EXPLIoT
Pentest framework like Metasploit but specialized for IoT.
A curated list of awesome embedded and IoT security resources.
This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.
Pentest framework like Metasploit but specialized for IoT.
Full-featured static analysis framework including extraction of firmware, analysis utilizing different plug-ins and comparison of different firmware versions.
Conference talk about FACT :tv:.
Analyze security of firmware based on customized rules. Intended as additional step in DevSecOps, similar to CI.
A comprehensive reverse engineering and manipulation framework for gate-level netlists.
Swiss Army Knife for Pentesting of IoT Devices.
Framework for automatisation of IoT layers security analysis: hardware, software and communication.
Framework for Testing & Auditing ZigBee and IEEE 802.15.4 Networks.
Printer Exploitation Toolkit.
Framework dedicated to exploit embedded devices.
Searches a binary for "interesting" stuff, as well as extracts arbitrary files.
Finds vulnerable patterns in binary executables - ELF support for x86, ARM, and MIPS, experimental bare-metal support.
Analyze Linux-based firmware of embedded devices.
Tries to emulate and pentest a firmware.
Searches extracted firmware images for interesting files and information.
Discovering vulnerabilities in firmware through concolic analysis and function clustering.
Software Reverse Engineering suite; handles arbitrary binaries, if you provide CPU architecture and endianness of the binary.
Software Reverse Engineering framework, also handles popular formats and arbitrary binaries, has an extensive command line toolset.
Searches extracted firmware images for interesting files and information.
Detects container format automatically and executes the corresponding extraction tool.
Extraction tools for several container formats.
Collection of tools for manipulating EPROM files (can convert lots of binary formats).
Set of tools for security testing of Internet of Things devices using specific network IoT protocols.
Low-level NAND Flash dump and parsing utility.
Tool for detecting, reading, writing, verifying and erasing flash chips.
Decrypt Samsung SSD firmware updates.
Detects and interacts with hardware debug ports like UART and JTAG.
Detects and interacts with hardware debug ports like UART and JTAG.
Detects and interacts with hardware debug ports like UART and JTAG. Among other protocols.
Detects JTAG Pinouts fast.
Easy to use Logic Analyzer that support many protocols :euro:.
Alternative to Saleae logic analyzers :euro:.
Open source multi-tool hardware similar to the BusPirate but with NFC capabilities.
Detects Glitch/Side-channel attacks.
Tool for exploring and debugging different digital interfaces.
J-Link offers USB powered JTAG debug probes for multiple different CPU cores :euro:.
Open source 2.4 GHz wireless development platform suitable for Bluetooth experimentation.
Easy to use Bluetooth Low Energy sniffer.
ZigBee security research hardware for learning about and evaluating the security of IEEE 802.15.4/ZigBee systems. Killerbee compatible.
Low Cost Battery Operated Wireless Arduino Board that can be turned into a IEEE 802.15.4 protocol sniffer.
Cheapest SDR for beginners. It is a computer based radio scanner for receiving live radio signals frequencies from 500 kHz up to 1.75 GHz.
Software Defined Radio peripheral capable of transmission or reception of radio signals from 1 MHz to 6 GHz (half-duplex).
Half-duplex sub-1 GHz wireless transceiver.
Software Defined Radio peripheral capable of transmission or reception of radio signals from 100 KHz to 3.8 GHz (full-duplex).
Software Defined Radio peripheral capable of transmission or reception of radio signals from 47 MHz to 6 GHz (full-duplex).
Software Defined Radio peripheral capable of transmission or reception of radio signals from 70 MHz to 6 GHz (full-duplex).
Powerful general purpose RFID tool. From Low Frequency (125kHz) to High Frequency (13.56MHz) tags.
Programmable, portable tool for NFC security analysis.
Powerful 13.56MHz RFID / NFC platform. Read / write / crack / sniff / emulate.
Conference talk presenting several real world examples on real bad implementations :tv:.
Introduction to PS4's security.
CSAW 2019 Embedded Security Challenge (ESC).
Microcorruption: Embedded Security CTF.
Workshop @ BSides Munich 2019.
IoTGoat is a deliberately insecure firmware based on OpenWrt.
First riscure Hack me hardware CTF challenge.
Riscure Hack me 2 is a low level hardware CTF challenge.
Riscure Hack Me 3 embedded hardware CTF 2017-2018.
All things printer.
Development best practices and list of hardware and software tools.
IoT common vulnerabilities and attack surfaces.
Default login credential database sorted by manufacturer.
A Wiki/Archive of all things IC reversing.
Probably the most popular blog covering electronics and hardware hacking with a whole staff of writers.
Miscellaneous ARM related Tutorials.
A walkthrough covering UART and JTAG bypassing a protected login shell.
Detailed tutorial about how to spot debug pads on a PCB.
An in depth explanation of the UART protocol.
A duo of hackers explaining their step by step approach to finding and exploiting vulnerabilities in embedded devices.
Reverse engineering and hardware hacking of embedded devices.
EU, The Hague, September.; USA, Santa Clara, June.
awesome-selfhosted/awesome-selfhosted
A list of Free Software network services and web applications which can be hosted on your own servers
edoardottt/awesome-hacker-search-engines
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
lissy93/awesome-privacy
🦄 A curated list of privacy & security-focused software and services
vavkamil/awesome-bugbounty-tools
A curated list of various bug bounty tools
ashishb/android-security-awesome
A collection of android security related resources
qazbnm456/awesome-web-security
🐶 A curated list of Web Security materials and resources.