.
Ubuntu LTSUbuntu is a Debian-based Linux distribution published by Canonical® who offer commercial support for enterprise-class…
ShodanShodan is a search engine that lets users search for various types of servers connected to the internet using a…
CensysCensys is a search engine that allows computer scientists to ask questions about the devices and networks that compose…
ZoomEyeZoomEye is a freemium online tool aimed to help aid cybersecurity in the areas of reconnaissance and threat evaluation.
BinaryEdgeThreat intelligence and attack surface analysis.
Thingfulis a Search Engine for the Internet of Things Find & use open IoT data from around the world.
WigleWi-fi "wardriving" database. Contains a global map containing crowdsourced information on the location, name, and…
Hunter.ioData broker providing a Web search interface for discovering the email addresses and other organizational details of a…
BuiltWithis a website that will help you find out all the technologies used to build a particular websites.
Recon-ngRecon-ng is a full-featured Web Reconnaissance framework written in Python. Recon-ng has a look and feel similar to…
PublicWWWFind any alphanumeric snippet, signature or keyword in the web pages HTML, JS and CSS code.
FCC ID Databaseseacrh by FCC ID, Country, Date, Company name or Frequency ( in Mhz)
CVE PoC SearchSearch public GitHub PoC repositories by CVE ID.
STRIDE Threat Model Guide - Practical DevSecOpsOWASP Threat Modeling ProcessSTRIDE-based Threat Modeling for IoT Precision AgricultureWhat is STRIDE in Threat Modeling - Security CompassThreat Modeling with ATT&CK - MITREWhat is Threat Modeling - FortinetSTRIDE Threat Modeling for IoT Smart HomeSTRIDE Threat Modeling for Smart Solar Energy SystemsSTRIDE Threat Modeling for IoT Healthcare SystemsSTRIDE for IoT Agriculture - IEEECompiler Options Hardening Guide for C and C++Linux Hardening GuideDocker Security - Step-by-Step Hardening(2023)
How To Secure A Linux ServerAn evolving how-to guide for securing a Linux server.
NIST IoT Cybersecurity FrameworkNIST SP 800-213 - IoT Device Cybersecurity GuidanceNISTIR 8259 - Foundational Cybersecurity Activities for IoT ManufacturersETSI EN 303 645 - Cyber Security for Consumer IoTOWASP IoT Top 10 (2018)OWASP IoT ProjectIoT common vulnerabilities and attack surfaces.
IoT Device Hardening Best PracticesEmbedded Linux HardeningZephyr RTOS Security FeaturesIoT Forensics and Incident ResponseEmbedded Device ForensicsOpenSecurityTraining2cryptopals.
Hardware Hacking CheatsheetNmap TutorialPentest Hardware HandbookTHC's favourite Tips, Tricks & HacksVarious tips & tricks
Cross Cache Attack CheetSheetOWASP IoT Top 10 2018 MappingReflecting on OWASP IoT Top 10CVE North StarsIoT Vulnerabilities with CVE and PoCLinux Privilege EscalationShodan Pentesting GuideModern Vulnerability Research on Embedded SystemsAwesome Embedded Systems Vulnerability ResearchJoe GrandLiveOverflowVideo tutorials on Exploitation.
Binary AdventureEEVBlogOne of the earliest and most successful YouTube channels where Dave Jones does teardowns, tutorials and more.
Craig SmithIoTSecurity101Besim ALTINOKGhidra NinjaCyber GibbonsScanlineAaron ChristophelValerio Di GiampietroGamozo Labs - Printer HackingThe Hardware Hacking Handbook - Jasper van Woudenberg & Colin O'Flynn (2021)Practical Hardware Pentesting - Jean-Georges Valle (2021)Practical Hardware Pentesting 2nd Edition (2023)Hardware Hacking: Have Fun While Voiding Your Warranty - Joe Grand (2004)Hacking the Xbox - Andrew "bunnie" Huang (2013)The Hardware Hacker - Andrew "bunnie" Huang (2019)The Art of PCB Reverse Engineering - Keng Tiong (2015)Manual PCB-RE: The Essentials - Keng Tiong (2021)Hardware Security Training, Hands-on! (2023)Hardware Security: Challenges and Solutions (2025)Mastering Hardware Hacking (2025)Ultimate Hardware Hacking Gear GuideMicrocontroller Exploits (2024)Engineering Secure Devices - Dominik Merli (2024)Cryptography and Embedded Systems Security - Hou & Breier (2024)The Firmware Handbook - Jack Ganssle (2004)Learning Linux Binary Analysis - Ryan O'Neill (2016)Fuzzing Against the Machine (2023)Rootkits and Bootkits - Matrosov, Rodionov, Bratus (2019)Ghidra Software Reverse Engineering 2nd Edition (2025)The Ghidra Book 2nd Edition - Nance & Eagle (2026)The Definitive Handbook on Reverse Engineering Tools (2025)x86 Software Reverse-Engineering, Cracking, and Counter-Measures - Domas & Domas (2024)Fuzzing Android - Zawawy, Rodionov et al. (2026)From Day Zero to Zero Day - Eugene Lim (2025)The Spacecraft Hacker's Handbook - Olchawa & Starcik (2026)Abusing the Internet of Things - Nitesh Dhanjani (2015)IoT Penetration Testing Cookbook - Aaron Guzman & Aditya Gupta (2017)Practical IoT Hacking: The Definitive Guide (2021)PatrIoT: Practical and Agile Threat Research for IoT (2022)The Embedded Linux Security Handbook - St. Onge & Krishnan (2025)Securing Smart Things - Massimo Nardone (2026)Inside Radio: An Attack and Defense Guide - Qing Yang, Lin Huang (2018)Hack the Airwaves: Advanced BLE Exploitation (2023)Practical SDR - David Clark & Paul Clark (2025)The Art of ARM Assembly, Volume 1 - Randall Hyde (2025)The Wireless Cookbook - Bill Zimmerman (2026)Linksys WRT54G Ultimate Hacking - Paul Asadoorian (2007)Near Field Communication (NFC): From Theory to Practice (2012)Security Issues in Mobile NFC Devices - Michael Roland (2024)The Car Hacker's Handbook - Craig Smith (2016)Building Secure Automotive IoT Applications - Oka et al. (2024)Offensive Automotive Cybersecurity - Nasser & Oka (2025)Gray Hat Hacking 5th Edition (2018)Black Hat Python 2nd Edition (2021)Attacking Network Protocols - James Forshaw (2017)A Hacker's Guide to Capture, Analysis, and Exploitation by James Forshaw.
Securing Industrial Control Systems - Rahman et al. (2026)IOActive: State of Silicon Chip Hacking 2025IoT Series I-IVIntro to Embedded RE SeriesDVID - Damn Vulnerable IoT DeviceDamn Vulnerable IoT Device
IoTGoat - Vulnerable OpenWrt FirmwareIoTGoat is a deliberately insecure firmware based on OpenWrt.
BLE CTFMicrocorruptionARM-X CTFHardware Hacking 101Workshop @ BSides Munich 2019.
Damn Vulnerable SafeSticky Fingers DV-PiDamn Vulnerable Chemical ProcessDamn Vulnerable SS7 NetworkHacklab VulnVoIPRHme Series (2015-2017)First riscure Hack me hardware CTF challenge.
IoT Village CTFRHme-2016Riscure Hack me 2 is a low level hardware CTF challenge.
RHme-2017Riscure Hack Me 3 embedded hardware CTF 2017-2018.
Emulate to ExploitateAzeria Labs ARM ChallengesHack The BoxAn online platform to test and advance your skills in penetration testing and cyber security. Join today and start…
Root MeHundreds of challenges are available to train yourself in different and not simulated environments
Pwnable.krCTFtimeDirectory of upcoming and archive of past Capture The Flag (CTF) competitions with links to challenge writeups.
Webthings Gateway - Raspberry PiDropcam HackingLED Light HackingPS4 Jailbreak StatusLenovo Watch X Privacy IssuesSmart Scale Privacy IssuesBesder IP Camera Security AnalysisTeam82 ResearchVoidstarsecwrongbaudFirmware AnalysisExploitee.rsPayatu BlogRaelize BlogJCJC DevW00tsecDevttys0Embedded BitsKeenlabCourk.ccIoT Security WikiCybergibbonsFirmware.REK3170makanTclaverieBesimaltinokCtrluIoT PentestDuo DecipherSp3ctr30x42424242DantheiotmanDanmanQuentinkaiserQuarkslabIce9F-Secure LabsMG.lolCJHackerzBunnie's BlogSynacktiv PublicationsCr4.shKtln2NaehrdineLimited ResultsFail0verflowExploit SecurityAttify BlogJilles.comSyss Tech BlogHardBreak Wiki8ksecStarlabsboschko.ca0xtribouletNozomi NetworksIoTSecurity101 TelegramIoTSecurity101 RedditHardware Hacking TelegramRF HackersJillesJoe FitzAseem JakharCybergibbonsJasperDave JonesbunnieIlya ShaposhnikovMark C.Aaron GuzmanYashin MehaboobeArun MageshMr-IoTQKaiser9lyphARLO: I'M WATCHING YOUHacking a Tapo TC60 CameraRooting a Hive CameraPwn2Own: Synology BC500 IP CameraTurning Camera Surveillance on its AxisPwn2Own Ireland 2024 - Ubiquiti AI BulletHacking a Smart Home DeviceThe Silent Spy Among Us: Smart Intercom AttacksPwnassistant - Home Assistant RCEHacking Sonoff Smart Home IoT DeviceTurning Google smart speakers into wiretaps for $100kSmart Speaker Shenanigans: Making the Sonos ONE Sing its SecretsListen Up: Sonos Over-The-Air Remote Kernel Exploitation and Covert WiretapStreaming Zero-Fi Shells to Your Smart SpeakerPwning a Brother labelmaker, for fun and interop!lexmark printer haxxPwn2Own Ireland 2024: Canon imageCLASS MF656CdwPrint Scan Hacks: Brother devicesDJI Mavic 3 Drone Research: Firmware AnalysisDJI Mavic 3 Drone Research: Vulnerability AnalysisDJI - The ART of obfuscationLocal Privilege Escalation on the DJI RM500 Smart ControllerLet Me Cook You a Vulnerability: Exploiting the Thermomix TM5A Pain in the NAS: Synology DS920+ EditionWeekend Destroyer - RCE in Western Digital PR4100 NASExploiting the Synology TC500 at Pwn2Own Ireland 2024Hacking the Nintendo DSi Browsermast1c0re: Exploiting the PS4 and PS5 through a game saveBeing Overlord on the Steam Deck with 1 ByteHacking the XBox 360 HypervisorPixel 6 Bootloader SeriesSolo: A Pixel 6 Pro StoryGaining kernel code execution on an MTE-enabled Pixel 8Bypassing MTE with CVE-2025-0072Debugging the Pixel 8 kernel via KGDBA First Glimpse of the Starlink User TerminalDiving into Starlink's User Terminal FirmwareARM TrustZone: pivoting to the secure worldTEE ReversingA Deep Dive into Samsung's TrustZone - Parts 1-3Researching Xiaomi's TEEKinibi TEE: Trusted Application ExploitationReversing Samsung's H-Arx Hypervisor FrameworkEL3vated Privileges: Glitching Google WiFi Pro from Root to EL3Your not so "Home Office" - SOHO Hacking at Pwn2OwnPwn2Own Toronto 2023 Series - Parts 1-5Pwn2Own: WAN-to-LAN Exploit Showcasebt-re-mad-skillzLLM skills for Bluetooth Controller firmware RE at the HCI layer, for Claude Code and ChatGPT/Codex.