A curated list of awesome embedded and IoT security resources.
Go to file
2019-07-31 09:14:27 +02:00
.gitattributes awesome embedded and iot security init 2019-07-26 09:22:29 +02:00
.gitignore awesome embedded and iot security init 2019-07-26 09:22:29 +02:00
.travis.yml awesome embedded and iot security init 2019-07-26 09:22:29 +02:00
code-of-conduct.md awesome embedded and iot security init 2019-07-26 09:22:29 +02:00
contributing.md awesome embedded and iot security init 2019-07-26 09:22:29 +02:00
LICENSE LICENSE File added 2019-07-26 09:41:47 +02:00
package.json awesome embedded and iot security init 2019-07-26 09:22:29 +02:00
readme.md Fixed Trainings headline, removed amazon links whenever possible, removed rather outdated books 2019-07-31 09:14:27 +02:00

Awesome Embedded and IoT Security Awesome

A curated list of awesome resources about embedded and IoT security. The list contains software and hardware tools, books, research papers and more.

If you are a beginner, you should have a look at the Books and Case Studies sections.
If you want to start right away with your own analysis, you should give the Analysis Frameworks a try. They are easy to use and you do not need to be an expert to get first meaningful results.

Contents

Software Tools

Software tools for analyzing embedded/IoT firmware.

Analysis Frameworks

  • FACT - The Firmware Analysis and Comparison Tool - Full-featured static analysis framework including extraction of firmware, analysis utilizing different plug-ins and comparison of different firmware versions.
  • EXPLIoT - Pentest framework like Metasploit but specialized for IoT.

Analysis Tools

  • Binwalk - Searches a binary for "interesting" stuff.
  • Firmadyne - Tries to emulate and pentest a firmware.
  • firmwalker - Searches extracted firmware images for interesting files and information.
  • Ghidra - Software Reverse Engineering suite; handles arbitrary binaries, if you provide CPU architecture and endianness of the binary.
  • Trommel - Searches extracted firmware images for interesting files and information.

Support Tools

  • JTAGenum - Add JTAG capabilities to an Arduino
  • OpenOCD - Free and Open On-Chip Debugging, In-System Programming and Boundary-Scan Testing

Extraction Tools

  • Binwalk - Extracts arbitrary files utilizing a carving approach.
  • FACT Extractor - Detects container format automatically and executes the corresponding extraction tool.
  • Firmware Mod Kit - Extraction tools for several container formats.

Hardware Tools

  • Bus Blaster - Detects and interacts with hardware debug ports like UART and JTAG.
  • Bus Pirate - Detects and interacts with hardware debug ports like UART and JTAG.
  • JTAGULATOR - Detects JTAG Pinouts fast.
  • Saleae - Easy to use Logic Analyzer that support many protocols. 💶
  • Ikalogic - Alternative to Saleae logic analyzers
  • HydraBus - Open source multi-tool hardware similar to the BusPirate but with NFC capabilities
  • ChipWhisperer - Detects Glitch/Side-channel attacks
  • Glasgow - Tool for exploring and debugging different digital interfaces
  • J-Link - J-Link offers USB powered JTAG debug probes for multiple different CPU cores

Books

Research Papers

Case Studies

Free Trainings

Websites

Conferences

Contribute

Contributions welcome! Read the contribution guidelines first.

License

CC0

To the extent possible under law, Fraunhofer FKIE has waived all copyright and related or neighboring rights to this work.