Skip to content
82

Awesome Connected Things Sec

A Curated list of Security Resources for all connected things

3.6k stars593 forks891 entriesLast push Aug 29, 2026 (1 month ago)License CC0-1.0

This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.

Hardware Attacks >Fundamentals

IoT Hardware Guide

Intro to Hardware Hacking - Dumping Your First Firmware

An Introduction to Hardware Hacking

Hardware Toolkits for IoT Security Analysis

Hardware Hacking for IoT Devices - Offensive IoT Exploitation

Hardware Attacks >Interface Attacks

Identifying UART Interface

An in depth explanation of the UART protocol.

In 2 lists

Serial Terminal Basics

Reverse Engineering Serial Ports

Intro to Embedded RE: UART Discovery and Firmware Extraction via UBoot

In 2 lists

Using UART to Connect to a Chinese IP Cam

A Journey into IoT Hardware Hacking: UART

Accessing and Dumping Firmware Through UART

UART Connections and Dynamic Analysis on Linksys e1000

Hardware Hacking 101: Introduction to JTAG

How to Find the JTAG Interface

Analyzing JTAG

Bus Pirate JTAG Connections with OpenOCD

Extracting Firmware from External Memory via JTAG

The Hitchhacker's Guide to iPhone Lightning and JTAG Hacking

Debugging AVR Microcontrollers Through JTAG

SWD Protocol Overview - HardBreak Wiki

Unveiling Vulnerabilities: Exploring SWD Attack Surface in Hardware

Introduction to ARM Serial Wire Debug Protocol

Serial Wire Debug and CoreSight Architecture

LibSWD - Serial Wire Debug Open Library

Hardware Hacking and Exploitation Bootcamp - SWD

Hardware Hacking 101: Identifying and Dumping eMMC Flash

In 2 lists

Dumping Firmware from Router Using Bus Pirate - SPI

In 2 lists

Extracting Flash Memory over SPI

Extracting Firmware from Embedded Devices (SPI NOR Flash)

How to Flash Chip of a Router with a Programmer

TPM 2.0: Extracting Bitlocker Keys Through SPI

IoT Security Part 16: Hardware Attack Surface I2C

I2C Exploitation - HackTricks

Non-invasive I2C Hardware Trojan Attack Vector (PDF)

Hardware Hacking: I2C Injection with Bus Pirate

Safeguarding SPI, I2C, and I3C Protocols

Introduction to TPM (Trusted Platform Module)

Trusted Platform Module Security Defeated in 30 Minutes

Hardware Attacks >Memory Extraction

eMMC Protocol

RPMB: A Secret Place Inside the eMMC

eMMC Data Recovery from Damaged Smartphone

In 2 lists

Unleash Your Smart-Home Devices: Vacuum Cleaning Robot Hacking

Hands-On IoT Hacking: Rapid7 at DEF CON 30

Hardware Attacks >Side-Channel and Fault Injection

Side Channel Attacks - Yifan Lu

Attacks on Implementations of Secure Systems

Fuzzing, Binary Analysis, IoT Security Collection

NAND Glitching Attack on Wink Hub

Voltage Glitching with Crowbars Tutorial

Voltage Glitching Attack using iCEstick Glitcher

FPGA Glitching and Side Channel Attacks - Samy Kamkar

Hardware Power Glitch Attack - rhme2

Keys in Flash - Glitching AES Keys from Arduino

Implementing Practical Electrical Glitching Attacks

How to Voltage Fault Injection

Glitcher Part 1 - Reproducible Voltage Glitching on STM32 Microcontrollers

In 2 lists

STM32L05 Voltage Glitching

In 2 lists

Breaking AES with ChipWhisperer

ChipWhisperer Wiki

Rowhammer Bit Flips to Steal Crypto Keys

Dumping the Amlogic A113X Bootrom

In 2 lists

Retreading The AMLogic A113X TrustZone Exploit Process

In 2 lists

Reverse Engineering an Unknown Microcontroller

In 2 lists

Hacking Microcontroller Firmware Through a USB

In 2 lists

There's A Hole In Your SoC: Glitching The MediaTek BootROM

In 2 lists

Hardware Attacks >PCIe and DMA Attacks

A Practical Tutorial on PCIe for Total Beginners on Windows - Part 1

In 2 lists

A Practical Tutorial on PCIe for Total Beginners on Windows - Part 2

In 2 lists

PCIe DMA Attack against a Secured Jetson Nano (CVE-2022-21819)

In 2 lists

Wireless Protocols >RF Fundamentals

Complete Course in Software Defined Radio - Michael Ossmann

Understanding Radio

Introduction to Software Defined Radio

Introduction to GNU Radio Companion

Creating a Flow Graph in GNU Radio Companion

Analyzing Radio Signals 433MHz

Recording Specific Radio Signals

Replay Attacks with Raspberry Pi and rpitx

Reverse Engineering a Car Key Fob Signal

In 2 lists

GRCON 2021 - Capture the Signal

In 2 lists

Wireless Protocols >Bluetooth / BLE

Awesome Bluetooth Security

Traffic Engineering in a Bluetooth Piconet

BLE Characteristics: A Beginner's Tutorial

Intro to Bluetooth Low Energy (PDF)

Bluetooth LE Security Study Guide

Reverse Engineering BLE Devices

In 2 lists

My Journey Towards Reverse Engineering a Smart Band - Bluetooth-LE RE

In 2 lists

Intel Edison as Bluetooth LE Exploit Box

Reverse Engineering and Exploiting a Smart Massager

In 2 lists

I Hacked MiBand 3

GATTacking Bluetooth Smart Devices

Examining the August Smart Lock

Practical Introduction to BLE GATT Reverse Engineering

In 2 lists

MojoBox - Yet Another Not So Smartlock

Bluetooth Smartlocks

Bluetooth Beacon Vulnerability

Denial of Pleasure: Attacking Unusual BLE Targets with a Flipper Zero

In 2 lists

Grand Theft Auto: A peek of BLE relay attack

In 2 lists

How I Hacked Smart Lights: CVE-2022-47758

In 2 lists

Finding Bugs in Bluetooth

Sweyntooth Vulnerabilities

BrakTooth: Causing Havoc on Bluetooth Link Manager

BLUFFS: Bluetooth Forward and Future Secrecy Attacks (CVE-2023-24023)

AirDrop Leak - Sniffing BLE Traffic from Apple Devices

BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution

In 2 lists

BRAKTOOTH: Causing Havoc on Bluetooth Link Manager (PDF)

In 2 lists

Norec Attack: Stripping BLE encryption from Nordic's Library (CVE-2020-15509)

In 2 lists

BlueDucky - HID Injection on Unpatched Android (CVE-2023-45866)

Microsoft Bluetooth Driver Spoofing - CVE-2024-21306

Bluetooth Auracast / LE Audio Security Analysis

Blue2thprinting: WTF Am I Even Looking At?

Open Wounds: Last 5 Years Have Left Bluetooth to Bleed

Sniffing Bluetooth Through My Mask During the Pandemic

Bluing - Intelligence Gathering for Bluetooth

BlueToolkit - Bluetooth Classic Vulnerability Testing

btproxy

hcitool and bluez

Testing with GATT Tool

crackle - Cracking BLE Encryption

Crack and decrypt BLE encryption.

In 3 lists

bettercap

The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.

In 5 listsDetails

GATTacker

BTLEjack - BLE Swiss Army Knife

Based on the micro:bit, it provides everything you need to sniff, jam and hijack Bluetooth Low Energy devices.

In 2 lists

DEDSEC Bluetooth Exploit

BrakTooth ESP32 PoC

SweynTooth BLE Attacks

ESP32 Bluetooth Classic Sniffer

Bluetooth Hacking Collection

nRF52840 Dongle

Ubertooth One

CSR 4.0 Bluetooth Dongle

ESP32

Sena UD100

ESP-WROVER-KIT

ice9-bluetooth-sniffer

In 2 lists

InternalBlue - Bluetooth Experimentation Framework

Bluetooth experimentation framework based on the Reverse Engineering of Broadcom Bluetooth Controllers

In 2 lists

Hacking Bluetooth to Brew Coffee from GitHub Actions - Part 1

In 2 lists

Hacking Bluetooth to Brew Coffee from GitHub Actions - Part 2

In 2 lists

Hacking Bluetooth to Brew Coffee from GitHub Actions - Part 3

In 2 lists

Wireless Protocols >Zigbee / Z-Wave

Introduction and Protocol Overview

ZigBee and Z-Wave Security Brief

Hacking ZigBee Networks

Hacking IoT Devices with Attify Zigbee Framework

Zigator: Analyzing Security of Zigbee-Enabled Smart Homes

Security Analysis of Zigbee with Zigator and GNU Radio

Low-Cost ZigBee Selective Jamming

Killerbee

Framework for Testing & Auditing ZigBee and IEEE 802.15.4 Networks.

In 3 lists

ZigDiggity

Zigator

Z3sec

zigbear

ApiMote

RaspBee

ATUSB IEEE 802.15.4 Adapter

USRP

Wireless Protocols >LoRa / LoRaWAN

LoRaWAN Security Overview - Tektelic

Security Vulnerabilities in LoRaWAN

Low Powered and High Risk: Attacks on LoRaWAN Devices

LAF - LoRaWAN Auditing Framework

ChirpOTLE - LoRaWAN Security Framework

LoRaWAN Security Survey - ScienceDirect

LoRaWAN - Wikipedia

Millions of Devices Using LoRaWAN Exposed - SecurityWeek

Do You Blindly Trust LoRaWAN Networks? - IOActive

LoRaWAN Encryption Keys Easy to Crack - Threatpost

LoPT: LoRa Penetration Testing Tool (PDF)

LoRa Craft - Packet Interception

Open Source LoRaWAN Hacking Tool

LoRaWAN Hackaday Projects

Wireless Protocols >Matter / Thread

Matter Standard - CSA-IoT

Matter Protocol Wikipedia

Matter Protocol Complete Guide 2025

How to Secure Smart Home Devices with Matter

Smart Home Device Solutions for Matter - DigiCert

Security Vulnerabilities and Attack Scenarios in Smart Home with Matter

Trust Matters: Uncovering Vulnerabilities in Matter Protocol - Nozomi

Matter over Thread Security

State-of-the-Art Review on IoT Wireless PAN Protocol Security

Matter Smart Home - Krasamo

Threadbare: Practical Attacks on Thread Networks (Black Hat USA 2024)

Matter Specification 1.3 - Connectivity Standards Alliance

Thread Group Security Analysis

Wireless Protocols >Cellular (GSM/LTE/5G)

Awesome Cellular Hacking

Introduction to GSM Security

Breaking LTE on Layer Two

5Ghoul - 5G NR Attacks and Fuzzing

Exploiting CSN.1 Bugs in MediaTek Basebands

In 2 lists

SIM Hijacking

In 2 lists

SigPloit - Telecom Signaling Exploitation Framework

Signaling security testing framework dedicated to telecom security for researching vulnerabilites in the signaling protocols used in mobile (cellular phone) operators.

In 2 lists

LTE Sniffer

5G NR Jamming, Spoofing and Sniffing

LTrack: Stealthy Tracking of Mobile Phones in LTE

Open5GS - Open Source 5G/4G Core

Open5GS is a C-language Open Source implementation for 5G Core and EPC, i.e. the core network of LTE/NR network (Release-19)

In 2 lists

SCAT - Signaling Collection and Analysis Tool for Cellular

GSM Security Part 2

What is Base Transceiver Station

Introduction to SS7 Signaling

SS7 Network Architecture

Introduction to SIGTRAN

How to Build Your Own Rogue GSM BTS

GSM Vulnerabilities with USRP B200

Security Testing 4G (LTE) Networks

Case Study of SS7/SIGTRAN Assessment

ss7MAPer - SS7 Pentesting Toolkit

Fake BTS Detector (SCL-8521)

Wireless Protocols >NFC/RFID

Awesome RFID/NFC Security Talks

RFID Discord Group

SoK: Security of EMV Contactless Payment Systems

In 2 lists

NFC Relay Attack on Tesla Model Y

In 2 lists

Wireless Protocols >DECT (Digital Enhanced Cordless Telecommunications)

Real Time Interception of DECT Cordless Telephone

Eavesdropping on Unencrypted DECT Voice Traffic

Decoding DECT Voice Traffic: In-depth Explanation

Wireless Protocols >Wi-Fi

Framing Frames: Bypassing Wi-Fi Encryption by Manipulating Transmit Queues

In 2 lists

Man-in-the-Middle Attacks without Rogue AP: When WPAs Meet ICMP Redirects

In 2 lists

WPAxFuzz: Sniffing Out Vulnerabilities in Wi-Fi Implementations

In 2 lists

Untangling the Knot: Breaking Access Control in Home Wireless Mesh Networks

In 2 lists

Over The Air: Exploiting Broadcom's Wi-Fi Stack (Part 1)

In 2 lists

Over The Air: Exploiting Broadcom's Wi-Fi Stack (Part 2)

In 2 lists

Over The Air: Exploiting The Wi-Fi Stack on Apple Devices

In 2 lists

Reverse-engineering Broadcom wireless chipsets

In 2 lists

Exploiting Qualcomm WLAN and Modem Over the Air

In 2 lists

Windows Wi-Fi Driver RCE Vulnerability - CVE-2024-30078

In 2 lists

When a Wi-Fi SSID Gives You Root on an MT02 Repeater - Part 1

In 2 lists

When a Wi-Fi SSID Gives You Root on an MT02 Repeater - Part 2

In 2 lists

Reverse Engineering WiFi on RISC-V BL602

In 2 lists

Unveiling secrets of the ESP32: creating an open-source MAC Layer

In 2 lists

Unveiling secrets of the ESP32: reverse engineering RX

In 2 lists

Wireless Protocols >USB

ALL ABOUT USB-C: INTRODUCTION FOR HACKERS

In 2 lists

Hi, My Name is Keyboard

In 2 lists

How to Weaponize the Yubikey

In 2 lists

Wireless Protocols >UWB (Ultra-Wideband)

UWB Real Time Locating Systems: How Secure Radio Communications May Fail in Practice

In 2 lists

Wireless Protocols >TETRA

All cops are broadcasting: TETRA under scrutiny

In 2 lists

TETRA:BURST - Five Vulnerabilities in TETRA Standard (Midnight Blue)

TETRA:BURST 2:ELECTRIC BOOGALOO - End-to-End Encryption Broken (BlackHat USA 2025)

TETRA Decoder - Open Source TETRA Receiver

Practical TETRA Sniffing with SDR

Firmware Security >Fundamentals

Introduction to Firmware Analysis - OWASP

OWASP Firmware Security Testing Methodology

IoT Security Verification Standard (ISVS)

Reversing 101

by Kevin Thomas

In 3 lists

Hands-on Firmware Extraction, Exploration, and Emulation

In 2 lists

Firmware Security >Extraction

Router Analysis Part 1: UART Discovery and SPI Flash Extraction

Hardware Hacking Tutorial: Dumping and Reversing Firmware

In 2 lists

Firmware Samples - firmware.center

BasicFUN Series: Hardware Analysis / SPI Flash Extraction

In 2 lists

BasicFUN Series: Reverse Engineering Firmware / Reflashing SPI Flash

In 2 lists

Retrofitting encrypted firmware is a Bad Idea

In 2 lists

Firmware Security >Static Analysis Tools

EMBA - Embedded Linux Firmware Analyzer

FACT - Firmware Analysis and Comparison Tool

Binwalk v3

Binwalk is a fast, easy to use tool for analyzing, reverse engineering, and extracting firmware images.

In 6 listsDetails

Firmwalker

Searches extracted firmware images for interesting files and information.

In 2 lists

fwanalyzer

Analyze security of firmware based on customized rules. Intended as additional step in DevSecOps, similar to CI.

In 2 lists

fwhunt-scan - UEFI Firmware Analysis

ByteSweep

BINSEC

unblob - Extraction Framework

Checksec.sh

bash script to check the properties of executables (like PIE, RELRO, PaX, Canaries, ASLR, Fortify Source)

In 2 lists

Firmware Modification Kit

Firmware Security >Dynamic Analysis and Emulation

Firmadyne - Automated Firmware Emulation

Tries to emulate and pentest a firmware.

In 2 lists

FirmAE - Firmware Analysis and Emulation

QEMU

is a fast processor emulator using a portable dynamic translator. QEMU emulates a full system, including a processor and various peripherals. It can be used to launch a different Operating System without rebooting the PC or to debug system code.

In 9 listsDetails

PANDA - Architecture-Neutral Dynamic Analysis

[Platform for Architecture-Neutral Dynamic Analysis]

In 4 listsDetails

Avatar2 - Dynamic Firmware Analysis

Renode - Embedded Systems Emulator

a virtual development tool for multinode embedded networks.

In 2 lists

Unicorn Engine - CPU Emulator

Unicorn CPU emulator framework (ARM, AArch64, M68K, Mips, Sparc, PowerPC, RiscV, S390x, TriCore, X86)

In 2 lists

Qiling Framework

HALucinator

FirmWire - Baseband Firmware Emulation

SymQEMU

S2E - Selective Symbolic Execution

Bochs - x86 Emulator

SAME70 Emulator

In 2 lists

Emulate Until You Make it

Firmware Emulation with QEMU

Emulating ARM Router Firmware - Azeria Labs

Emulating IoT Firmware Made Easy

In 2 lists

IoT Binary Analysis and Emulation Part 1

Cross Debugging for ARM/MIPS with QEMU

QEMU + Buildroot 101

Simulating and Hunting Firmware Vulnerabilities with Qiling

Qiling and Binary Emulation for Automatic Unpacking

Debugging D-Link: Emulating Firmware and Hacking Hardware

In 2 lists

Adaptive Emulation Framework for Multi-Architecture IoT

Automatic Firmware Emulation through Invalidity-guided Knowledge Inference

Emulating RH850 architecture with Unicorn Engine

In 2 lists

Icicle: A Re-designed Emulator for Grey-Box Firmware Fuzzing

In 2 lists

Challenges and Pitfalls while Emulating Six Current Icelandic Household Routers

In 2 lists

My Emulation Goes to the Moon... Until False Flag

In 2 lists

How to Emulate Android Native Libraries Using Qiling

In 2 lists

Firmware Security >OTA Update Security

IoT Firmware Security and Update Mechanisms

Implementing OTA Updates for IoT Devices

Secure OTA Boot Chains and Firmware Verification

The Key to Firmware Security in Connected IoT Devices

Security Considerations for OTA Updates - Stack Overflow

Top 10 IoT Vulnerabilities - OTA Update Attacks

Updating IoT Devices 2025: Best Practices

Review of IoT Firmware Vulnerabilities and Auditing Techniques

Firmware Security >RTOS Security

Zephyr RTOS GitHub

Primary Git Repository for the Zephyr Project. Zephyr is a new generation, scalable, optimized, secure RTOS for multiple hardware architectures.

In 6 listsDetails

Zephyr Vulnerabilities List

NCC Group Zephyr and MCUboot Security Assessment

26 Flaws in Zephyr and MCUboot

Tackling Security in Zephyr RTOS

Enhancing Security with Zephyr RTOS

FreeRTOS 13 Vulnerabilities in TCP/IP Stack

Exploiting Memory Corruption in FreeRTOS - ShmooCon

RTOS Security Analysis - USENIX

Dynamic Vulnerability Patching for RTOS

AWS FreeRTOS Vulnerabilities

Firmware Security >Reverse Engineering Tools

Ghidra

A software reverse engineering (SRE) framework created and maintained by the National Security Agency Research Directorate.

In 6 listsDetails

IDA Pro

Proprietary multi-processor disassembler and debugger for Windows, GNU/Linux, or macOS; also has a free version, IDA Free.

In 4 lists

Radare2

Cutter - GUI for Radare2

Free and Open Source Reverse Engineering Platform powered by rizin.

In 4 lists

Binary Ninja

A reversing engineering platform that is an alternative to IDA.

In 3 lists

GDB

GNU Project debugger. GPL-3.0-or-later

In 5 listsDetails

RetDec - Decompiler

RetDec is a retargetable machine-code decompiler based on LLVM.

In 3 lists

Diaphora - Binary Diffing

[diff]

In 2 lists

Angr - Binary Analysis

Platform-agnostic binary analysis framework developed at UCSB's Seclab.

In 5 listsDetails

Frida - Dynamic Instrumentation

Dynamic instrumentation toolkit for developers, reverse-engineers, and security researchers.

In 4 lists

Ret-sync

ret-sync is a set of plugins that helps to synchronize a debugging session (WinDbg/GDB/LLDB/OllyDbg2/x64dbg) with IDA/Ghidra/Binary Ninja disassemblers.

In 4 lists

OllyDbg

x86 debugger for Windows binaries that emphasizes binary code analysis.

In 5 listsDetails

x64dbg

An open-source x64/x32 debugger for windows.

In 3 lists

Hopper

copyright: — macOS and Linux reverse engineering tool that lets you disassemble, decompile and debug applications. Hopper displays the code using different representations, e.g. the Control Flow Graph, and the pseudo-code of a procedure. Supports Apple Silicon.

In 5 listsDetails

Immunity Debugger

PEiD

Ghidriff - Ghidra Binary Diffing Engine

[Python Command-Line Ghidra Binary Diffing Engine]

In 3 lists

The rev.ng decompiler goes open source

In 2 lists

Intro to Cutter

In 2 lists

pyghidra-mcp: Headless Ghidra MCP Server

In 2 lists

Mindshare: Using Binary Ninja API to Detect Potential Use-after-free Vulnerabilities

In 2 lists

Reverse Engineering and Patching with Ghidra

Reverse Engineering with Ghidra: Breaking Firmware Encryption

Reversing Firmware with Radare

In 2 lists

Reversing ESP8266 Firmware

In 2 lists

Automating Binary Vulnerability Discovery with Ghidra and Semgrep

Finding Bugs in Netgear Router

Ghidra 101: Cursor Text Highlighting

In 2 lists

Ghidra 101: Decoding Stack Strings

In 2 lists

Extending Ghidra Part 1: Setting up a Development Environment

In 2 lists

Expanding the Dragon: Adding an ISA to Ghidra

Ghidra nanoMIPS ISA module

In 2 lists

Binary type inference in Ghidra

In 2 lists

Writing a Ghidra processor module

In 2 lists

Firmware Security >Online Assemblers

AZM Online ARM Assembler - Azeria Labs

Online Disassembler

Compiler Explorer

Run GNAT FSF compilers interactively from your web browser and interact with the assembly.

In 3 lists

Firmware Security >ARM Exploitation

Azeria Labs ARM Tutorials

Miscellaneous ARM related Tutorials.

In 2 lists

ARM Exploitation for IoT

Damn Vulnerable ARM Router (DVAR)

Exploit Education

A Guide to ARM64 / AArch64 Assembly on Linux

ARMv8 AArch64/ARM64 Full Beginner's Assembly Tutorial

In 2 lists

A Noobs Guide to ARM Exploitation

In 2 lists

ARM64 Reversing And Exploitation Series (8ksec) - Parts 1-10

In 2 lists

AArch64 memory and paging

In 2 lists

We are ARMed no more ROPpery Here

In 2 lists

Firmware Security >Binary Analysis

Practical Binary Analysis

Firmware Security >Secure Boot

Writing a Bootloader

Pwn the ESP32 Secure Boot

Pwn ESP32 Forever: Flash Encryption and Secure Boot Keys Extraction

ESP32 Secure Boot Bypass (CVE-2020-13629)

In 2 lists

Amlogic S905 SoC: Bypassing Secure Boot

Defeating Secure Boot with Symlink Attacks

PS4 Secure Boot Hacking - Fail0verflow

Dell BIOS Vulnerabilities - BIOSDisconnect

U-Boot USB DFU Vulnerability (CVE-2022-2347)

Breaking Secure Boot on Silicon Labs Gecko

In 2 lists

Firmware Security >UEFI Security

Using Symbolic Execution to Detect UEFI Vulnerabilities

HP Enterprise UEFI Vulnerabilities

Emulating and Exploiting UEFI Firmware

The Dark Side of UEFI: A technical Deep-Dive into Cross-Silicon Exploitation

In 2 lists

Inside the LogoFAIL PoC: From Integer Overflow to Arbitrary Code Execution

In 2 lists

PixieFail: Nine vulnerabilities in Tianocore's EDK II IPv6 network stack

In 2 lists

For Science! - Using an Unimpressive Bug in EDK II

In 2 lists

Hydroph0bia: SecureBoot bypass for Insyde H2O

In 2 lists

PKfail: Untrusted Platform Keys in UEFI Firmware (Binarly, 2024)

LogoFAIL: Image Parsing Vulnerabilities in System Firmware (Binarly)

BlackLotus UEFI Bootkit Analysis - ESET

In 2 lists

Bootkitty: First UEFI Bootkit for Linux (ESET, 2024)

Threadbare: Practical Attacks on Thread Networks (Black Hat USA 2024)

CVE-2024-0762 - PixieFail Followup TPM Bypass

Zip Slip Vulnerability

Firmware Security >Router Firmware Analysis

A Journey into IoT: Discover Components and Ports

In 2 lists

A Journey into IoT: Firmware Dump and Analysis

In 2 lists

A Journey into IoT: Radio Communications

In 2 lists

A Journey into IoT: Internal Communications

In 2 lists

Dynamic Analysis of Firmware Components in IoT Devices

In 2 lists

RV130X Firmware Analysis

In 2 lists

TP-Link Firmware Decryption C210 V2 cloud camera bootloaders

In 2 lists

Firmware Security >Router Exploitation

Hunting for Unauthenticated n-days in Asus Routers

In 2 lists

Pulling MikroTik into the Limelight

In 2 lists

Exploiting MikroTik RouterOS Hardware with CVE-2023-30799

In 2 lists

Rooting Xiaomi WiFi Routers

In 2 lists

Route to Safety: Navigating Router Pitfalls

ROPing our way to RCE

In 2 lists

ROPing Routers from scratch: Tenda Ac8v4

In 2 lists

PwnAgent: A One-Click WAN-side RCE in Netgear RAX Routers

In 2 lists

Puckungfu 2: Another NETGEAR WAN Command Injection

In 2 lists

Reversing, Discovering, And Exploiting A TP-Link Router Vulnerability - CVE-2024-54887

In 2 lists

Exploiting Zero-Day (CVE-2025-9961) Vulnerability in the TP-Link AX10 Router

In 2 lists

FiberGateway GR241AG - Full Exploit Chain

In 2 lists

Blackbox-Fuzzing of IoT Devices Using the Router TL-WR902AC

In 2 lists

Rooting the TP-Link Tapo C200 Rev.5

In 2 lists

Netgear Orbi: Introduction, UART Access, Recon

Netgear Orbi: Crashes in SOAP-API

Netgear Orbi: NDay Exploit CVE-2020-27861

The Last Breath of Our Netgear RAX30 Bugs

In 2 lists

TP-Link TDDP Buffer Overflow Vulnerability

In 2 lists

Pwn2Own Tokyo 2020: Defeating the TP-Link AC1750

In 2 lists

TP-Link Tapo c200 Camera Unauthenticated RCE (CVE-2021-4045)

In 2 lists

Patch Diffing a Cisco RV110W Firmware Update - Part 1

In 2 lists

CVE-2024-20356: Jailbreaking a Cisco appliance to run DOOM

In 2 lists

Flashback Connects - Cisco RV340 SSL VPN RCE

In 2 lists

Firmware Security >Secure Boot Bypasses

Bypassing Secure Boot using Fault Injection

In 2 lists

Breaking Secure Boot on Google Nest Hub (2nd Gen)

In 2 lists

Booting into Breaches: Hunting Windows SecureBoot's Remote Attack Surfaces

In 2 lists

Network and Web Protocols >MQTT

Introduction to MQTT

MQTT Broker Security 101

Hacking the IoT with MQTT

IoT Security: RCE in MQTT Protocol

IoXY - MQTT Intercepting Proxy

MQTT-PWN

Understanding the MQTT Protocol Packet Structure

Are Smart Homes Vulnerable to Hacking?

Penetration Testing Sesame Smart Door Lock

Servisnet Tessa - MQTT Credentials Dump (Metasploit)

Eclipse Mosquitto Unquoted Service Path

CVE-2020-13849

DoS vulnerability (CVSS 7.5)

CVE-2023-3028

Insufficient authentication (CVSS 9.8)

CVE-2021-0229

Resource consumption (CVSS 5.3)

CVE-2019-5432

Malformed packet crash (CVSS 7.5)

Mosquitto - Open Source MQTT Broker

"The" Open Source MQTT Broker.

In 2 lists

HiveMQ

Java MQTT Broker that supports MQTT 3.1, 3.1.1 and 5.0. Commercial and open source editions available.

In 2 lists

MQTT Explorer

Tool to visualize your MQTT topics in a topic hierarchy, a MQTT swiss-army knife.

In 3 lists

MQTT Topic ACL Linter

Local-only static analysis for invalid, broad, duplicate, and overlapping MQTT topic-filter ACL rules; does not connect to a broker or replace a security audit.

Nmap MQTT Library

Seven Best MQTT Client Tools

Using IoT MQTT for V2V and Connected Cars

MQTT Hardware Development Projects

100,000 Connected Cars with Kubernetes, Kafka, MQTT, TensorFlow

Authenticating Devices Using MQTT with Auth0

Deep Learning UDF for MQTT IoT Anomaly Detection

Guide to MQTT: Hacking a Doorbell

WailingCrab Malware Using MQTT for C2

Alert: New WailingCrab Malware Loader

MQTT on Snapcraft

Network and Web Protocols >CoAP

IETF Security Protocol Comparison

RFC 8613 - OSCORE

Radware - CoAP Protocol Overview

EMQX on CoAP and IoT Security (2024)

RFC 8323 - CoAP over TCP

RFC 8824 - SCHC Header Compression

CoAP NSE (Nmap)

Copper4Cr - CoAP User-Agent for Chrome

libcoap CLI Tools

C implementation of a lightweight application-protocol for devices that are constrained their resources such as computing power, RF range, memory, bandwidth, or network packet sizes. This protocol, CoAP, is standardized by the IETF as RFC 7252.

In 4 listsDetails

Scapy CoAP Plugin

Python-based interactive packet manipulation program & library. Supports CAN/ISOTP/UDS/GMLAN plus many other protocols.

In 7 listsDetails

Eclipse Californium (Java)

Peach Fuzzer

Raspberry Pi / Arduino + 6LoWPAN

Contiki-NG: The OS for Next Generation IoT Devices

In 2 lists

Zolertia

OpenMote

Nordic Boards

Official Website

In 2 lists

SpectralOps - Top IoT Protocol Security Issues

CoAP Exposure Study (2024)

Network and Web Protocols >mTLS

mTLS: When Certificate Authentication is Done Wrong

mTLS Authentication in IoT: Enhancing Security for Connected Devices

Hands On IoT MitM Part 1 - AWS IoT MQTT + mTLS Interception

OWASP MASTG-TECH-0012: Bypassing Certificate Pinning in Android IoT Companion Apps

Theory to Practice: mTLS in Action Part 1

Configuring mTLS on Mosquitto MQTT Broker

AWS IoT Docs: X.509 Client Certificates and Fleet Provisioning

Azure IoT Hub: mTLS X.509 CA Authentication Concept

Evaluation of TLS and mTLS in Internet of Things Systems - MIUN DiVA, 2024

Atlas: Enabling Cross-Vendor mTLS Authentication for IoT - arXiv 2025

Lightweight mTLS Authentication for Industrial IoT - PMC/NIH 2023

Quantum-Enhanced mTLS for IoT Battlefield Networks - IJPSAT

AI vs. IoT Security: Fingerprinting and Defenses Against TLS Attacks - IEEE Xplore 2025

Intercepting IoT Device Traffic with ARP Poisoning + mitmproxy TLS Intercept

Using Linux to Intercept IoT Device Traffic with mitmrouter

Mutual TLS - The Backend Engineering Show Deep Dive

Intercepting SSL/TLS - Fiddler and MITMProxy Decrypt Walkthrough

Decrypting Kubernetes mTLS Traffic - eCapture, Custom CA, eBPF Methods

Mastering mTLS: Stop MITM Attacks and Boost API/IoT Security

Introduction to IoT Penetration Testing Webinar - CyberWarFare Labs

Network and Web Protocols >IoT Protocols Overview

IoT Protocols Overview

IoT Architecture

Attacking IoT Devices from Web Perspective

In 2 lists

Awesome Industrial Protocols

In 2 lists

Cloud and Backend Security >AWS IoT Security

AWS Penetration Testing Policy

AWS Pentesting Guide - HackerOne

A few notes on AWS Nitro Enclaves

In 2 lists

Comprehensive AWS Pentesting Guide - BreachLock

AWS Pentest Methodology - MorattiSec

AWS Penetration Testing Methodology - Rootshell

AWS Penetration Testing Techniques 2025

CloudFox - Cloud Attack Paths

Automating situational awareness for cloud penetration tests

In 2 lists

S3Scanner - Leaky Bucket Discovery

Scan for misconfigured S3 buckets across S3-compatible APIs!

In 3 lists

Cloudfoxable Labs

AWS Security Pentesting Resources

Pacu - AWS Exploitation Framework

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments. By RhinoSecurityLabs.

In 4 lists

ScoutSuite - Multi-cloud Security Auditing

Open source multi-cloud security-auditing tool, which enables security posture assessment of cloud environments.

In 4 lists

Prowler - Cloud Security Assessment

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.

In 2 lists

7 Best AWS Pentesting Tools 2026

PayloadsAllTheThings - AWS Pentest

An API key is a unique identifier that is used to authenticate requests associated with your project. Some developers might hardcode them or leave it on public shares.

In 12 listsDetails

Cloud and Backend Security >Firebase / Cloud Misconfigurations

Firebase Security Rules Testing

Misconfigured Firebase Databases

Mobile Application Security >Android

Android App Reverse Engineering 101

In 2 lists

Android Application Pentesting Book

Android Pentest Video Course - TutorialsPoint

Android Tamer

Android Hacker's Handbook

A first look at Android 14 forensics

In 2 lists

Deobfuscating Android ARM64 strings with Ghidra

In 2 lists

Introduction to Fuzzing Android Native Components

In 2 lists

Hacking Android Games

In 2 lists

Intercepting HTTPS Communication in Flutter

In 2 lists

Android Kernel Exploitation

In 2 lists

Attacking Android Binder: Analysis and Exploitation of CVE-2023-20938

In 2 lists

Attacking the Android kernel using the Qualcomm TrustZone

In 2 lists

Driving forward in Android drivers

In 2 lists

Analyzing a Modern In-the-wild Android Exploit

In 2 lists

Exploiting Android's Hardened Memory Allocator

In 2 lists

GPUAF - Two ways of Rooting All Qualcomm based Android phones

The Qualcomm DSP Driver - Unexpectedly Excavating an Exploit

In 2 lists

Qualcomm DSP Kernel Internals

In 2 lists

Binder Fuzzing

In 2 lists

Android: Scudo

In 2 lists

Behind the Shield: Unmasking Scudo's Defenses

In 2 lists

scudo Hardened Allocator - Unofficial Internals Documentation

In 2 lists

Mobile Application Security >iOS

iOS Pentesting Guide

In 2 lists

OWASP Mobile Security Testing Guide

An iOS hacker tries Android

In 2 lists

Analyzing iOS Kernel Panic Logs

Blasting Past iOS 18

In 2 lists

Emulating an iPhone in QEMU

In 2 lists

First analysis of Apple's USB Restricted Mode bypass (CVE-2025-24200)

In 2 lists

Exploring UNIX pipes for iOS kernel exploit primitives

In 2 lists

Industrial and Automotive >ICS/SCADA

ICS Village

ICS Discord Group

Controlthings.io Platform

Applied Cyber Security and the Smart Grid

Deep Lateral Movement in OT Networks

In 2 lists

Hacking ICS Historians: The Pivot Point from IT to OT

In 2 lists

OPC UA Deep Dive Series - Parts 1-5

In 2 lists

Inside a New OT/IoT Cyberweapon: IOCONTROL

In 2 lists

Attention, High Voltage: Exploring the Attack Surface of the Rockwell Automation PowerMonitor 1000

In 2 lists

Industrial and Automotive >Automotive Security

Awesome Vehicle Security

Books, hardware, software, applications, car hacking and more.

In 3 listsDetails

Car Hacking Village

In 2 lists

Jeep Hack

Subaru Head Unit Jailbreak

Car Hacking Practical Guide 101

CAN Injection: keyless car theft

In 2 lists

How I Hacked my Car Series - Parts 1-6

In 2 lists

How I Also Hacked my Car

In 2 lists

Extracting Secure Onboard Communication (SecOC) keys from a 2021 Toyota RAV4 Prime

In 2 lists

Recovering an ECU firmware using disassembler and branches

In 2 lists

Automotive Memory Protection Units: Uncovering Hidden Vulnerabilities

In 2 lists

Web Hackers vs The Auto Industry: Critical Vulnerabilities in Cars (Sam Curry, 2023)

In 2 lists

Hacking Kia: Remotely Controlling Cars With Just a License Plate (Sam Curry, 2024)

Hacking Subaru: Tracking and Controlling Cars via the STARLINK Admin Panel (Sam Curry, 2025)

Pwn2Own Automotive (ZDI Blog Category - 2024 & 2025 Tokyo)

Synacktiv Publications - Pwn2Own Automotive Writeups

Awesome CAN Bus - Curated Resources

A curated list of awesome CAN bus tools, hardware and resources.

In 3 listsDetails

Industrial and Automotive >EV Chargers

A Detailed Look at Pwn2own Automotive EV Charger Hardware

In 2 lists

Pwn2Own Automotive 2024: Hacking the ChargePoint Home Flex

In 2 lists

Reverse engineering an EV charger

In 2 lists

Pwn2Own Automotive 2024: Autel MaxiCharger Analysis (Computest Sector7)

SaiFlow Blog - OCPP/EV Charging Protocol Vulnerabilities

Payment Systems >ATM Hacking

Introduction to ATM Penetration Testing

Pwning ATMs for Fun and Profit

Jackpotting ATMs Redux - Barnaby Jack

Root Shell on Credit Card Terminal

In 2 lists

Payment Systems >Payment Village

Payment Village

Tools >Hardware Tools

Bus Pirate

Bus Pirate 5: The Swiss ARRRmy Knife of Hardware Hacking

In 2 lists

The Shikra

Detects and interacts with hardware debug ports like UART and JTAG. Among other protocols.

In 2 lists

Attify Badge

Flipper Zero

HackRF

A Software Defined Radio peripheral capable of transmission or reception of radio signals from 1 MHz to 6 GHz. Designed to enable test and development of modern and next generation radio technologies.

In 3 lists

RTL-SDR

In 2 lists

An In-Depth Look at the ICE-V Wireless FPGA Development Board

In 2 lists

Logic Analyzer - Saleae

Easy to use Logic Analyzer that support many protocols :euro:.

In 2 lists

JTAGulator

EEPROM Reader/SOIC Cable

ST-Link

Segger J-Link

FTDI-based Adapters

Black Magic Probe

FaceDancer21

RfCat

NullSec Ducky Payloads

Rubber Ducky BadUSB payload collection for Windows, macOS and Linux.

NullSec Flipper Suite

Flipper Zero payload collection for RF, RFID/NFC, BadUSB, infrared and wireless pentesting.

PineFlip

Flipper Zero companion app for Linux with screen mirroring, file manager and firmware management.

Hak5 Field Kits

NullSec Pineapple Suite

WiFi Pineapple payload collection for deauth, evil twin, handshake capture and network recon.

Tools >Software Tools

BlueSploit

IoTSecFuzz

Framework for automatisation of IoT layers security analysis: hardware, software and communication.

In 2 lists

PENIOT

ISF - Industrial Security Framework

HAL - Hardware Analyzer

A comprehensive reverse engineering and manipulation framework for gate-level netlists.

In 2 lists

PRET - Printer Exploitation Toolkit

Tool for printer security testing capable of IP and USB connectivity, fuzzing, and exploitation of PostScript, PJL, and PCL printer language features.

In 3 lists

Expliot Framework

Pentest framework like Metasploit but specialized for IoT.

In 2 lists

RouterSploit

Framework dedicated to exploit embedded devices.

In 4 lists

HomePwn

Swiss Army Knife for Pentesting of IoT Devices.

In 2 lists

Firmware Analysis Toolkit (FAT)

Shambles: The Next-Generation IoT Reverse Engineering Tool

In 2 lists

Samsung Firmware Magic

Decrypt Samsung SSD firmware updates.

In 2 lists

Tools >Fuzzing Tools

The art of Fuzzing: Introduction

A LibAFL Introductory Workshop

In 2 lists

The Blitz Tutorial Lab on Fuzzing with AFL++

In 2 lists

State of Linux Snapshot Fuzzing

In 2 lists

Fuzzing between the lines in popular barcode software

In 2 lists

Boofuzz

Fuzzing engine and fuzz testing framework.

In 4 lists

Syzkaller - Kernel Fuzzer

(2015) - An unsupervised coverage-guided kernel fuzzer supporting FreeBSD, Fuchsia, gVisor, Linux, NetBSD, OpenBSD, and Windows.

In 6 listsDetails

parking-game-fuzzer

In 2 lists

OWASP Fuzzing Info

Fuzz Testing of Application Reliability

FuzzingPaper Collection

Fuzzing ICS Protocols

Fuzzowski - Network Protocol Fuzzer

FIRM-AFL: High-Throughput IoT Firmware Fuzzing

Snipuzz: Black-box Fuzzing of IoT Firmware

In 2 lists

Fuzzing IoT Binaries Part 1

Fuzzing IoT Binaries Part 2

Awesome Embedded Fuzzing

AFL Training Exercises

Frankenstein - Broadcom/Cypress Firmware Emulation for Fuzzing

Dr. Memory

Memory Debugger for Windows, Linux, Mac, and Android

In 3 lists

Tools >Pentesting Operating Systems

AttifyOS

GNU/Linux distribution focused on tools useful during Internet of Things (IoT) security assessments.

In 3 lists

IoT Penetration Testing OS v1

EmbedOS

Sigint OS - LTE IMSI Catcher

Instant GNU Radio OS

Dragon OS - SDR Software

Skywave Linux - SDR

Zephyr RTOS

Linux Foundation Projects RTOS aiming at beeing secure and safe.

In 2 lists

Ubuntu LTS

Ubuntu is a Debian-based Linux distribution published by Canonical® who offer commercial support for enterprise-class Ubuntu Server variant.

In 4 listsDetails

Tools >Search Engines

Shodan

Shodan is a search engine that lets users search for various types of servers connected to the internet using a variety of filters. Some have also described it as a search engine of service banners, which are metadata that the server sends back to the client.

In 12 listsDetails

Censys

Censys is a search engine that allows computer scientists to ask questions about the devices and networks that compose the Internet by University of Michigan.

In 7 listsDetails

ZoomEye

ZoomEye is a freemium online tool aimed to help aid cybersecurity in the areas of reconnaissance and threat evaluation.

In 7 listsDetails

BinaryEdge

Threat intelligence and attack surface analysis.

In 3 lists

Thingful

is a Search Engine for the Internet of Things Find & use open IoT data from around the world.

In 4 listsDetails

Wigle

Wi-fi "wardriving" database. Contains a global map containing crowdsourced information on the location, name, and other properties of wi-fi networks. Software available to download to contribute data to the public infoset.

In 5 listsDetails

Hunter.io

Data broker providing a Web search interface for discovering the email addresses and other organizational details of a company.

In 8 listsDetails

BuiltWith

is a website that will help you find out all the technologies used to build a particular websites.

In 5 listsDetails

Recon-ng

Recon-ng is a full-featured Web Reconnaissance framework written in Python. Recon-ng has a look and feel similar to the Metasploit Framework.

In 6 listsDetails

PublicWWW

Find any alphanumeric snippet, signature or keyword in the web pages HTML, JS and CSS code.

In 7 listsDetails

FCC ID Database

seacrh by FCC ID, Country, Date, Company name or Frequency ( in Mhz)

In 3 lists

CVE PoC Search

Search public GitHub PoC repositories by CVE ID.

In 4 listsDetails

Defensive Security >Threat Modeling

STRIDE Threat Model Guide - Practical DevSecOps

OWASP Threat Modeling Process

In 2 lists

STRIDE-based Threat Modeling for IoT Precision Agriculture

What is STRIDE in Threat Modeling - Security Compass

Threat Modeling with ATT&CK - MITRE

What is Threat Modeling - Fortinet

STRIDE Threat Modeling for IoT Smart Home

STRIDE Threat Modeling for Smart Solar Energy Systems

STRIDE Threat Modeling for IoT Healthcare Systems

STRIDE for IoT Agriculture - IEEE

Defensive Security >Secure Development

Compiler Options Hardening Guide for C and C++

In 3 lists

Linux Hardening Guide

In 2 lists

Docker Security - Step-by-Step Hardening

(2023)

In 3 lists

How To Secure A Linux Server

An evolving how-to guide for securing a Linux server.

In 7 listsDetails

NIST IoT Cybersecurity Framework

NIST SP 800-213 - IoT Device Cybersecurity Guidance

NISTIR 8259 - Foundational Cybersecurity Activities for IoT Manufacturers

ETSI EN 303 645 - Cyber Security for Consumer IoT

OWASP IoT Top 10 (2018)

OWASP IoT Project

IoT common vulnerabilities and attack surfaces.

In 2 lists

IoT Device Hardening Best Practices

Embedded Linux Hardening

In 2 lists

Zephyr RTOS Security Features

Defensive Security >Incident Response

IoT Forensics and Incident Response

Embedded Device Forensics

Learning Resources >Training Platforms

OpenSecurityTraining2

cryptopals

.

In 3 lists

Learning Resources >Cheatsheets

Hardware Hacking Cheatsheet

Nmap Tutorial

Pentest Hardware Handbook

THC's favourite Tips, Tricks & Hacks

Various tips & tricks

In 3 lists

Cross Cache Attack CheetSheet

In 2 lists

Learning Resources >Vulnerability Guides

OWASP IoT Top 10 2018 Mapping

Reflecting on OWASP IoT Top 10

CVE North Stars

In 2 lists

IoT Vulnerabilities with CVE and PoC

Linux Privilege Escalation

In 2 lists

Learning Resources >Pentesting Guides

Shodan Pentesting Guide

Modern Vulnerability Research on Embedded Systems

Awesome Embedded Systems Vulnerability Research

Learning Resources >YouTube Channels

Joe Grand

LiveOverflow

Video tutorials on Exploitation.

In 3 lists

Binary Adventure

EEVBlog

One of the earliest and most successful YouTube channels where Dave Jones does teardowns, tutorials and more.

In 2 lists

Craig Smith

IoTSecurity101

Besim ALTINOK

Ghidra Ninja

Cyber Gibbons

Scanline

Aaron Christophel

Valerio Di Giampietro

Gamozo Labs - Printer Hacking

Learning Resources >Books

The Hardware Hacking Handbook - Jasper van Woudenberg & Colin O'Flynn (2021)

Practical Hardware Pentesting - Jean-Georges Valle (2021)

Practical Hardware Pentesting 2nd Edition (2023)

Hardware Hacking: Have Fun While Voiding Your Warranty - Joe Grand (2004)

Hacking the Xbox - Andrew "bunnie" Huang (2013)

The Hardware Hacker - Andrew "bunnie" Huang (2019)

The Art of PCB Reverse Engineering - Keng Tiong (2015)

Manual PCB-RE: The Essentials - Keng Tiong (2021)

Hardware Security Training, Hands-on! (2023)

Hardware Security: Challenges and Solutions (2025)

Mastering Hardware Hacking (2025)

Ultimate Hardware Hacking Gear Guide

Microcontroller Exploits (2024)

Engineering Secure Devices - Dominik Merli (2024)

Cryptography and Embedded Systems Security - Hou & Breier (2024)

The Firmware Handbook - Jack Ganssle (2004)

Learning Linux Binary Analysis - Ryan O'Neill (2016)

Fuzzing Against the Machine (2023)

Rootkits and Bootkits - Matrosov, Rodionov, Bratus (2019)

Ghidra Software Reverse Engineering 2nd Edition (2025)

The Ghidra Book 2nd Edition - Nance & Eagle (2026)

The Definitive Handbook on Reverse Engineering Tools (2025)

x86 Software Reverse-Engineering, Cracking, and Counter-Measures - Domas & Domas (2024)

Fuzzing Android - Zawawy, Rodionov et al. (2026)

From Day Zero to Zero Day - Eugene Lim (2025)

The Spacecraft Hacker's Handbook - Olchawa & Starcik (2026)

Abusing the Internet of Things - Nitesh Dhanjani (2015)

IoT Penetration Testing Cookbook - Aaron Guzman & Aditya Gupta (2017)

Practical IoT Hacking: The Definitive Guide (2021)

PatrIoT: Practical and Agile Threat Research for IoT (2022)

The Embedded Linux Security Handbook - St. Onge & Krishnan (2025)

Securing Smart Things - Massimo Nardone (2026)

Inside Radio: An Attack and Defense Guide - Qing Yang, Lin Huang (2018)

Hack the Airwaves: Advanced BLE Exploitation (2023)

Practical SDR - David Clark & Paul Clark (2025)

The Art of ARM Assembly, Volume 1 - Randall Hyde (2025)

The Wireless Cookbook - Bill Zimmerman (2026)

Linksys WRT54G Ultimate Hacking - Paul Asadoorian (2007)

Near Field Communication (NFC): From Theory to Practice (2012)

Security Issues in Mobile NFC Devices - Michael Roland (2024)

The Car Hacker's Handbook - Craig Smith (2016)

In 2 lists

Building Secure Automotive IoT Applications - Oka et al. (2024)

Offensive Automotive Cybersecurity - Nasser & Oka (2025)

Gray Hat Hacking 5th Edition (2018)

Black Hat Python 2nd Edition (2021)

Attacking Network Protocols - James Forshaw (2017)

A Hacker's Guide to Capture, Analysis, and Exploitation by James Forshaw.

In 2 lists

Securing Industrial Control Systems - Rahman et al. (2026)

IOActive: State of Silicon Chip Hacking 2025

Learning Resources >IoT Series

IoT Series I-IV

In 2 lists

Intro to Embedded RE Series

In 2 lists

Labs and CTFs >Vulnerable Applications

DVID - Damn Vulnerable IoT Device

Damn Vulnerable IoT Device

In 2 lists

IoTGoat - Vulnerable OpenWrt Firmware

IoTGoat is a deliberately insecure firmware based on OpenWrt.

In 2 lists

BLE CTF

Microcorruption

ARM-X CTF

Hardware Hacking 101

Workshop @ BSides Munich 2019.

In 2 lists

Damn Vulnerable Safe

Sticky Fingers DV-Pi

Damn Vulnerable Chemical Process

Damn Vulnerable SS7 Network

Hacklab VulnVoIP

Labs and CTFs >CTF Competitions

RHme Series (2015-2017)

First riscure Hack me hardware CTF challenge.

In 2 lists

IoT Village CTF

In 2 lists

RHme-2016

Riscure Hack me 2 is a low level hardware CTF challenge.

In 2 lists

RHme-2017

Riscure Hack Me 3 embedded hardware CTF 2017-2018.

In 2 lists

Emulate to Exploitate

Azeria Labs ARM Challenges

Labs and CTFs >Continuous Learning Platforms

Hack The Box

An online platform to test and advance your skills in penetration testing and cyber security. Join today and start training in our online labs.

In 7 listsDetails

Root Me

Hundreds of challenges are available to train yourself in different and not simulated environments

In 6 listsDetails

Pwnable.kr

CTFtime

Directory of upcoming and archive of past Capture The Flag (CTF) competitions with links to challenge writeups.

In 5 listsDetails

Labs and CTFs >Lab Setup

Webthings Gateway - Raspberry Pi

Research and Community >Technical Research

Dropcam Hacking

LED Light Hacking

PS4 Jailbreak Status

Lenovo Watch X Privacy Issues

Smart Scale Privacy Issues

Besder IP Camera Security Analysis

Research and Community >Blogs

Team82 Research

In 2 lists

Voidstarsec

wrongbaud

In 2 lists

Firmware Analysis

Exploitee.rs

In 2 lists

Payatu Blog

In 2 lists

Raelize Blog

JCJC Dev

In 2 lists

W00tsec

Devttys0

Embedded Bits

Keenlab

Courk.cc

IoT Security Wiki

Cybergibbons

Firmware.RE

K3170makan

Tclaverie

Besimaltinok

Ctrlu

IoT Pentest

Duo Decipher

Sp3ctr3

0x42424242

Dantheiotman

Danman

Quentinkaiser

Quarkslab

In 2 lists

Ice9

F-Secure Labs

MG.lol

CJHackerz

Bunnie's Blog

Synacktiv Publications

Cr4.sh

Ktln2

Naehrdine

Limited Results

Fail0verflow

Exploit Security

Attify Blog

In 2 lists

Jilles.com

Syss Tech Blog

HardBreak Wiki

8ksec

Starlabs

boschko.ca

0xtriboulet

In 2 lists

Nozomi Networks

Research and Community >Community Platforms

IoTSecurity101 Telegram

IoTSecurity101 Reddit

Hardware Hacking Telegram

Research and Community >Villages

RF Hackers

Research and Community >Researchers to Follow

Jilles

Joe Fitz

Aseem Jakhar

Cybergibbons

Jasper

Dave Jones

bunnie

Ilya Shaposhnikov

Mark C.

Aaron Guzman

Yashin Mehaboobe

Arun Magesh

Mr-IoT

QKaiser

9lyph

Research and Community >Device-Specific Research

ARLO: I'M WATCHING YOU

In 2 lists

Hacking a Tapo TC60 Camera

In 2 lists

Rooting a Hive Camera

In 2 lists

Pwn2Own: Synology BC500 IP Camera

In 2 lists

Turning Camera Surveillance on its Axis

In 2 lists

Pwn2Own Ireland 2024 - Ubiquiti AI Bullet

In 2 lists

Hacking a Smart Home Device

In 2 lists

The Silent Spy Among Us: Smart Intercom Attacks

In 2 lists

Pwnassistant - Home Assistant RCE

In 2 lists

Hacking Sonoff Smart Home IoT Device

In 2 lists

Turning Google smart speakers into wiretaps for $100k

In 2 lists

Smart Speaker Shenanigans: Making the Sonos ONE Sing its Secrets

Listen Up: Sonos Over-The-Air Remote Kernel Exploitation and Covert Wiretap

In 2 lists

Streaming Zero-Fi Shells to Your Smart Speaker

In 2 lists

Pwning a Brother labelmaker, for fun and interop!

In 2 lists

lexmark printer haxx

In 2 lists

Pwn2Own Ireland 2024: Canon imageCLASS MF656Cdw

In 2 lists

Print Scan Hacks: Brother devices

In 2 lists

DJI Mavic 3 Drone Research: Firmware Analysis

In 2 lists

DJI Mavic 3 Drone Research: Vulnerability Analysis

In 2 lists

DJI - The ART of obfuscation

In 2 lists

Local Privilege Escalation on the DJI RM500 Smart Controller

In 2 lists

Let Me Cook You a Vulnerability: Exploiting the Thermomix TM5

In 2 lists

A Pain in the NAS: Synology DS920+ Edition

In 2 lists

Weekend Destroyer - RCE in Western Digital PR4100 NAS

In 2 lists

Exploiting the Synology TC500 at Pwn2Own Ireland 2024

In 2 lists

Hacking the Nintendo DSi Browser

In 2 lists

mast1c0re: Exploiting the PS4 and PS5 through a game save

In 2 lists

Being Overlord on the Steam Deck with 1 Byte

In 2 lists

Hacking the XBox 360 Hypervisor

In 2 lists

Pixel 6 Bootloader Series

In 2 lists

Solo: A Pixel 6 Pro Story

In 2 lists

Gaining kernel code execution on an MTE-enabled Pixel 8

In 2 lists

Bypassing MTE with CVE-2025-0072

In 2 lists

Debugging the Pixel 8 kernel via KGDB

In 2 lists

A First Glimpse of the Starlink User Terminal

In 2 lists

Diving into Starlink's User Terminal Firmware

In 2 lists

Research and Community >TrustZone and TEE Research

ARM TrustZone: pivoting to the secure world

In 2 lists

TEE Reversing

In 2 lists

A Deep Dive into Samsung's TrustZone - Parts 1-3

Researching Xiaomi's TEE

In 2 lists

Kinibi TEE: Trusted Application Exploitation

In 2 lists

Reversing Samsung's H-Arx Hypervisor Framework

In 2 lists

EL3vated Privileges: Glitching Google WiFi Pro from Root to EL3

In 2 lists

Research and Community >Pwn2Own Research

Your not so "Home Office" - SOHO Hacking at Pwn2Own

Pwn2Own Toronto 2023 Series - Parts 1-5

In 2 lists

Pwn2Own: WAN-to-LAN Exploit Showcase

In 2 lists

MCP / AI Agent >Bluetooth Reverse Engineering

bt-re-mad-skillz

LLM skills for Bluetooth Controller firmware RE at the HCI layer, for Claude Code and ChatGPT/Codex.

See category
94

Awesome-Selfhosted

awesome-selfhosted/awesome-selfhosted

A list of Free Software network services and web applications which can be hosted on your own servers

Fresh★ 323k1312 entriesPushed today
91

Awesome Hacker Search Engines

edoardottt/awesome-hacker-search-engines

A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more

Fresh★ 11k574 entriesPushed today
91

Awesome Privacy

lissy93/awesome-privacy

🦄 A curated list of privacy & security-focused software and services

Fresh★ 9.9k459 entriesPushed today
89

Awesome Bug Bounty Tools

vavkamil/awesome-bugbounty-tools

A curated list of various bug bounty tools

Fresh★ 6.3k400 entriesPushed yesterday
88

android-security-awesome

ashishb/android-security-awesome

A collection of android security related resources

Fresh★ 9.7k233 entriesPushed 2 days ago
87

Awesome Web Security

qazbnm456/awesome-web-security

🐶 A curated list of Web Security materials and resources.

Fresh★ 14k368 entriesPushed 15 days ago