{"id":91168,"url":"https://github.com/V33RU/awesome-connected-things-sec","name":"awesome-connected-things-sec","description":"A Curated list of Security Resources for all connected things","projects_count":906,"last_synced_at":"2026-08-23T01:00:30.734Z","repository":{"id":40669560,"uuid":"133933655","full_name":"V33RU/awesome-connected-things-sec","owner":"V33RU","description":"A Curated list of Security Resources for all connected things","archived":false,"fork":false,"pushed_at":"2026-08-17T21:45:10.000Z","size":47692,"stargazers_count":3514,"open_issues_count":0,"forks_count":585,"subscribers_count":109,"default_branch":"main","last_synced_at":"2026-08-18T05:56:20.721Z","etag":null,"topics":["automotive-security","awesome","awesome-list","ble-security","bluetooth-security","embedded-security","firmware-analysis","firmware-security","hardware-hacking","ics-security","iot-pentesting","iot-security","reverse-engineering","rf-security","wireless-security"],"latest_commit_sha":null,"homepage":"https://v33ru.github.io/awesome-connected-things-sec/","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"cc0-1.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/V33RU.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"claude":null,"gemini":null,"cursor":null,"copilot":null,"dco":null,"cla":null,"disclosure":null},"funding":{"buymecoffee":null,"ko_fi":null}},"created_at":"2018-05-18T09:31:21.000Z","updated_at":"2026-08-17T21:45:17.000Z","dependencies_parsed_at":"2026-08-10T13:27:01.733Z","dependency_job_id":null,"html_url":"https://github.com/V33RU/awesome-connected-things-sec","commit_stats":null,"previous_names":["v33ru/awesome-connected-things-sec","v33ru/iotsecurity101"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/V33RU/awesome-connected-things-sec","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/V33RU%2Fawesome-connected-things-sec","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/V33RU%2Fawesome-connected-things-sec/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/V33RU%2Fawesome-connected-things-sec/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/V33RU%2Fawesome-connected-things-sec/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/V33RU","download_url":"https://codeload.github.com/V33RU/awesome-connected-things-sec/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/V33RU%2Fawesome-connected-things-sec/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36838003,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-22T15:14:58.755Z","status":"ssl_error","status_checked_at":"2026-08-22T15:14:58.237Z","response_time":51,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"created_at":"2025-07-08T12:02:00.082Z","updated_at":"2026-08-23T01:00:30.735Z","primary_language":null,"list_of_lists":false,"displayable":true,"categories":["Industrial and Automotive","Tools","Firmware Security","Network and Web Protocols","Labs and CTFs","Wireless Protocols","🗂️ Resource Index","Mobile Application Security","Learning Resources","Defensive Security","Research and Community","Hardware Attacks","Cloud and Backend Security","Payment Systems","MCP / AI Agent"],"sub_categories":["Automotive Security","Pentesting Operating Systems","Reverse Engineering Tools","Online Assemblers","Hardware Tools","mTLS","Search Engines","Dynamic Analysis and Emulation","MQTT","Continuous Learning Platforms","Bluetooth / BLE","Wi-Fi","iOS","Books","Android","Secure Boot","Secure Development","Blogs","Binary Analysis","CTF Competitions","Vulnerable Applications","Interface Attacks","Threat Modeling","ARM Exploitation","Lab Setup","Introduction","CoAP","Matter / Thread","AWS IoT Security","ICS/SCADA","Router Exploitation","Router Firmware Analysis","Device-Specific Research","IoT Series","UEFI Security","IoT Protocols Overview","Side-Channel and Fault Injection","Fuzzing Tools","Vulnerability Guides","USB","Technical Research","Community Platforms","Training Platforms","Fundamentals","RF Fundamentals","Cellular Hacking GSM BTS","Cellular (GSM/LTE/5G)","Zigbee / Z-Wave","Payment Village","Villages","Static Analysis Tools","Extraction","Symlink Attacks","Memory Extraction","Storage Medium","ATM Hacking","IoT hardware Overview and Hacking","Pentesting Guides","Researchers to Follow","NFC/RFID","Pwn2Own Research","Secure Boot Bypasses","Cheatsheets","RTOS Security","Pentesting Firmwares and emulating and analyzing","Software Tools","Exploitation Tools","LoRa / LoRaWAN","TrustZone and TEE Research","Technical Research and Hacking","Books for IoT Penetration Testing","IoT Web and Message Services","Zigbee ALL Stuff","Blogs for IoT Pentest","BLE Intro and SW-HW Tools to pentest","TETRA","PCIe and DMA Attacks","DECT (Digital Enhanced Cordless Telecommunications)","UWB (Ultra-Wideband)","OTA Update Security","Firebase / Cloud Misconfigurations","EV Chargers","Incident Response","YouTube Channels","Bluetooth Reverse Engineering"],"readme":"\u003ch1 align=\"center\"\u003e🔐 Awesome Connected Things Security Resources\u003c/h1\u003e\n\u003cp align=\"center\"\u003eSecurity research and exploitation techniques for IoT, embedded, industrial, and automotive systems.\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"https://github.com/V33RU/awesome-connected-things-sec\"\u003e\n    \u003cimg src=\"/docs/images/banner.png\" width=\"900\"/\u003e\n  \u003c/a\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"https://awesome.re\"\u003e\u003cimg src=\"https://awesome.re/badge-flat2.svg\" alt=\"Awesome\"\u003e\u003c/a\u003e\n  \u003cimg src=\"https://img.shields.io/github/stars/V33RU/awesome-connected-things-sec?style=flat-square\u0026logo=github\u0026label=Stars\u0026color=gold\"/\u003e\n  \u003cimg src=\"https://img.shields.io/github/forks/V33RU/awesome-connected-things-sec?style=flat-square\u0026logo=git\u0026label=Forks\u0026color=blue\"/\u003e\n  \u003cimg src=\"https://img.shields.io/github/license/V33RU/awesome-connected-things-sec?style=flat-square\u0026label=License\u0026color=green\"/\u003e\n  \u003cimg src=\"https://img.shields.io/github/last-commit/V33RU/awesome-connected-things-sec?style=flat-square\u0026label=Updated\u0026color=red\"/\u003e\n  \u003cimg src=\"https://img.shields.io/badge/Resources-900%2B-blueviolet?style=flat-square\"/\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003cimg src=\"https://readme-typing-svg.demolab.com?font=Fira+Code\u0026weight=600\u0026size=22\u0026pause=1000\u0026color=58A6FF\u0026center=true\u0026vCenter=true\u0026random=false\u0026width=600\u0026lines=Firmware+%E2%80%A2+Wireless+%E2%80%A2+Hardware+%E2%80%A2+Protocols;UART+%E2%86%92+JTAG+%E2%86%92+SWD+%E2%86%92+Firmware+%E2%86%92+Root;Hack+The+Planet%2C+One+Device+At+A+Time\" alt=\"Typing SVG\" /\u003e\n\u003c/p\u003e\n\n\u003cbr/\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"https://github.com/V33RU/awesome-connected-things-sec/blob/main/docs/ICS/Industrial-Control-Systems.md\"\u003e\u003cimg src=\"https://img.shields.io/badge/🏭_ICS-SCADA_\u0026_OT-ff6b6b?style=for-the-badge\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://github.com/V33RU/awesome-connected-things-sec/blob/main/docs/Automotive/automotive-security.md\"\u003e\u003cimg src=\"https://img.shields.io/badge/🚗_AUTO-CAN_\u0026_ECU-4ecdc4?style=for-the-badge\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://github.com/V33RU/awesome-connected-things-sec/blob/main/docs/Robotics/robotics-security.md\"\u003e\u003cimg src=\"https://img.shields.io/badge/🤖_ROBOTICS-ROS_\u0026_DDS-8b5cf6?style=for-the-badge\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://github.com/V33RU/awesome-connected-things-sec/blob/main/docs/awesome-collection.md\"\u003e\u003cimg src=\"https://img.shields.io/badge/📚_AWESOME-COLLECTION-a855f7?style=for-the-badge\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://github.com/V33RU/awesome-connected-things-sec/blob/main/contributing.md\"\u003e\u003cimg src=\"https://img.shields.io/badge/🤝_CONTRIBUTE-JOIN_US-f59e0b?style=for-the-badge\"/\u003e\u003c/a\u003e\n\u003c/p\u003e\n\n\u003cbr/\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"#hardware-attacks\"\u003e\u003cimg src=\"https://img.shields.io/badge/⚡_Hardware-Hacking-dc2626?style=flat-square\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"#bluetooth--ble\"\u003e\u003cimg src=\"https://img.shields.io/badge/📶_Bluetooth-BLE-2563eb?style=flat-square\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"#firmware-security\"\u003e\u003cimg src=\"https://img.shields.io/badge/💾_Firmware-Analysis-16a34a?style=flat-square\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"#wireless-protocols\"\u003e\u003cimg src=\"https://img.shields.io/badge/📡_Wireless-Protocols-9333ea?style=flat-square\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"#tools\"\u003e\u003cimg src=\"https://img.shields.io/badge/🛠️_Tools-Arsenal-ea580c?style=flat-square\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"#labs-and-ctfs\"\u003e\u003cimg src=\"https://img.shields.io/badge/🎮_Labs-CTFs-0891b2?style=flat-square\"/\u003e\u003c/a\u003e\n\u003c/p\u003e\n\n\u003cbr/\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"https://t.me/iotsrg\"\u003e\u003cimg src=\"https://img.shields.io/badge/Telegram-26A5E4?style=for-the-badge\u0026logo=telegram\u0026logoColor=white\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://discord.gg/EH9dxT9\"\u003e\u003cimg src=\"https://img.shields.io/badge/Discord-5865F2?style=for-the-badge\u0026logo=discord\u0026logoColor=white\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://twitter.com/v33riot\"\u003e\u003cimg src=\"https://img.shields.io/badge/Twitter-1DA1F2?style=for-the-badge\u0026logo=twitter\u0026logoColor=white\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://www.linkedin.com/in/veeraiot\"\u003e\u003cimg src=\"https://img.shields.io/badge/LinkedIn-0A66C2?style=for-the-badge\u0026logo=linkedin\u0026logoColor=white\"/\u003e\u003c/a\u003e\n\u003c/p\u003e\n\n---\n\n## Contents\n\n- [Hardware Attacks](#hardware-attacks)\n  - [Fundamentals](#fundamentals)\n  - [Interface Attacks](#interface-attacks)\n  - [Memory Extraction](#memory-extraction)\n  - [Side-Channel and Fault Injection](#side-channel-and-fault-injection)\n  - [PCIe and DMA Attacks](#pcie-and-dma-attacks)\n- [Wireless Protocols](#wireless-protocols)\n  - [RF Fundamentals](#rf-fundamentals)\n  - [Bluetooth / BLE](#bluetooth--ble)\n  - [Zigbee / Z-Wave](#zigbee--z-wave)\n  - [LoRa / LoRaWAN](#lora--lorawan)\n  - [Matter / Thread](#matter--thread)\n  - [Cellular (GSM/LTE/5G)](#cellular-gsmlte5g)\n  - [NFC/RFID](#nfcrfid)\n  - [DECT (Digital Enhanced Cordless Telecommunications)](#dect-digital-enhanced-cordless-telecommunications)\n  - [Wi-Fi](#wi-fi)\n  - [USB](#usb)\n  - [UWB (Ultra-Wideband)](#uwb-ultra-wideband)\n  - [TETRA](#tetra)\n- [Firmware Security](#firmware-security)\n  - [Fundamentals](#fundamentals-1)\n  - [Extraction](#extraction)\n  - [Static Analysis Tools](#static-analysis-tools)\n  - [Dynamic Analysis and Emulation](#dynamic-analysis-and-emulation)\n  - [OTA Update Security](#ota-update-security)\n  - [RTOS Security](#rtos-security)\n  - [Reverse Engineering Tools](#reverse-engineering-tools)\n  - [Online Assemblers](#online-assemblers)\n  - [ARM Exploitation](#arm-exploitation)\n  - [Binary Analysis](#binary-analysis)\n  - [Secure Boot](#secure-boot)\n  - [UEFI Security](#uefi-security)\n  - [Symlink Attacks](#symlink-attacks)\n  - [Router Firmware Analysis](#router-firmware-analysis)\n  - [Router Exploitation](#router-exploitation)\n  - [Secure Boot Bypasses](#secure-boot-bypasses)\n- [Network and Web Protocols](#network-and-web-protocols)\n  - [MQTT](#mqtt)\n  - [CoAP](#coap)\n  - [mTLS](#mtls)\n  - [IoT Protocols Overview](#iot-protocols-overview)\n- [Cloud and Backend Security](#cloud-and-backend-security)\n  - [AWS IoT Security](#aws-iot-security)\n  - [Firebase / Cloud Misconfigurations](#firebase--cloud-misconfigurations)\n- [Mobile Application Security](#mobile-application-security)\n  - [Android](#android)\n  - [iOS](#ios)\n- [Industrial and Automotive](#industrial-and-automotive)\n  - [ICS/SCADA](#icsscada)\n  - [Automotive Security](#automotive-security)\n  - [EV Chargers](#ev-chargers)\n- [Payment Systems](#payment-systems)\n  - [ATM Hacking](#atm-hacking)\n  - [Payment Village](#payment-village)\n- [Tools](#tools)\n  - [Hardware Tools](#hardware-tools)\n  - [Software Tools](#software-tools)\n  - [Fuzzing Tools](#fuzzing-tools)\n  - [Pentesting Operating Systems](#pentesting-operating-systems)\n  - [Search Engines](#search-engines)\n- [Defensive Security](#defensive-security)\n  - [Threat Modeling](#threat-modeling)\n  - [Secure Development](#secure-development)\n  - [Incident Response](#incident-response)\n- [Learning Resources](#learning-resources)\n  - [Training Platforms](#training-platforms)\n  - [Cheatsheets](#cheatsheets)\n  - [Vulnerability Guides](#vulnerability-guides)\n  - [Pentesting Guides](#pentesting-guides)\n  - [YouTube Channels](#youtube-channels)\n  - [Books](#books)\n  - [IoT Series](#iot-series)\n- [Labs and CTFs](#labs-and-ctfs)\n  - [Vulnerable Applications](#vulnerable-applications)\n  - [CTF Competitions](#ctf-competitions)\n  - [Continuous Learning Platforms](#continuous-learning-platforms)\n  - [Lab Setup](#lab-setup)\n- [Research and Community](#research-and-community)\n  - [Technical Research](#technical-research)\n  - [Blogs](#blogs)\n  - [Community Platforms](#community-platforms)\n  - [Villages](#villages)\n  - [Researchers to Follow](#researchers-to-follow)\n  - [Device-Specific Research](#device-specific-research)\n  - [TrustZone and TEE Research](#trustzone-and-tee-research)\n  - [Pwn2Own Research](#pwn2own-research)\n- [MCP / AI Agent](#mcp--ai-agent)\n  - [Bluetooth Reverse Engineering](#bluetooth-reverse-engineering)\n\n## Hardware Attacks\n\n### Fundamentals\n\n- [IoT Hardware Guide](https://www.postscapes.com/internet-of-things-hardware/)\n- [Intro to Hardware Hacking - Dumping Your First Firmware](https://web.archive.org/web/2021/https://blog.nvisium.com/intro-to-hardware-hacking-dumping-your-first-firmware)\n- [An Introduction to Hardware Hacking](https://securityboulevard.com/2020/09/an-introduction-to-hardware-hacking/)\n- [Hardware Toolkits for IoT Security Analysis](https://web.archive.org/web/2020/https://defcon-nn.ru/0x0B/Hardware%20toolkits%20for%20IoT%20security%20analysis.pdf)\n- [Hardware Hacking for IoT Devices - Offensive IoT Exploitation](https://www.infosecinstitute.com/resources/hacking/hardware-hacking-iot-devices-offensive-iot-exploitation/)\n\n### Interface Attacks\n\n#### UART\n\n- [Identifying UART Interface](https://www.mikroe.com/blog/uart-serial-communication)\n- [Serial Terminal Basics](https://learn.sparkfun.com/tutorials/terminal-basics/all)\n- [Reverse Engineering Serial Ports](https://www.devttys0.com/2012/11/reverse-engineering-serial-ports/)\n- [Intro to Embedded RE: UART Discovery and Firmware Extraction via UBoot](https://voidstarsec.com/blog/uart-uboot-and-usb)\n- [Using UART to Connect to a Chinese IP Cam](https://www.davidsopas.com/using-uart-to-connect-to-a-chinese-ip-cam/)\n- [A Journey into IoT Hardware Hacking: UART](https://techblog.mediaservice.net/2019/03/a-journey-into-iot-hardware-hacking-uart/)\n- [Accessing and Dumping Firmware Through UART](https://www.cyberark.com/resources/threat-research-blog/fantastic-rootkits-and-where-to-find-them-part-1)\n- [UART Connections and Dynamic Analysis on Linksys e1000](https://www.youtube.com/watch?v=ix6rSV2Dj44)\n\n#### JTAG\n\n- [Hardware Hacking 101: Introduction to JTAG](https://www.riverloopsecurity.com/blog/2021/05/hw-101-jtag/)\n- [How to Find the JTAG Interface](https://www.youtube.com/watch?v=_FSM_10JXsM)\n- [Analyzing JTAG](https://nse.digital/pages/guides/hardware/jtag.html)\n- [Bus Pirate JTAG Connections with OpenOCD](https://web.archive.org/web/2020/https://research.kudelskisecurity.com/2014/05/01/jtag-debugging-made-easy-with-bus-pirate-and-openocd/)\n- [Extracting Firmware from External Memory via JTAG](https://www.youtube.com/watch?v=IadnBUJAvks)\n- [The Hitchhacker's Guide to iPhone Lightning and JTAG Hacking](https://media.defcon.org/DEF%20CON%2030/DEF%20CON%2030%20presentations/stacksmashing%20-%20The%20hitchhackers%20guide%20to%20iPhone%20Lightning%20%26%20JTAG%20hacking.pdf)\n- [Debugging AVR Microcontrollers Through JTAG](https://hev0x.github.io/posts/debugging-avr-with-atmelice-and-gdb/)\n\n#### SWD (Serial Wire Debug)\n\n- [SWD Protocol Overview - HardBreak Wiki](https://www.hardbreak.wiki/hardware-hacking/interface-interaction/jtag-swd/swd)\n- [Unveiling Vulnerabilities: Exploring SWD Attack Surface in Hardware](https://web.archive.org/web/2024/https://redfoxsec.com/blog/unveiling-vulnerabilities-exploring-swd-attack-surface-in-hardware/)\n- [Introduction to ARM Serial Wire Debug Protocol](https://developer.arm.com/documentation/ihi0031/a/The-Serial-Wire-Debug-Port--SW-DP-/Introduction-to-the-ARM-Serial-Wire-Debug--SWD--protocol)\n- [Serial Wire Debug and CoreSight Architecture](https://community.nxp.com/pwmxy87654/attachments/pwmxy87654/imxrt/4786/2/Serial_Wire_Debug.pdf)\n- [LibSWD - Serial Wire Debug Open Library](https://github.com/cederom/LibSWD)\n- [Hardware Hacking and Exploitation Bootcamp - SWD](https://happeningnext.com/event/hardware-hacking-and-exploitation-bootcamp-eid4sntq7lbas1)\n\n#### SPI\n\n- [Hardware Hacking 101: Identifying and Dumping eMMC Flash](https://www.riverloopsecurity.com/blog/2020/03/hw-101-emmc/)\n- [Dumping Firmware from Router Using Bus Pirate - SPI](https://www.iotpentest.com/2019/06/dumping-firmware-from-device-using.html)\n- [Extracting Flash Memory over SPI](https://web.archive.org/web/2023/https://akimbocore.com/article/extracting-flash-memory-over-spi/)\n- [Extracting Firmware from Embedded Devices (SPI NOR Flash)](https://www.youtube.com/watch?v=nruUuDalNR0)\n- [How to Flash Chip of a Router with a Programmer](https://www.youtube.com/watch?v=fbt4OJXJdOc)\n- [TPM 2.0: Extracting Bitlocker Keys Through SPI](https://lucasteske.dev/2024/01/tpm2-bitlocker-keys)\n\n#### I2C\n\n- [IoT Security Part 16: Hardware Attack Surface I2C](https://payatu.com/masterclass/iot-security-part-16-101-hardware-attack-surface-i2c/)\n- [I2C Exploitation - HackTricks](https://book.hacktricks.xyz/todo/hardware-hacking/i2c)\n- [Non-invasive I2C Hardware Trojan Attack Vector (PDF)](https://hal.science/hal-03703165/document)\n- [Hardware Hacking: I2C Injection with Bus Pirate](https://www.rockfishsec.com/2014/09/hardware-hacking-i2c-injection-with-bus.html)\n- [Safeguarding SPI, I2C, and I3C Protocols](https://ez.analog.com/ez-blogs/b/engineering-mind/posts/do-your-embedded-systems-safeguard-against-threats-to-spi-i2c-and-i3c)\n\n#### TPM\n\n- [Introduction to TPM (Trusted Platform Module)](https://sergioprado.blog/introduction-to-tpm-trusted-platform-module/)\n- [Trusted Platform Module Security Defeated in 30 Minutes](https://arstechnica.com/gadgets/2021/08/how-to-go-from-stolen-pc-to-network-intrusion-in-30-minutes/)\n\n### Memory Extraction\n\n#### eMMC\n\n- [eMMC Protocol](https://prodigytechno.com/emmc-protocol/)\n- [RPMB: A Secret Place Inside the eMMC](https://sergioprado.blog/rpmb-a-secret-place-inside-the-emmc/)\n- [eMMC Data Recovery from Damaged Smartphone](https://dangerouspayload.com/2018/10/24/emmc-data-recovery-from-damaged-smartphone/)\n- [Unleash Your Smart-Home Devices: Vacuum Cleaning Robot Hacking](https://media.ccc.de/v/34c3-9147-unleash_your_smart-home_devices_vacuum_cleaning_robot_hacking)\n- [Hands-On IoT Hacking: Rapid7 at DEF CON 30](https://www.rapid7.com/blog/post/2022/10/18/hands-on-iot-hacking-rapid7-at-def-con-30-iot-village-part-1/)\n\n### Side-Channel and Fault Injection\n\n#### Fundamentals\n\n- [Side Channel Attacks - Yifan Lu](https://yifan.lu/)\n- [Attacks on Implementations of Secure Systems](https://github.com/Yossioren/AttacksonImplementationsCourseBook)\n- [Fuzzing, Binary Analysis, IoT Security Collection](https://github.com/0xricksanchez/paper_collection)\n\n#### Glitching Attacks\n\n- [NAND Glitching Attack on Wink Hub](https://www.brettlischalk.com/posts/nand-glitching-wink-hub-for-root)\n- [Voltage Glitching with Crowbars Tutorial](https://chipwhisperer.readthedocs.io/en/latest/tutorials.html)\n- [Voltage Glitching Attack using iCEstick Glitcher](https://www.youtube.com/watch?v=FVUhVewFmxw)\n- [FPGA Glitching and Side Channel Attacks - Samy Kamkar](https://www.youtube.com/watch?v=oGndiX5tvEk)\n- [Hardware Power Glitch Attack - rhme2](https://www.youtube.com/watch?v=6Pf3pY3GxBM)\n- [Keys in Flash - Glitching AES Keys from Arduino](https://srfilipek.medium.com/keys-in-a-flash-3e984d0de54b)\n- [Implementing Practical Electrical Glitching Attacks](https://blackhat.com/docs/eu-15/materials/eu-15-Giller-Implementing-Electrical-Glitching-Attacks.pdf)\n- [How to Voltage Fault Injection](https://www.synacktiv.com/publications/how-to-voltage-fault-injection)\n- [Glitcher Part 1 - Reproducible Voltage Glitching on STM32 Microcontrollers](https://sec-consult.com/blog/detail/secglitcher-part-1-reproducible-voltage-glitching-on-stm32-microcontrollers/)\n- [STM32L05 Voltage Glitching](https://blog.syss.com/posts/voltage-glitching-the-stm32l05-microcontroller/)\n\n#### Power Analysis\n\n- [Breaking AES with ChipWhisperer](https://www.youtube.com/watch?v=FktI4qSjzaE)\n- [ChipWhisperer Wiki](https://chipwhisperer.readthedocs.io/)\n- [Rowhammer Bit Flips to Steal Crypto Keys](https://arstechnica.com/information-technology/2019/06/researchers-use-rowhammer-bitflips-to-steal-2048-bit-crypto-key/)\n\n#### Other Microcontrollers\n\n- [Dumping the Amlogic A113X Bootrom](https://haxx.in/posts/dumping-the-amlogic-a113x-bootrom/)\n- [Retreading The AMLogic A113X TrustZone Exploit Process](https://boredpentester.com/retreading-the-amlogic-a113x-trustzone-exploit-process/)\n- [Reverse Engineering an Unknown Microcontroller](https://dmitry.gr/?r=05.Projects\u0026proj=30.%20Reverse%20Engineering%20an%20Unknown%20Microcontroller)\n- [Hacking Microcontroller Firmware Through a USB](https://securelist.com/hacking-microcontroller-firmware-through-a-usb/89919/)\n- [There's A Hole In Your SoC: Glitching The MediaTek BootROM](https://research.nccgroup.com/2020/10/15/theres-a-hole-in-your-soc-glitching-the-mediatek-bootrom/)\n\n### PCIe and DMA Attacks\n\n- [A Practical Tutorial on PCIe for Total Beginners on Windows - Part 1](https://ctf.re/windows/kernel/pcie/tutorial/2023/02/14/pcie-part-1/)\n- [A Practical Tutorial on PCIe for Total Beginners on Windows - Part 2](https://ctf.re/kernel/pcie/tutorial/dma/mmio/tlp/2024/03/26/pcie-part-2/)\n- [PCIe DMA Attack against a Secured Jetson Nano (CVE-2022-21819)](https://www.thegoodpenguin.co.uk/blog/pcie-dma-attack-against-a-secured-jetson-nano-cve-2022-21819/)\n\n\n---\n\n## Wireless Protocols\n\n### RF Fundamentals\n\n- [Complete Course in Software Defined Radio - Michael Ossmann](https://greatscottgadgets.com/sdr/)\n- [Understanding Radio](https://www.taitradioacademy.com/lessons/introduction-to-radio-communications-principals/)\n- [Introduction to Software Defined Radio](https://www.allaboutcircuits.com/technical-articles/introduction-to-software-defined-radio/)\n- [Introduction to GNU Radio Companion](https://wiki.gnuradio.org/index.php/Guided_Tutorial_GRC)\n- [Creating a Flow Graph in GNU Radio Companion](https://blog.didierstevens.com/2017/09/19/quickpost-creating-a-simple-flow-graph-with-gnu-radio-companion/)\n- [Analyzing Radio Signals 433MHz](https://www.rtl-sdr.com/analyzing-433-mhz-transmitters-rtl-sdr/)\n- [Recording Specific Radio Signals](https://www.rtl-sdr.com/freqwatch-rtl-sdr-frequency-scanner-recorder/)\n- [Replay Attacks with Raspberry Pi and rpitx](https://www.rtl-sdr.com/tutorial-replay-attacks-with-an-rtl-sdr-raspberry-pi-and-rpitx/)\n- [Reverse Engineering a Car Key Fob Signal](https://0x44.cc/radio/2024/03/13/reversing-a-car-key-fob-signal.html)\n- [GRCON 2021 - Capture the Signal](https://blog.tclaverie.eu/posts/grcon-2021---capture-the-signal/)\n\n### Bluetooth / BLE\n\n#### Fundamentals\n\n- [Awesome Bluetooth Security](https://github.com/engn33r/awesome-bluetooth-security)\n- [BLE-NullBlr: Step by Step Guide to BLE Understanding and Exploiting](https://github.com/V33RU/BLE-NullBlr)\n- [Traffic Engineering in a Bluetooth Piconet](https://www.diva-portal.org/smash/record.jsf?pid=diva2%3A833159)\n- [BLE Characteristics: A Beginner's Tutorial](https://devzone.nordicsemi.com/nordic/short-range-guides/b/bluetooth-low-energy/posts/ble-characteristics-a-beginners-tutorial)\n- [Intro to Bluetooth Low Energy (PDF)](https://daskalakispiros.com/files/Ebooks/Intro+to+Bluetooth+Low+Energy+v1.1.pdf)\n- [Bluetooth LE Security Study Guide](https://www.bluetooth.com/bluetooth-resources/le-security-study-guide/)\n- [Reverse Engineering BLE Devices](https://reverse-engineering-ble-devices.readthedocs.io/en/latest/)\n- [My Journey Towards Reverse Engineering a Smart Band - Bluetooth-LE RE](https://medium.com/@arunmag/my-journey-towards-reverse-engineering-a-smart-band-bluetooth-le-re-d1dea00e4de2)\n\n#### Exploitation Techniques\n\n- [Intel Edison as Bluetooth LE Exploit Box](https://medium.com/@arunmag/intel-edison-as-bluetooth-le-exploit-box-a63e4cad6580)\n- [Reverse Engineering and Exploiting a Smart Massager](https://medium.com/@arunmag/how-i-reverse-engineered-and-exploited-a-smart-massager-ee7c9f21bf33)\n- [I Hacked MiBand 3](https://medium.com/@yogeshojha/i-hacked-xiaomi-miband-3-and-here-is-how-i-did-it-43d68c272391)\n- [GATTacking Bluetooth Smart Devices](https://securing.pl/en/gattacking-bluetooth-smart-devices-introducing-a-new-ble-proxy-tool/index.html)\n- [Examining the August Smart Lock](https://blog.quarkslab.com/examining-the-august-smart-lock.html)\n- [Practical Introduction to BLE GATT Reverse Engineering](https://jcjc-dev.com/2023/03/19/reversing-domyos-el500-elliptical/)\n- [MojoBox - Yet Another Not So Smartlock](https://mandomat.github.io/2023-03-15-testing-mojobox-security/)\n- [Bluetooth Smartlocks](https://www.getkisi.com/blog/smart-locks-hacked-bluetooth-ble)\n- [Bluetooth Beacon Vulnerability](https://www.beaconzone.co.uk/blog/category/security/)\n- [Denial of Pleasure: Attacking Unusual BLE Targets with a Flipper Zero](https://www.whid.ninja/blog/denial-of-pleasure-attacking-unusual-ble-targets-with-a-flipper-zero)\n- [Grand Theft Auto: A peek of BLE relay attack](https://rollingpwn.github.io/BLE-Relay-Aattck/)\n- [How I Hacked Smart Lights: CVE-2022-47758](https://pwning.tech/cve-2022-47758/)\n\n#### Vulnerability Research\n\n- [Finding Bugs in Bluetooth](https://bluetooth.lol/)\n- [Sweyntooth Vulnerabilities](https://asset-group.github.io/disclosures/sweyntooth/)\n- [BrakTooth: Causing Havoc on Bluetooth Link Manager](https://asset-group.github.io/disclosures/braktooth/)\n- [BLUFFS: Bluetooth Forward and Future Secrecy Attacks (CVE-2023-24023)](https://github.com/francozappa/bluffs)\n- [AirDrop Leak - Sniffing BLE Traffic from Apple Devices](https://github.com/hexway/apple_bleee)\n- [BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution](https://google.github.io/security-research/pocs/linux/bleedingtooth/writeup.html)\n- [BRAKTOOTH: Causing Havoc on Bluetooth Link Manager (PDF)](https://asset-group.github.io/disclosures/braktooth/braktooth.pdf)\n- [Norec Attack: Stripping BLE encryption from Nordic's Library (CVE-2020-15509)](https://infosecwriteups.com/norec-attack-stripping-ble-encryption-from-nordics-library-cve-2020-15509-9798ab893b95)\n- [BlueDucky - HID Injection on Unpatched Android (CVE-2023-45866)](https://github.com/pentestfunctions/BlueDucky)\n- [Microsoft Bluetooth Driver Spoofing - CVE-2024-21306](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21306)\n- [Bluetooth Auracast / LE Audio Security Analysis](https://www.bluetooth.com/learn-about-bluetooth/recent-enhancements/le-audio/)\n\n#### Conference Talks\n\n- [Blue2thprinting: WTF Am I Even Looking At?](https://darkmentor.com/publication/2023-11-hardweario/)\n- [Open Wounds: Last 5 Years Have Left Bluetooth to Bleed](https://darkmentor.com/publication/2023-10-hacklu/)\n- [Sniffing Bluetooth Through My Mask During the Pandemic](https://darkmentor.com/publication/2023-08-hitb/)\n\n#### Tools - Software\n\n- [Bluing - Intelligence Gathering for Bluetooth](https://github.com/fO-000/bluing)\n- [BlueToolkit - Bluetooth Classic Vulnerability Testing](https://github.com/sgxgsx/BlueToolkit)\n- [btproxy](https://github.com/conorpp/btproxy)\n- [hcitool and bluez](https://www.pcsuggest.com/linux-bluetooth-setup-hcitool-bluez)\n- [Testing with GATT Tool](https://www.jaredwolff.com/blog/get-started-with-bluetooth-low-energy/)\n- [crackle - Cracking BLE Encryption](https://github.com/mikeryan/crackle)\n- [bettercap](https://github.com/bettercap/bettercap)\n- [GATTacker](https://github.com/securing/gattacker)\n- [BTLEjack - BLE Swiss Army Knife](https://github.com/virtualabs/btlejack)\n- [DEDSEC Bluetooth Exploit](https://github.com/0xbitx/DEDSEC-Bluetooth-exploit)\n- [BrakTooth ESP32 PoC](https://github.com/Matheus-Garbelini/braktooth_esp32_bluetooth_classic_attacks)\n- [SweynTooth BLE Attacks](https://github.com/Matheus-Garbelini/sweyntooth_bluetooth_low_energy_attacks)\n- [ESP32 Bluetooth Classic Sniffer](https://github.com/Matheus-Garbelini/esp32_bluetooth_classic_sniffer)\n- [Bluetooth Hacking Collection](https://github.com/zedxpace/bluetooth-hacking-)\n\n#### Tools - Hardware\n\n- [nRF52840 Dongle](https://www.nordicsemi.com/Software-and-tools/Development-Kits/nRF52840-Dongle)\n- [Ubertooth One](https://github.com/greatscottgadgets/ubertooth/wiki/Ubertooth-One)\n- [CSR 4.0 Bluetooth Dongle](https://www.amazon.in/GENERIC-Ultra-Mini-Bluetooth-Dongle-Adapter/dp/B0117H7GZ6/)\n- [ESP32](https://www.espressif.com/en/products/hardware/esp32/overview)\n- [Sena UD100](https://web.archive.org/web/2020/http://www.senanetworks.com/ud100-g03.html)\n- [ESP-WROVER-KIT](https://www.digikey.in/en/products/detail/espressif-systems/ESP-WROVER-KIT-VB/8544301)\n\n#### Tools\n\n- [ice9-bluetooth-sniffer](https://github.com/mikeryan/ice9-bluetooth-sniffer)\n- [InternalBlue - Bluetooth Experimentation Framework](https://github.com/seemoo-lab/internalblue)\n\n#### Hacking Bluetooth Coffee Machines\n\n- [Hacking Bluetooth to Brew Coffee from GitHub Actions - Part 1](https://grack.com/blog/2022/12/01/hacking-bluetooth-to-brew-coffee-on-github-actions-part-1/)\n- [Hacking Bluetooth to Brew Coffee from GitHub Actions - Part 2](https://grack.com/blog/2022/12/02/hacking-bluetooth-to-brew-coffee-on-github-actions-part-2/)\n- [Hacking Bluetooth to Brew Coffee from GitHub Actions - Part 3](https://grack.com/blog/2022/12/04/hacking-bluetooth-to-brew-coffee-on-github-actions-part-3/)\n\n### Zigbee / Z-Wave\n\n#### Fundamentals\n\n- [Introduction and Protocol Overview](http://www.informit.com/articles/article.aspx?p=1409785)\n- [ZigBee and Z-Wave Security Brief](http://www.riverloopsecurity.com/blog/2018/05/zigbee-zwave-part1/)\n- [Hacking ZigBee Networks](https://www.infosecinstitute.com/resources/hacking/hacking-zigbee-networks/)\n\n#### Exploitation\n\n- [Hacking IoT Devices with Attify Zigbee Framework](https://blog.attify.com/hack-iot-devices-zigbee-sniffing-exploitation/)\n- [Zigator: Analyzing Security of Zigbee-Enabled Smart Homes](https://mews.sv.cmu.edu/papers/wisec-20.pdf)\n- [Security Analysis of Zigbee with Zigator and GNU Radio](https://mews.sv.cmu.edu/research/zigator/testbed-grcon2020-slides.pdf)\n- [Low-Cost ZigBee Selective Jamming](https://www.bastibl.net/reactive-zigbee-jamming/)\n\n#### Tools - Software\n\n- [Killerbee](https://github.com/riverloopsec/killerbee)\n- [ZigDiggity](https://github.com/BishopFox/zigdiggity)\n- [Zigator](https://github.com/akestoridis/zigator)\n- [Z3sec](https://github.com/IoTsec/Z3sec)\n- [zigbear](https://github.com/philippnormann/zigbear)\n\n#### Tools - Hardware\n\n- [ApiMote](https://www.riverloopsecurity.com/projects/apimote/)\n- [RaspBee](https://phoscon.de/en/raspbee/)\n- [ATUSB IEEE 802.15.4 Adapter](http://shop.sysmocom.de/products/atusb)\n- [USRP](https://www.ettus.com/products/)\n\n### LoRa / LoRaWAN\n\n- [LoRaWAN Security Overview - Tektelic](https://tektelic.com/expertise/lorawan-security/)\n- [Security Vulnerabilities in LoRaWAN](https://www.cyber-threat-intelligence.com/publications/IoTDI2018-LoraWAN.pdf)\n- [Low Powered and High Risk: Attacks on LoRaWAN Devices](https://www.trendmicro.com/en_us/research/21/a/Low-Powered-but-High-Risk-Evaluating-Possible-Attacks-on-LoRaWAN-Devices.html)\n- [LAF - LoRaWAN Auditing Framework](https://github.com/IOActive/laf)\n- [ChirpOTLE - LoRaWAN Security Framework](https://github.com/seemoo-lab/chirpotle)\n\n#### Fundamentals\n\n- [LoRaWAN Security Survey - ScienceDirect](https://www.sciencedirect.com/science/article/abs/pii/S2542660520301359)\n- [LoRaWAN - Wikipedia](https://en.wikipedia.org/wiki/LoRa)\n\n#### Exploitation\n\n- [Millions of Devices Using LoRaWAN Exposed - SecurityWeek](https://www.securityweek.com/millions-devices-using-lorawan-exposed-hacker-attacks/)\n- [Do You Blindly Trust LoRaWAN Networks? - IOActive](https://www.ioactive.com/do-you-blindly-trust-lorawan-networks-for-iot/)\n- [LoRaWAN Encryption Keys Easy to Crack - Threatpost](https://threatpost.com/lorawan-encryption-keys-easy-to-crack-jeopardizing-security-of-iot-networks/152276/)\n- [LoPT: LoRa Penetration Testing Tool (PDF)](https://www.ijitee.org/wp-content/uploads/papers/v8i9S2/I10810789S219.pdf)\n\n#### Tools\n\n- [LoRa Craft - Packet Interception](https://github.com/PentHertz/LoRa_Craft)\n- [Open Source LoRaWAN Hacking Tool](https://www.thethingsnetwork.org/forum/t/open-source-tool-for-hacking-auditing-and-monitoring-lorawan-networks/31185)\n- [LoRaWAN Hackaday Projects](https://hackaday.com/tag/lorawan/)\n\n### Matter / Thread\n\n#### Fundamentals\n\n- [Matter Standard - CSA-IoT](https://csa-iot.org/all-solutions/matter/)\n- [Matter Protocol Wikipedia](https://en.wikipedia.org/wiki/Matter_%28standard%29)\n- [Matter Protocol Complete Guide 2025](https://thinkrobotics.com/blogs/learn/matter-protocol-explained-for-smart-homes-complete-guide-2025)\n- [How to Secure Smart Home Devices with Matter](https://www.iot-now.com/2022/07/12/122292-how-to-secure-smart-home-devices-with-the-matter-standard/)\n- [Smart Home Device Solutions for Matter - DigiCert](https://www.digicert.com/solutions/security-solutions-for-matter-devices)\n\n#### Security Research\n\n- [Security Vulnerabilities and Attack Scenarios in Smart Home with Matter](https://www.ndss-symposium.org/wp-content/uploads/2024/07/sdiotsec2024-48-paper.pdf)\n- [Trust Matters: Uncovering Vulnerabilities in Matter Protocol - Nozomi](https://www.nozominetworks.com/blog/trust-matters-uncovering-vulnerabilities-in-the-matter-protocol)\n- [Matter over Thread Security](https://sensereo.com/community/matter-over-thread-security-how-safe-is-your-smart-home-network/)\n- [State-of-the-Art Review on IoT Wireless PAN Protocol Security](https://www.mdpi.com/2073-8994/12/4/579)\n- [Matter Smart Home - Krasamo](https://www.krasamo.com/matter-smart-home/)\n- [Threadbare: Practical Attacks on Thread Networks (Black Hat USA 2024)](https://www.blackhat.com/us-24/briefings/schedule/#threadbare-practical-attacks-on-thread-networks-39616)\n- [Matter Specification 1.3 - Connectivity Standards Alliance](https://csa-iot.org/developer-resource/specifications-download-request/)\n- [Thread Group Security Analysis](https://www.threadgroup.org/Portals/0/documents/support/ThreadCommissioningWhitePaper_2120.pdf)\n\n### Cellular (GSM/LTE/5G)\n\n- [Awesome Cellular Hacking](https://github.com/W00t3k/Awesome-Cellular-Hacking/)\n- [Introduction to GSM Security](http://www.pentestingexperts.com/introduction-to-gsm-security/)\n- [Breaking LTE on Layer Two](https://alter-attack.net/)\n- [5Ghoul - 5G NR Attacks and Fuzzing](https://github.com/asset-group/5ghoul-5g-nr-attacks)\n- [Exploiting CSN.1 Bugs in MediaTek Basebands](https://labs.taszk.io/articles/post/mtk_baseband_csn1_exploitation/)\n- [SIM Hijacking](https://sensepost.com/blog/2022/sim-hijacking/)\n- [SigPloit - Telecom Signaling Exploitation Framework](https://github.com/SigPloiter/SigPloit)\n- [LTE Sniffer](https://github.com/SysSec-KAIST/LTESniffer)\n- [5G NR Jamming, Spoofing and Sniffing](https://github.com/aligungr/UERANSIM)\n- [LTrack: Stealthy Tracking of Mobile Phones in LTE](https://www.usenix.org/conference/usenixsecurity22/presentation/kotuliak)\n- [Open5GS - Open Source 5G/4G Core](https://github.com/open5gs/open5gs)\n- [SCAT - Signaling Collection and Analysis Tool for Cellular](https://github.com/fgsect/scat)\n\n#### Fundamentals\n\n- [GSM Security Part 2](https://web.archive.org/web/2020/https://www.ehacking.net/2011/02/gsm-security-2.html)\n- [What is Base Transceiver Station](https://en.wikipedia.org/wiki/Base_transceiver_station)\n- [Introduction to SS7 Signaling](https://www.patton.com/whitepapers/Intro_to_SS7_Tutorial.pdf)\n- [SS7 Network Architecture](https://youtu.be/pg47dDUL1T0)\n- [Introduction to SIGTRAN](https://www.youtube.com/watch?v=XUY6pyoRKsg)\n\n#### Exploitation\n\n- [How to Build Your Own Rogue GSM BTS](https://l33t.gg/how-to-build-a-rogue-gsm-bts/)\n- [GSM Vulnerabilities with USRP B200](https://ieeexplore.ieee.org/document/7581461/)\n- [Security Testing 4G (LTE) Networks](https://web.archive.org/web/2018/https://labs.mwrinfosecurity.com/assets/BlogFiles/mwri-44con-lte-presentation-2012-09-11.pdf)\n- [Case Study of SS7/SIGTRAN Assessment](https://nullcon.net/website/archives/pdf/goa-2017/case-study-of-SS7-sigtran.pdf)\n\n#### Tools\n\n- [ss7MAPer - SS7 Pentesting Toolkit](https://n0where.net/ss7-pentesting-toolkit-ss7maper)\n- [Fake BTS Detector (SCL-8521)](https://www.shoghicom.com/fake-bts-detector.php)\n\n### NFC/RFID\n\n- [Awesome RFID/NFC Security Talks](https://github.com/doegox/awesome-rfid-talks)\n- [RFID Discord Group](https://discord.gg/Z43TrcVyPr)\n- [SoK: Security of EMV Contactless Payment Systems](https://arxiv.org/pdf/2504.12812)\n- [NFC Relay Attack on Tesla Model Y](https://act-on.ioactive.com/acton/attachment/34793/f-6460b49e-1afe-41c3-8f73-17dc14916847/1/-/-/-/-/NFC-relay-TESlA_JRoriguez.pdf)\n\n### DECT (Digital Enhanced Cordless Telecommunications)\n\n- [Real Time Interception of DECT Cordless Telephone](https://www.youtube.com/watch?v=MDF1eUvOte0)\n- [Eavesdropping on Unencrypted DECT Voice Traffic](https://www.youtube.com/watch?v=WBvYsXrs3DI)\n- [Decoding DECT Voice Traffic: In-depth Explanation](https://www.youtube.com/watch?v=oiMkirm_xfY)\n\n---\n\n### Wi-Fi\n\n#### Protocol Vulnerabilities\n\n- [Framing Frames: Bypassing Wi-Fi Encryption by Manipulating Transmit Queues](https://papers.mathyvanhoef.com/usenix2023-wifi.pdf)\n- [Man-in-the-Middle Attacks without Rogue AP: When WPAs Meet ICMP Redirects](https://csis.gmu.edu/ksun/publications/WiFi_Interception_SP23.pdf)\n- [WPAxFuzz: Sniffing Out Vulnerabilities in Wi-Fi Implementations](https://www.mdpi.com/2410-387X/6/4/53/)\n- [Untangling the Knot: Breaking Access Control in Home Wireless Mesh Networks](https://www.cs.ucr.edu/%7Ezhiyunq/pub/ccs24_wireless_mesh.pdf)\n\n#### Exploitation\n\n- [Over The Air: Exploiting Broadcom's Wi-Fi Stack (Part 1)](https://googleprojectzero.blogspot.com/2017/04/over-air-exploiting-broadcoms-wi-fi_4.html)\n- [Over The Air: Exploiting Broadcom's Wi-Fi Stack (Part 2)](https://googleprojectzero.blogspot.com/2017/04/over-air-exploiting-broadcoms-wi-fi_11.html)\n- [Over The Air: Exploiting The Wi-Fi Stack on Apple Devices](https://googleprojectzero.blogspot.com/2017/10/over-air-vol-2-pt-3-exploiting-wi-fi.html)\n- [Reverse-engineering Broadcom wireless chipsets](https://blog.quarkslab.com/reverse-engineering-broadcom-wireless-chipsets.html)\n- [Exploiting Qualcomm WLAN and Modem Over the Air](https://i.blackhat.com/USA-19/Thursday/us-19-Pi-Exploiting-Qualcomm-WLAN-And-Modem-Over-The-Air-wp.pdf)\n- [Windows Wi-Fi Driver RCE Vulnerability - CVE-2024-30078](https://www.crowdfense.com/windows-wi-fi-driver-rce-vulnerability-cve-2024-30078/)\n- [When a Wi-Fi SSID Gives You Root on an MT02 Repeater - Part 1](https://chocapikk.com/posts/2025/when-a-wifi-name-gives-you-root/)\n- [When a Wi-Fi SSID Gives You Root on an MT02 Repeater - Part 2](https://chocapikk.com/posts/2025/when-a-wifi-name-gives-you-root-part-two/)\n\n#### Reverse Engineering WiFi\n\n- [Reverse Engineering WiFi on RISC-V BL602](https://lupyuen.github.io/articles/wifi)\n- [Unveiling secrets of the ESP32: creating an open-source MAC Layer](https://zeus.ugent.be/blog/23-24/open-source-esp32-wifi-mac/)\n- [Unveiling secrets of the ESP32: reverse engineering RX](https://zeus.ugent.be/blog/23-24/esp32-reverse-engineering-continued/)\n\n### USB\n\n- [ALL ABOUT USB-C: INTRODUCTION FOR HACKERS](https://hackaday.com/2022/12/06/usb-c-introduction-for-hackers/)\n- [Hi, My Name is Keyboard](https://github.com/skysafe/reblog/blob/main/cve-2024-0230/README.md)\n- [How to Weaponize the Yubikey](https://www.blackhillsinfosec.com/how-to-weaponize-the-yubikey/)\n\n### UWB (Ultra-Wideband)\n\n- [UWB Real Time Locating Systems: How Secure Radio Communications May Fail in Practice](https://uploads-ssl.webflow.com/645a4534705010e2cb244f50/64912bac55ece2717e14e84a_Nozomi-Networks-WP-UWB-Real-Time-Locating-Systems.pdf)\n\n### TETRA\n\n- [All cops are broadcasting: TETRA under scrutiny](https://uploads-ssl.webflow.com/64a2900ed5e9bb672af9b2ed/64d42fcc2e3fdcf3d323f3d9_All_cops_are_broadcasting_TETRA_under_scrutiny.pdf)\n- [TETRA:BURST - Five Vulnerabilities in TETRA Standard (Midnight Blue)](https://tetraburst.com/)\n- [TETRA:BURST 2:ELECTRIC BOOGALOO - End-to-End Encryption Broken (BlackHat USA 2025)](https://www.blackhat.com/us-25/briefings/schedule/index.html#tetraburst)\n- [TETRA Decoder - Open Source TETRA Receiver](https://github.com/sq5bpf/telive)\n- [Practical TETRA Sniffing with SDR](https://github.com/sq5bpf/osmo-tetra-sq5bpf)\n\n---\n\n## Firmware Security\n\n### Fundamentals\n\n- [Introduction to Firmware Analysis - OWASP](https://www.owasp.org/index.php/IoT_Firmware_Analysis)\n- [OWASP Firmware Security Testing Methodology](https://scriptingxss.gitbook.io/firmware-security-testing-methodology/)\n- [IoT Security Verification Standard (ISVS)](https://github.com/OWASP/IoT-Security-Verification-Standard-ISVS)\n- [Reversing 101](https://0xinfection.github.io/reversing/)\n- [Hands-on Firmware Extraction, Exploration, and Emulation](https://github.com/onekey-sec/BHEU23-firmware-workshop)\n\n### Extraction\n\n- [Router Analysis Part 1: UART Discovery and SPI Flash Extraction](https://wrongbaud.github.io/posts/router-teardown/)\n- [Hardware Hacking Tutorial: Dumping and Reversing Firmware](https://ivanorsolic.github.io/post/hardwarehacking1/)\n- [Firmware Samples - firmware.center](https://firmware.center/)\n- [BasicFUN Series: Hardware Analysis / SPI Flash Extraction](https://wrongbaud.github.io/posts/BasicFUN-flashing/)\n- [BasicFUN Series: Reverse Engineering Firmware / Reflashing SPI Flash](https://wrongbaud.github.io/posts/BasicFUN-rom-analysis/)\n- [Retrofitting encrypted firmware is a Bad Idea](https://haxx.in/posts/wtm-wtf/)\n\n### Static Analysis Tools\n\n- [EMBA - Embedded Linux Firmware Analyzer](https://p4cx.medium.com/emba-b370ce503602)\n- [FACT - Firmware Analysis and Comparison Tool](https://github.com/fkie-cad/FACT_core)\n- [Binwalk v3](https://github.com/ReFirmLabs/binwalk)\n- [Firmwalker](https://github.com/craigz28/firmwalker)\n- [fwanalyzer](https://github.com/cruise-automation/fwanalyzer)\n- [fwhunt-scan - UEFI Firmware Analysis](https://github.com/binarly-io/fwhunt-scan)\n- [ByteSweep](https://gitlab.com/bytesweep/bytesweep)\n- [BINSEC](https://github.com/binsec/binsec)\n- [unblob - Extraction Framework](https://github.com/onekey-sec/unblob)\n- [Checksec.sh](https://github.com/slimm609/checksec.sh)\n- [Firmware Modification Kit](https://code.google.com/archive/p/firmware-mod-kit/)\n\n### Dynamic Analysis and Emulation\n\n- [Firmadyne - Automated Firmware Emulation](https://github.com/firmadyne/firmadyne)\n- [FirmAE - Firmware Analysis and Emulation](https://github.com/pr0v3rbs/FirmAE)\n- [QEMU](https://www.qemu.org/)\n- [PANDA - Architecture-Neutral Dynamic Analysis](https://github.com/panda-re/panda)\n- [Avatar2 - Dynamic Firmware Analysis](https://github.com/avatartwo/avatar2)\n- [Renode - Embedded Systems Emulator](https://github.com/renode/renode)\n- [Unicorn Engine - CPU Emulator](https://github.com/unicorn-engine/unicorn)\n- [Qiling Framework](https://github.com/qilingframework/qiling)\n- [HALucinator](https://github.com/embedded-sec/halucinator)\n- [FirmWire - Baseband Firmware Emulation](https://github.com/FirmWire/FirmWire)\n- [SymQEMU](https://github.com/eurecom-s3/symqemu)\n- [S2E - Selective Symbolic Execution](https://github.com/S2E/s2e)\n- [Bochs - x86 Emulator](https://github.com/bochs-emu/Bochs)\n- [SAME70 Emulator](https://www.0x01team.com/sw_security/same70-emulator/)\n- [Emulate Until You Make it](https://www.hexacon.fr/conference/speakers/#draytek)\n\n#### Emulation Tutorials\n\n- [Firmware Emulation with QEMU](https://www.youtube.com/watch?v=G0NNBloGIvs)\n- [Emulating ARM Router Firmware - Azeria Labs](https://azeria-labs.com/emulating-arm-firmware/)\n- [Emulating IoT Firmware Made Easy](https://boschko.ca/qemu-emulating-firmware/)\n- [IoT Binary Analysis and Emulation Part 1](https://hacklido.com/blog/529-iot-binary-analysis-emulation-part-1)\n- [Cross Debugging for ARM/MIPS with QEMU](https://reverseengineering.stackexchange.com/questions/8829/cross-debugging-for-arm-mips-elf-with-qemu-toolchain)\n- [QEMU + Buildroot 101](https://gitbook.seguranca-informatica.pt/arm/tools/qemu-101)\n- [Simulating and Hunting Firmware Vulnerabilities with Qiling](https://blog.vincss.net/2020/12/pt007-simulating-and-hunting-firmware-vulnerabilities-with-Qiling.html)\n- [Qiling and Binary Emulation for Automatic Unpacking](https://kernemporium.github.io/articles/en/auto_unpacking/m.html)\n- [Debugging D-Link: Emulating Firmware and Hacking Hardware](https://www.greynoise.io/blog/debugging-d-link-emulating-firmware-and-hacking-hardware)\n- [Adaptive Emulation Framework for Multi-Architecture IoT](https://www.techscience.com/cmc/v75n2/52069/pdf)\n- [Automatic Firmware Emulation through Invalidity-guided Knowledge Inference](https://www.usenix.org/conference/usenixsecurity21/presentation/zhou)\n- [Emulating RH850 architecture with Unicorn Engine](https://blog.quarkslab.com/emulating-rh850-architecture-with-unicorn-engine.html)\n- [Icicle: A Re-designed Emulator for Grey-Box Firmware Fuzzing](https://arxiv.org/pdf/2301.13346.pdf)\n- [Challenges and Pitfalls while Emulating Six Current Icelandic Household Routers](https://skemman.is/bitstream/1946/50456/1/Challenges_and_Pitfalls_while_Emulating_Six_Current_Icelandic_Household_Routers.pdf)\n- [My Emulation Goes to the Moon... Until False Flag](https://retooling.io/blog/my-emulation-goes-to-the-moon-until-false-flag)\n- [How to Emulate Android Native Libraries Using Qiling](https://www.appknox.com/security/how-to-emulate-android-native-libraries-using-qiling)\n\n### OTA Update Security\n\n#### Fundamentals\n\n- [IoT Firmware Security and Update Mechanisms](https://www.encryptionconsulting.com/iot-firmware-security-and-update-mechanisms-a-deep-dive/)\n- [Implementing OTA Updates for IoT Devices](https://www.kaaiot.com/iot-knowledge-base/implementing-over-the-air-updates-for-iot-devices)\n- [Secure OTA Boot Chains and Firmware Verification](https://promwad.com/news/secure-ota-boot-chains-firmware-verification)\n- [The Key to Firmware Security in Connected IoT Devices](https://www.keyfactor.com/blog/firmware-security-iot-devices/)\n- [Security Considerations for OTA Updates - Stack Overflow](https://stackoverflow.blog/2020/12/14/security-considerations-for-ota-software-updates-for-iot-gateway-devices/)\n\n#### Attack Vectors\n\n- [Top 10 IoT Vulnerabilities - OTA Update Attacks](https://www.keyfactor.com/blog/top-10-iot-vulnerabilities-in-your-devices/)\n- [Updating IoT Devices 2025: Best Practices](https://stormotion.io/blog/updating-iot-devices/)\n- [Review of IoT Firmware Vulnerabilities and Auditing Techniques](https://pmc.ncbi.nlm.nih.gov/articles/PMC10821153/)\n\n### RTOS Security\n\n#### Zephyr RTOS\n\n- [Zephyr RTOS GitHub](https://github.com/zephyrproject-rtos/zephyr)\n- [Zephyr Vulnerabilities List](https://docs.zephyrproject.org/latest/security/vulnerabilities.html)\n- [NCC Group Zephyr and MCUboot Security Assessment](https://www.nccgroup.com/us/research-blog/research-report-zephyr-and-mcuboot-security-assessment/)\n- [26 Flaws in Zephyr and MCUboot](https://web.archive.org/web/2024/https://embeddedcomputing.com/technology/open-source/linux-freertos-related/another-iot-security-uh-oh-26-flaws-in-open-source-zephyr-and-mcuboot-stacks)\n- [Tackling Security in Zephyr RTOS](https://www.electronicdesign.com/technologies/embedded/article/21215503/percepio-tackling-security-and-reliability-in-the-zephyr-rtos)\n- [Enhancing Security with Zephyr RTOS](https://witekio.com/blog/zephyr-rtos-security/)\n\n#### FreeRTOS\n\n- [FreeRTOS 13 Vulnerabilities in TCP/IP Stack](https://hub.packtpub.com/freertos-affected-by-13-vulnerabilities-in-its-tcp-ip-stack/)\n- [Exploiting Memory Corruption in FreeRTOS - ShmooCon](https://shmoo.gitbook.io/2016-shmoocon-proceedings/bring_it_on/01_exploiting_memory_corruption)\n- [RTOS Security Analysis - USENIX](https://www.usenix.org/system/files/usenixsecurity25-shao.pdf)\n- [Dynamic Vulnerability Patching for RTOS](https://www.arxiv.org/pdf/2509.10213)\n- [AWS FreeRTOS Vulnerabilities](https://web.archive.org/web/2022/https://info.cgcompliance.com/blog/vulnerabilities-in-the-aws-iot-platform-you-should-know-about)\n\n### Reverse Engineering Tools\n\n- [Ghidra](https://github.com/NationalSecurityAgency/ghidra)\n- [IDA Pro](https://www.hex-rays.com/products/ida/)\n- [Radare2](https://www.rada.re/n/)\n- [Cutter - GUI for Radare2](https://github.com/rizinorg/cutter)\n- [Binary Ninja](https://binary.ninja/)\n- [GDB](https://www.gnu.org/software/gdb/)\n- [RetDec - Decompiler](https://github.com/avast/retdec)\n- [Diaphora - Binary Diffing](https://github.com/joxeankoret/diaphora)\n- [Angr - Binary Analysis](https://github.com/angr/angr)\n- [Frida - Dynamic Instrumentation](https://github.com/frida/frida)\n- [Ret-sync](https://github.com/bootleg/ret-sync)\n- [OllyDbg](http://www.ollydbg.de/)\n- [x64dbg](https://x64dbg.com/)\n- [Hopper](https://www.hopperapp.com/)\n- [Immunity Debugger](https://web.archive.org/web/2022/https://www.immunityinc.com/products/debugger/)\n- [PEiD](https://www.aldeid.com/wiki/PEiD)\n- [Ghidriff - Ghidra Binary Diffing Engine](https://github.com/clearbluejar/ghidriff)\n- [The rev.ng decompiler goes open source](https://rev.ng/blog/open-sourcing-renvg-decompiler-ui-closed-beta)\n- [Intro to Cutter](https://goggleheadedhacker.com/post/intro-to-cutter)\n- [pyghidra-mcp: Headless Ghidra MCP Server](https://clearbluejar.github.io/posts/pyghidra-mcp-headless-ghidra-mcp-server-for-project-wide-multi-binary-analysis/)\n- [Mindshare: Using Binary Ninja API to Detect Potential Use-after-free Vulnerabilities](https://www.zerodayinitiative.com/blog/2025/3/20/mindshare-using-binary-ninja-api-to-detect-potential-use-after-free-vulnerabilities)\n\n#### Reverse Engineering Tutorials\n\n- [Reverse Engineering and Patching with Ghidra](https://www.coalfire.com/the-coalfire-blog/reverse-engineering-and-patching-with-ghidra)\n- [Reverse Engineering with Ghidra: Breaking Firmware Encryption](https://www.youtube.com/watch?v=4urMITJKQQs)\n- [Reversing Firmware with Radare](https://www.bored-nerds.com/reversing/radare/automotive/2019/07/07/reversing-firmware-with-radare.html)\n- [Reversing ESP8266 Firmware](https://boredpentester.com/reversing-esp8266-firmware-part-1/)\n- [Automating Binary Vulnerability Discovery with Ghidra and Semgrep](https://security.humanativaspa.it/automating-binary-vulnerability-discovery-with-ghidra-and-semgrep/)\n- [Finding Bugs in Netgear Router](https://flattsecurity.medium.com/finding-bugs-to-trigger-unauthenticated-command-injection-in-a-netgear-router-psv-2022-0044-2b394fb9edc)\n\n#### Ghidra Tutorials\n\n- [Debugger Ghidra Class](https://github.com/NationalSecurityAgency/ghidra/tree/master/GhidraDocs/GhidraClass/Debugger)\n- [Ghidra 101: Cursor Text Highlighting](https://www.tripwire.com/state-of-security/ghidra-101-cursor-text-highlighting)\n- [Ghidra 101: Decoding Stack Strings](https://www.tripwire.com/state-of-security/ghidra-101-decoding-stack-strings)\n- [Extending Ghidra Part 1: Setting up a Development Environment](https://voidstarsec.com/blog/ghidra-dev-environment)\n- [Expanding the Dragon: Adding an ISA to Ghidra](https://web.archive.org/web/2022/https://trenchant.io/expanding-the-dragon-adding-an-isa-to-ghidra/)\n- [Ghidra nanoMIPS ISA module](https://research.nccgroup.com/2024/05/07/ghidra-nanomips-isa-module/)\n- [Binary type inference in Ghidra](https://blog.trailofbits.com/2024/02/07/binary-type-inference-in-ghidra/)\n- [Writing a Ghidra processor module](https://irisc-research-syndicate.github.io/2025/02/14/writing-a-ghidra-processor-module/)\n\n### Online Assemblers\n\n- [AZM Online ARM Assembler - Azeria Labs](https://azeria-labs.com/azm/)\n- [Online Disassembler](https://web.archive.org/web/2023/https://onlinedisassembler.com/odaweb/)\n- [Compiler Explorer](https://godbolt.org/)\n\n### ARM Exploitation\n\n- [Azeria Labs ARM Tutorials](https://azeria-labs.com/)\n- [ARM Exploitation for IoT](https://www.exploit-db.com/docs/english/43906-arm-exploitation-for-iot.pdf)\n- [Damn Vulnerable ARM Router (DVAR)](https://blog.exploitlab.net/2018/01/dvar-damn-vulnerable-arm-router.html)\n- [Exploit Education](https://exploit.education/)\n- [A Guide to ARM64 / AArch64 Assembly on Linux](https://web.archive.org/web/2024/https://modexp.wordpress.com/2018/10/30/arm64-assembly/)\n- [ARMv8 AArch64/ARM64 Full Beginner's Assembly Tutorial](https://mariokartwii.com/armv8/)\n- [A Noobs Guide to ARM Exploitation](https://ad2001.gitbook.io/a-noobs-guide-to-arm-exploitation/)\n- [ARM64 Reversing And Exploitation Series (8ksec) - Parts 1-10](https://8ksec.io/arm64-reversing-and-exploitation-part-1-arm-instruction-set-simple-heap-overflow/)\n- [AArch64 memory and paging](https://krinkinmu.github.io/2024/01/14/aarch64-virtual-memory.html)\n- [We are ARMed no more ROPpery Here](https://zeyadazima.com/exploit%20development/pointer_pac/)\n\n### Binary Analysis\n\n- [Practical Binary Analysis](https://nostarch.com/binaryanalysis)\n\n### Secure Boot\n\n#### Development\n\n- [Writing a Bootloader](https://3zanders.co.uk/2017/10/13/writing-a-bootloader/)\n\n#### Bypasses\n\n- [Pwn the ESP32 Secure Boot](https://web.archive.org/web/2024/https://limitedresults.com/2019/09/pwn-the-esp32-secure-boot/)\n- [Pwn ESP32 Forever: Flash Encryption and Secure Boot Keys Extraction](https://web.archive.org/web/2024/https://limitedresults.com/2019/11/pwn-the-esp32-forever-flash-encryption-and-sec-boot-keys-extraction/)\n- [ESP32 Secure Boot Bypass (CVE-2020-13629)](https://raelize.com/blog/espressif-esp32-bypassing-encrypted-secure-boot-cve-2020-13629/)\n- [Amlogic S905 SoC: Bypassing Secure Boot](https://fredericb.info/2016/10/amlogic-s905-soc-bypassing-not-so.html)\n- [Defeating Secure Boot with Symlink Attacks](https://www.anvilsecure.com/blog/defeating-secure-boot-with-symlink-attacks.html)\n- [PS4 Secure Boot Hacking - Fail0verflow](https://www.psxhax.com/threads/ps4-aux-hax-5-psvr-secure-boot-hacking-with-keys-by-fail0verflow.12820/)\n- [Dell BIOS Vulnerabilities - BIOSDisconnect](https://eclypsium.com/2021/06/24/biosdisconnect/)\n- [U-Boot USB DFU Vulnerability (CVE-2022-2347)](https://research.nccgroup.com/2023/01/20/technical-advisory-u-boot-unchecked-download-size-and-direction-in-usb-dfu-cve-2022-2347/)\n- [Breaking Secure Boot on Silicon Labs Gecko](https://blog.quarkslab.com/breaking-secure-boot-on-the-silicon-labs-gecko-platform.html)\n\n### UEFI Security\n\n- [Using Symbolic Execution to Detect UEFI Vulnerabilities](https://binarly.io/posts/Using_Symbolic_Execution_to_Detect_UEFI_Firmware_Vulnerabilities/index.html)\n- [HP Enterprise UEFI Vulnerabilities](https://www.binarly.io/posts/Binarly_Finds_Six_High_Severity_Firmware_Vulnerabilities_in_HP_Enterprise_Devices/index.html)\n- [Emulating and Exploiting UEFI Firmware](https://margin.re/2023/09/emulating-and-exploiting-uefi-firmware/)\n- [The Dark Side of UEFI: A technical Deep-Dive into Cross-Silicon Exploitation](https://www.binarly.io/blog/the-dark-side-of-uefi-a-technical-deep-dive-into-cross-silicon-exploitation)\n- [Inside the LogoFAIL PoC: From Integer Overflow to Arbitrary Code Execution](https://www.binarly.io/blog/inside-the-logofail-poc-from-integer-overflow-to-arbitrary-code-execution)\n- [PixieFail: Nine vulnerabilities in Tianocore's EDK II IPv6 network stack](https://blog.quarkslab.com/pixiefail-nine-vulnerabilities-in-tianocores-edk-ii-ipv6-network-stack.html)\n- [For Science! - Using an Unimpressive Bug in EDK II](https://blog.quarkslab.com/for-science-using-an-unimpressive-bug-in-edk-ii-to-do-some-fun-exploitation.html)\n- [Hydroph0bia: SecureBoot bypass for Insyde H2O](https://coderush.me/hydroph0bia-part1/)\n- [PKfail: Untrusted Platform Keys in UEFI Firmware (Binarly, 2024)](https://www.binarly.io/blog/pkfail-untrusted-platform-keys-undermine-secure-boot-on-uefi-ecosystem)\n- [LogoFAIL: Image Parsing Vulnerabilities in System Firmware (Binarly)](https://www.binarly.io/blog/the-far-reaching-consequences-of-logofail)\n- [BlackLotus UEFI Bootkit Analysis - ESET](https://www.welivesecurity.com/2023/03/01/blacklotus-uefi-bootkit-myth-confirmed/)\n- [Bootkitty: First UEFI Bootkit for Linux (ESET, 2024)](https://www.welivesecurity.com/en/eset-research/bootkitty-analyzing-first-uefi-bootkit-linux/)\n- [UEFI Firmware Rootkits: Myths and Reality (BlackHat 2024)](https://www.blackhat.com/us-24/briefings/schedule/index.html)\n- [CVE-2024-0762 - PixieFail Followup TPM Bypass](https://eclypsium.com/blog/ueficanhazbufferoverflow-widespread-impact-from-vulnerability-in-popular-pc-and-server-firmware/)\n\n### Symlink Attacks\n\n- [Zip Slip Vulnerability](https://security.snyk.io/research/zip-slip-vulnerability)\n\n---\n\n### Router Firmware Analysis\n\n- [A Journey into IoT: Discover Components and Ports](https://security.humanativaspa.it/a-journey-into-iot-unknown-chinese-alarm-part-1-discover-components-and-ports/)\n- [A Journey into IoT: Firmware Dump and Analysis](https://security.humanativaspa.it/a-journey-into-iot-unknown-chinese-alarm-part-2-firmware-dump-and-analysis/)\n- [A Journey into IoT: Radio Communications](https://security.humanativaspa.it/a-journey-into-iot-unknown-chinese-alarm-part-3-radio-communications/)\n- [A Journey into IoT: Internal Communications](https://security.humanativaspa.it/a-journey-into-iot-unknown-chinese-alarm-part-4-internal-communications/)\n- [Dynamic Analysis of Firmware Components in IoT Devices](https://ics-cert.kaspersky.com/publications/reports/2022/07/06/dynamic-analysis-of-firmware-components-in-iot-devices/)\n- [RV130X Firmware Analysis](https://raffo24.github.io/hardware%20hacking/FirmwareAnalysis/)\n- [TP-Link Firmware Decryption C210 V2 cloud camera bootloaders](https://watchfulip.github.io/28-12-24/tp-link_c210_v2.html)\n\n### Router Exploitation\n\n- [Hunting for Unauthenticated n-days in Asus Routers](https://www.shielder.com/blog/2024/01/hunting-for-~~un~~authenticated-n-days-in-asus-routers/)\n- [Pulling MikroTik into the Limelight](https://margin.re/2022/06/pulling-mikrotik-into-the-limelight/)\n- [Exploiting MikroTik RouterOS Hardware with CVE-2023-30799](https://vulncheck.com/blog/mikrotik-foisted-revisited)\n- [Rooting Xiaomi WiFi Routers](https://blog.thalium.re/posts/rooting-xiaomi-wifi-routers/)\n- [Route to Safety: Navigating Router Pitfalls](https://web.archive.org/web/2024/https://starlabs.sg/blog/2024/04-route-to-safety-navigating-router-pitfalls/)\n- [ROPing our way to RCE](https://modzero.com/en/blog/roping-our-way-to-rce/)\n- [ROPing Routers from scratch: Tenda Ac8v4](https://0reg.dev/blog/tenda-ac8-rop)\n- [PwnAgent: A One-Click WAN-side RCE in Netgear RAX Routers](https://mahaloz.re/2023/02/25/pwnagent-netgear.html)\n- [Puckungfu 2: Another NETGEAR WAN Command Injection](https://research.nccgroup.com/2024/02/09/puckungfu-2-another-netgear-wan-command-injection/)\n- [Reversing, Discovering, And Exploiting A TP-Link Router Vulnerability - CVE-2024-54887](https://infosecwriteups.com/reversing-discovering-and-exploiting-a-tp-link-router-vulnerability-cve-2024-54887-341552c4b104)\n- [Exploiting Zero-Day (CVE-2025-9961) Vulnerability in the TP-Link AX10 Router](https://blog.byteray.co.uk/exploiting-zero-day-cve-2025-9961-in-the-tp-link-ax10-router-8745f9af9c46)\n- [FiberGateway GR241AG - Full Exploit Chain](https://r0ny.net/FiberGateway-GR241AG-Full-Exploit-Chain/)\n- [Blackbox-Fuzzing of IoT Devices Using the Router TL-WR902AC](https://tsmr.eu/blackbox-fuzzing.html)\n- [Rooting the TP-Link Tapo C200 Rev.5](https://quentinkaiser.be/security/2025/07/25/rooting-tapo-c200/)\n\n#### Netgear Series\n\n- [Netgear Orbi: Introduction, UART Access, Recon](https://blog.coffinsec.com/research/2022/06/12/orbi-hunting-0-intro-uart.html)\n- [Netgear Orbi: Crashes in SOAP-API](https://blog.coffinsec.com/research/2022/06/19/orbi-hunting-1-soap-api-crashes.html)\n- [Netgear Orbi: NDay Exploit CVE-2020-27861](https://blog.coffinsec.com/research/2022/07/02/orbi-nday-exploit-cve-2020-27861.html)\n- [The Last Breath of Our Netgear RAX30 Bugs](https://starlabs.sg/blog/2022/12-the-last-breath-of-our-netgear-rax30-bugs-a-tragic-tale-before-pwn2own-toronto-2022/)\n\n#### TP-Link Series\n\n- [TP-Link TDDP Buffer Overflow Vulnerability](https://boschko.ca/tp-link-tddp-bof/)\n- [Pwn2Own Tokyo 2020: Defeating the TP-Link AC1750](https://www.synacktiv.com/en/publications/pwn2own-tokyo-2020-defeating-the-tp-link-ac1750.html)\n- [TP-Link Tapo c200 Camera Unauthenticated RCE (CVE-2021-4045)](https://www.hacefresko.com/posts/tp-link-tapo-c200-unauthenticated-rce)\n\n#### Cisco Series\n\n- [Patch Diffing a Cisco RV110W Firmware Update - Part 1](https://quentinkaiser.be/exploitdev/2020/09/23/ghetto-patch-diffing-cisco/)\n- [CVE-2024-20356: Jailbreaking a Cisco appliance to run DOOM](https://labs.nettitude.com/blog/cve-2024-20356-jailbreaking-a-cisco-appliance-to-run-doom/)\n- [Flashback Connects - Cisco RV340 SSL VPN RCE](https://www.flashback.sh/blog/flashback-connects-cisco-rv340-ssl-vpn-rce)\n\n### Secure Boot Bypasses\n\n- [Bypassing Secure Boot using Fault Injection](https://raelize.com/upload/research/2016/2016_BlackHat-EU_Bypassing-Secure-Boot-Using-Fault-Injection_NT-AS.pdf)\n- [Breaking Secure Boot on Google Nest Hub (2nd Gen)](https://fredericb.info/2022/06/breaking-secure-boot-on-google-nest-hub-2nd-gen-to-run-ubuntu.html)\n- [Booting into Breaches: Hunting Windows SecureBoot's Remote Attack Surfaces](https://i.blackhat.com/BH-USA-25/Presentations/US-25-Yang-Booting-into-breaches-Wednesday.pdf)\n\n## Network and Web Protocols\n\n### MQTT\n\n- [Introduction to MQTT](https://www.hivemq.com/blog/mqtt-essentials-part-1-introducing-mqtt)\n- [MQTT Broker Security 101](https://payatu.com/blog/mqtt-broker-security/)\n- [Hacking the IoT with MQTT](https://morphuslabs.com/hacking-the-iot-with-mqtt-8edaf0d07b9b)\n- [IoT Security: RCE in MQTT Protocol](https://systemweakness.com/iot-security-rce-in-mqtt-protocol-929e533f12b4)\n- [IoXY - MQTT Intercepting Proxy](https://blog.nviso.eu/2020/07/06/introducing-ioxy-an-open-source-mqtt-intercepting-proxy/)\n- [MQTT-PWN](https://mqtt-pwn.readthedocs.io/en/latest/)\n\n#### Fundamentals\n\n- [Understanding the MQTT Protocol Packet Structure](https://www.steves-internet-guide.com/mqtt-protocol-messages-overview/)\n\n#### Security and Exploitation\n\n- [Are Smart Homes Vulnerable to Hacking?](https://blog.avast.com/mqtt-vulnerabilities-hacking-smart-homes)\n- [Penetration Testing Sesame Smart Door Lock](https://www.diva-portal.org/smash/record.jsf?pid=diva2%3A1750933)\n- [Servisnet Tessa - MQTT Credentials Dump (Metasploit)](https://www.exploit-db.com/exploits/50713)\n- [Eclipse Mosquitto Unquoted Service Path](https://www.exploit-db.com/exploits/49673)\n\n#### Known CVEs\n\n- [CVE-2020-13849](https://nvd.nist.gov/vuln/detail/CVE-2020-13849) - DoS vulnerability (CVSS 7.5)\n- [CVE-2023-3028](https://nvd.nist.gov/vuln/detail/CVE-2023-3028) - Insufficient authentication (CVSS 9.8)\n- [CVE-2021-0229](https://nvd.nist.gov/vuln/detail/CVE-2021-0229) - Resource consumption (CVSS 5.3)\n- [CVE-2019-5432](https://nvd.nist.gov/vuln/detail/CVE-2019-5432) - Malformed packet crash (CVSS 7.5)\n\n#### Tools\n\n- [Mosquitto - Open Source MQTT Broker](https://mosquitto.org/)\n- [HiveMQ](https://www.hivemq.com/)\n- [MQTT Explorer](https://mqtt-explorer.com/)\n- [MQTT Topic ACL Linter](https://github.com/visoar/mqtt-acl-linter) - Local-only static analysis for invalid, broad, duplicate, and overlapping MQTT topic-filter ACL rules; does not connect to a broker or replace a security audit.\n- [Nmap MQTT Library](https://nmap.org/nsedoc/lib/mqtt.html)\n- [Seven Best MQTT Client Tools](https://www.hivemq.com/blog/seven-best-mqtt-client-tools)\n\n#### Applications\n\n- [Using IoT MQTT for V2V and Connected Cars](https://mobilebit.wordpress.com/tag/mqtt/)\n- [MQTT Hardware Development Projects](https://www.hackster.io/search?i=projects\u0026q=Mqtt)\n- [100,000 Connected Cars with Kubernetes, Kafka, MQTT, TensorFlow](https://dzone.com/articles/iot-live-demo-100000-connected-cars-with-kubernete)\n- [Authenticating Devices Using MQTT with Auth0](https://auth0.com/docs/integrations/authenticate-devices-using-mqtt)\n- [Deep Learning UDF for MQTT IoT Anomaly Detection](https://github.com/kaiwaehner/ksql-udf-deep-learning-mqtt-iot)\n- [Guide to MQTT: Hacking a Doorbell](https://youtu.be/J_BAXVSVPVI)\n\n#### Malware Research\n\n- [WailingCrab Malware Using MQTT for C2](https://securityonline.info/wailingcrab-malware-evolves-embracing-mqtt-for-stealthier-c2-communication)\n- [Alert: New WailingCrab Malware Loader](https://thehackernews.com/2023/11/alert-new-wailingcrab-malware-loader.html)\n- [MQTT on Snapcraft](https://snapcraft.io/search?q=mqtt)\n\n### CoAP\n\n- [IETF Security Protocol Comparison](https://datatracker.ietf.org/doc/draft-ietf-iotops-security-protocol-comparison/03/)\n- [RFC 8613 - OSCORE](https://datatracker.ietf.org/doc/html/rfc8613)\n- [Radware - CoAP Protocol Overview](https://www.radware.com/security/ddos-knowledge-center/ddospedia/coap/)\n\n#### Specifications and Security\n\n- [EMQX on CoAP and IoT Security (2024)](https://www.emqx.com/en/blog/iot-protocols-mqtt-coap-lwm2m)\n- [RFC 8323 - CoAP over TCP](https://datatracker.ietf.org/doc/html/rfc8323)\n- [RFC 8824 - SCHC Header Compression](https://datatracker.ietf.org/doc/html/rfc8824)\n\n#### Tools - Software\n\n- [CoAP NSE (Nmap)](https://nmap.org/nsedoc/lib/coap.html)\n- [Copper - Firefox CoAP Plugin](https://github.com/mkovatsc/Copper)\n- [libcoap CLI Tools](https://github.com/obgm/libcoap)\n- [Scapy CoAP Plugin](https://github.com/secdev/scapy)\n- [Eclipse Californium (Java)](https://www.eclipse.org/californium/)\n- [Peach Fuzzer](https://peachtech.gitlab.io/peach-fuzzer-community/)\n\n#### Tools - Hardware\n\n- [Raspberry Pi / Arduino + 6LoWPAN](https://github.com/contiki-ng/contiki-ng/wiki/Tutorial:-RPL-border-router)\n- [Zolertia](https://zolertia.io/)\n- [OpenMote](https://web.archive.org/web/2022/http://www.openmote.com/)\n- [Nordic Boards](https://www.nordicsemi.com/)\n\n#### Research and Tutorials\n\n- [SpectralOps - Top IoT Protocol Security Issues](https://spectralops.io/blog/top-5-most-commonly-used-iot-protocols-and-their-security-issues/)\n- [CoAP Exposure Study (2024)](https://raid2024.github.io/papers/raid2024-9.pdf)\n\n### mTLS\n\n#### Tools\n\n| Tool                      | Use                                                                                             | Link                                                                                                     |\n| ───────────────────────── | ─────────────────────────────────────────────────────────────────────────────────────────────── | ──────────────────────────────────────────────────────────────────────────────────────────────────────── |\n| mtls-intercept            | Reverse proxy that dynamically signs client certs to MITM full mTLS sessions                    | [github.com/fungaren/mtls-intercept](https://github.com/fungaren/mtls-intercept)                         |\n| mitmproxy                 | Configure client_certs with extracted IoT device cert to impersonate device in mTLS handshake   | [mitmproxy.org](https://mitmproxy.org)                                                                   |\n| SSLsplit                  | Transparent mTLS proxy - forward extracted device cert to complete mutual handshake with cloud  | [github.com/droe/sslsplit](https://github.com/droe/sslsplit)                                             |\n| eCapture (eBPF)           | Hook OpenSSL/BoringSSL on Linux IoT gateways pre-encrypt - decrypts mTLS + TLS 1.3 + PFS        | [ecapture.cc](https://ecapture.cc)                                                                       |\n| Wireshark + SSLKEYLOGFILE | Decrypt captured mTLS sessions from IoT gateways using NSS pre-master secret logs               | [wiki.wireshark.org/TLS](https://wiki.wireshark.org/TLS)                                                 |\n| Frida                     | Runtime hook SSLContext, TrustManager, KeyManager in Android IoT companion apps                 | [frida.re](https://frida.re/)                                                                            |\n| Objection                 | Android sslpinning disable - strips mTLS pinning in companion apps                              | [github.com/sensepost/objection](https://github.com/sensepost/objection)                                 |\n| apk-mitm                  | Statically patches IoT companion APK to disable mTLS cert pinning                               | [github.com/shroudedcode/apk-mitm](https://github.com/shroudedcode/apk-mitm)                             |\n| MagiskTrustUserCerts      | Moves custom CA to system store on rooted Android POS/kiosk to complete mTLS MITM               | [github.com/NVISOsecurity/MagiskTrustUserCerts](https://github.com/NVISOsecurity/MagiskTrustUserCerts)   |\n| frida-multiple-unpinning  | Universal Frida script targeting 20+ mTLS/pinning patterns in hardened IoT apps                 | [github.com/httptoolkit/frida-android-unpinning](https://github.com/httptoolkit/frida-android-unpinning) |\n| NEU-SNS/IoTLS             | IMC'21 research repo - SSLKEYLOGFILE files to decrypt MITM'd mTLS connections across 32 devices | [github.com/NEU-SNS/IoTLS](https://github.com/NEU-SNS/IoTLS)                                             |\n| mitmrouter                | Linux-based IoT traffic interception router - intercepts device TLS at network level            | [github.com/nmatt0/mitmrouter](https://github.com/nmatt0/mitmrouter)                                     |\n\n#### Blogs \u0026 Articles\n\n- [mTLS: When Certificate Authentication is Done Wrong](https://github.blog/security/vulnerability-research/mtls-when-certificate-authentication-is-done-wrong/)\n- [mTLS Authentication in IoT: Enhancing Security for Connected Devices](https://www.regamiota.com/post/mtls-authentication-in-iot-enhancing-security-for-connected-devices)\n- [Hands On IoT MitM Part 1 - AWS IoT MQTT + mTLS Interception](https://samrambles.com/projects/hunter-hacking/hands-on-iot-mitm-part-1/)\n- [OWASP MASTG-TECH-0012: Bypassing Certificate Pinning in Android IoT Companion Apps](https://mas.owasp.org/MASTG/techniques/android/MASTG-TECH-0012/)\n- [Theory to Practice: mTLS in Action Part 1](https://klika-tech.com/blog/2025/08/28/theory-to-practice-mtls-in-action-part-1)\n- [Configuring mTLS on Mosquitto MQTT Broker](https://mosquitto.org/man/mosquitto-tls-7.html)\n- [AWS IoT Docs: X.509 Client Certificates and Fleet Provisioning](https://docs.aws.amazon.com/iot/latest/developerguide/x509-client-certs.html)\n- [Azure IoT Hub: mTLS X.509 CA Authentication Concept](https://learn.microsoft.com/en-us/azure/iot-hub/iot-hub-x509ca-concept)\n\n#### Research Papers\n\n- [Evaluation of TLS and mTLS in Internet of Things Systems - MIUN DiVA, 2024](https://miun.diva-portal.org/smash/record.jsf?pid=diva2%3A1937634)\n- [Atlas: Enabling Cross-Vendor mTLS Authentication for IoT - arXiv 2025](https://arxiv.org/html/2602.09263v1)\n- [Lightweight mTLS Authentication for Industrial IoT - PMC/NIH 2023](https://pmc.ncbi.nlm.nih.gov/articles/PMC10222187/)\n- [Quantum-Enhanced mTLS for IoT Battlefield Networks - IJPSAT](https://ijpsat.org/index.php/ijpsat/article/download/6969/4447)\n- [AI vs. IoT Security: Fingerprinting and Defenses Against TLS Attacks - IEEE Xplore 2025](https://ieeexplore.ieee.org/document/11168239/)\n\n#### YouTube\n\n- [Intercepting IoT Device Traffic with ARP Poisoning + mitmproxy TLS Intercept](https://www.youtube.com/watch?v=f7XFcZ2_9ww)\n- [Using Linux to Intercept IoT Device Traffic with mitmrouter](https://www.youtube.com/watch?v=k134j9E5oZE)\n- [Mutual TLS - The Backend Engineering Show Deep Dive](https://www.youtube.com/watch?v=KwpV-ICpkc4)\n- [Intercepting SSL/TLS - Fiddler and MITMProxy Decrypt Walkthrough](https://www.youtube.com/watch?v=gJiVbhyBixM)\n- [Decrypting Kubernetes mTLS Traffic - eCapture, Custom CA, eBPF Methods](https://www.youtube.com/watch?v=4gNuZFkpz8U)\n- [Mastering mTLS: Stop MITM Attacks and Boost API/IoT Security](https://www.youtube.com/watch?v=F-H5ftwKarc)\n- [Introduction to IoT Penetration Testing Webinar - CyberWarFare Labs](https://www.youtube.com/watch?v=qMdg-Rj53jA)\n\n### IoT Protocols Overview\n\n- [IoT Protocols Overview](https://www.postscapes.com/internet-of-things-protocols/)\n- [IoT Architecture](https://www.c-sharpcorner.com/UploadFile/f88748/internet-of-things-part-2/)\n- [Attacking IoT Devices from Web Perspective](https://lug.uniroma2.it/eventi/linux-day-23/files/Linux%20Day%20-%20Attacking%20IoT%20Devices.pdf)\n- [Awesome Industrial Protocols](https://github.com/Orange-Cyberdefense/awesome-industrial-protocols)\n\n## Cloud and Backend Security\n\n### AWS IoT Security\n\n- [AWS Penetration Testing Policy](https://aws.amazon.com/security/penetration-testing/)\n- [AWS Pentesting Guide - HackerOne](https://www.hackerone.com/knowledge-center/penetration-testing-aws-practical-guide)\n- [A few notes on AWS Nitro Enclaves](https://blog.trailofbits.com/2024/02/16/a-few-notes-on-aws-nitro-enclaves-images-and-attestation/)\n\n#### Fundamentals\n\n- [Comprehensive AWS Pentesting Guide - BreachLock](https://www.breachlock.com/resources/blog/comprehensive-aws-pentesting-guide/)\n- [AWS Pentest Methodology - MorattiSec](https://medium.com/@MorattiSec/my-aws-pentest-methodology-14c333b7fb58)\n- [AWS Penetration Testing Methodology - Rootshell](https://www.rootshellsecurity.net/aws-penetration-testing-methodology-and-guidelines/)\n- [AWS Penetration Testing Techniques 2025](https://deepstrike.io/blog/aws-penetration-testing-guide-techniques-and-methodology)\n\n#### Tools\n\n- [CloudFox - Cloud Attack Paths](https://github.com/BishopFox/cloudfox)\n- [S3Scanner - Leaky Bucket Discovery](https://github.com/sa7mon/S3Scanner)\n- [Cloudfoxable Labs](https://github.com/BishopFox/cloudfoxable)\n- [AWS Security Pentesting Resources](https://github.com/redskycyber/Cloud-Security/blob/main/AWS-Security-Pentesting-Resources.md)\n- [Pacu - AWS Exploitation Framework](https://github.com/RhinoSecurityLabs/pacu)\n- [ScoutSuite - Multi-cloud Security Auditing](https://github.com/nccgroup/ScoutSuite)\n- [Prowler - Cloud Security Assessment](https://github.com/prowler-cloud/prowler)\n\n#### Vulnerabilities\n\n- [7 Best AWS Pentesting Tools 2026](https://www.getastra.com/blog/cloud/aws/aws-pentesting-tools/)\n- [PayloadsAllTheThings - AWS Pentest](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Cloud%20-%20AWS%20Pentest.md)\n\n### Firebase / Cloud Misconfigurations\n\n- [Firebase Security Rules Testing](https://firebase.google.com/docs/rules/unit-tests)\n- [Misconfigured Firebase Databases](https://web.archive.org/web/2022/https://www.comparitech.com/blog/information-security/firebase-misconfiguration-vulnerability/)\n\n---\n\n## Mobile Application Security\n\n### Android\n\n- [Android App Reverse Engineering 101](https://maddiestone.github.io/AndroidAppRE/)\n- [Android Application Pentesting Book](https://www.packtpub.com/hardware-and-creative/learning-pentesting-android-devices)\n- [Android Pentest Video Course - TutorialsPoint](https://www.youtube.com/watch?v=zHknRia3I6s\u0026list=PLWPirh4EWFpESLreb04c4eZoCvJQJrC6H)\n- [Android Tamer](https://github.com/AndroidTamer/Tools_Repository)\n- [Android Hacker's Handbook](https://www.amazon.in/Android-Hackers-Handbook-MISL-WILEY-Joshua/dp/812654922X)\n- [A first look at Android 14 forensics](https://blog.digital-forensics.it/2024/01/a-first-look-at-android-14-forensics.html?m=1)\n- [Deobfuscating Android ARM64 strings with Ghidra](https://blog.nviso.eu/2024/01/15/deobfuscating-android-arm64-strings-with-ghidra-emulating-patching-and-automating/)\n- [Introduction to Fuzzing Android Native Components](https://blog.convisoappsec.com/en/introduction-to-fuzzing-android-native-components/)\n- [Hacking Android Games](https://8ksec.io/hacking-android-games/)\n- [Intercepting HTTPS Communication in Flutter](https://sensepost.com/blog/2025/intercepting-https-communication-in-flutter-going-full-hardcore-mode-with-frida/)\n\n#### Android Kernel Exploitation\n\n- [Android Kernel Exploitation](https://cloudfuzz.github.io/android-kernel-exploitation/)\n- [Attacking Android Binder: Analysis and Exploitation of CVE-2023-20938](https://androidoffsec.withgoogle.com/posts/attacking-android-binder-analysis-and-exploitation-of-cve-2023-20938/)\n- [Attacking the Android kernel using the Qualcomm TrustZone](https://tamirzb.com/attacking-android-kernel-using-qualcomm-trustzone)\n- [Driving forward in Android drivers](https://googleprojectzero.blogspot.com/2024/06/driving-forward-in-android-drivers.html)\n- [Analyzing a Modern In-the-wild Android Exploit](https://googleprojectzero.blogspot.com/2023/09/analyzing-modern-in-wild-android-exploit.html)\n- [Exploiting Android's Hardened Memory Allocator](https://www.usenix.org/system/files/woot24-mao.pdf)\n- [GPUAF - Two ways of Rooting All Qualcomm based Android phones](https://powerofcommunity.net/)\n- [The Qualcomm DSP Driver - Unexpectedly Excavating an Exploit](https://googleprojectzero.blogspot.com/2024/12/qualcomm-dsp-driver-unexpectedly-excavating-exploit.html)\n- [Qualcomm DSP Kernel Internals](https://streypaws.github.io/posts/DSP-Kernel-Internals/)\n- [Binder Fuzzing](https://androidoffsec.withgoogle.com/posts/binder-fuzzing/)\n\n#### Android Scudo Allocator\n\n- [Android: Scudo](https://technologeeks.com/blog/Scudo/)\n- [Behind the Shield: Unmasking Scudo's Defenses](https://www.synacktiv.com/en/publications/behind-the-shield-unmasking-scudos-defenses)\n- [scudo Hardened Allocator - Unofficial Internals Documentation](https://www.l3harris.com/newsroom/editorial/2023/10/scudo-hardened-allocator-unofficial-internals-documentation)\n\n### iOS\n\n- [iOS Pentesting Guide](https://web.securityinnovation.com/hubfs/iOS%20Hacking%20Guide.pdf)\n- [OWASP Mobile Security Testing Guide](https://owasp.org/www-project-mobile-security-testing-guide/)\n- [An iOS hacker tries Android](https://googleprojectzero.blogspot.com/2020/12/an-ios-hacker-tries-android.html)\n- [Analyzing iOS Kernel Panic Logs](https://8ksec.io/analyzing-kernel-panic-ios/)\n- [Blasting Past iOS 18](https://blog.dfsec.com/ios/2025/05/30/blasting-past-ios-18/)\n- [Emulating an iPhone in QEMU](https://eshard.com/posts/emulating-ios-14-with-qemu)\n- [First analysis of Apple's USB Restricted Mode bypass (CVE-2025-24200)](https://blog.quarkslab.com/first-analysis-of-apples-usb-restricted-mode-bypass-cve-2025-24200.html)\n- [Exploring UNIX pipes for iOS kernel exploit primitives](https://www.corellium.com/blog/exploring-unix-pipes-for-ios-kernel-exploit-primitives)\n\n## Industrial and Automotive\n\n### ICS/SCADA\n\n- [ICS Village](https://www.icsvillage.com/)\n- [ICS Discord Group](https://discord.com/invite/CmDDsFK)\n- [Controlthings.io Platform](https://www.controlthings.io/platform)\n- [Applied Cyber Security and the Smart Grid](https://www.amazon.com/Applied-Cyber-Security-Smart-Grid/dp/1597499986/)\n- [Deep Lateral Movement in OT Networks](https://www.forescout.com/resources/l1-lateral-movement-reportg)\n- [Hacking ICS Historians: The Pivot Point from IT to OT](https://claroty.com/team82/research/hacking-ics-historians-the-pivot-point-from-it-to-ot)\n- [OPC UA Deep Dive Series - Parts 1-5](https://claroty.com/team82/research/opc-ua-deep-dive-history-of-the-opc-ua-protocol)\n- [Inside a New OT/IoT Cyberweapon: IOCONTROL](https://claroty.com/team82/research/inside-a-new-ot-iot-cyber-weapon-iocontrol)\n- [Attention, High Voltage: Exploring the Attack Surface of the Rockwell Automation PowerMonitor 1000](https://claroty.com/team82/research/attention-high-voltage-exploring-the-attack-surface-of-the-rockwell-automation-powermonitor-1000)\n\n### Automotive Security\n\n- [Awesome Vehicle Security](https://github.com/jaredthecoder/awesome-vehicle-security)\n- [Car Hacking Village](https://www.carhackingvillage.com/)\n- [Jeep Hack](https://illmatics.com/Remote%20Car%20Hacking.pdf)\n- [Subaru Head Unit Jailbreak](https://github.com/sgayou/subaru-starlink-research/blob/master/doc/README.md)\n- [Car Hacking Practical Guide 101](https://medium.com/@yogeshojha/car-hacking-101-practical-guide-to-exploiting-can-bus-using-instrument-cluster-simulator-part-i-cd88d3eb4a53)\n- [CAN Injection: keyless car theft](https://kentindell.github.io/2023/04/03/can-injection/)\n- [How I Hacked my Car Series - Parts 1-6](https://programmingwithstyle.com/posts/howihackedmycar/)\n- [How I Also Hacked my Car](https://goncalomb.com/blog/2024/01/30/f57cf19b-how-i-also-hacked-my-car)\n- [Extracting Secure Onboard Communication (SecOC) keys from a 2021 Toyota RAV4 Prime](https://icanhack.nl/blog/secoc-key-extraction/)\n- [Recovering an ECU firmware using disassembler and branches](https://blog.quarkslab.com/recovering-an-ecu-firmware-using-disassembler-and-branches.html)\n- [Automotive Memory Protection Units: Uncovering Hidden Vulnerabilities](https://plaxidityx.com/blog/blog-post/is-your-memory-protecteduncovering-hidden-vulnerabilities-in-automotive-mpu-mechanisms/)\n- [Web Hackers vs The Auto Industry: Critical Vulnerabilities in Cars (Sam Curry, 2023)](https://samcurry.net/web-hackers-vs-the-auto-industry/)\n- [Hacking Kia: Remotely Controlling Cars With Just a License Plate (Sam Curry, 2024)](https://samcurry.net/hacking-kia)\n- [Hacking Subaru: Tracking and Controlling Cars via the STARLINK Admin Panel (Sam Curry, 2025)](https://samcurry.net/hacking-subaru)\n- [Pwn2Own Automotive (ZDI Blog Category - 2024 \u0026 2025 Tokyo)](https://www.zerodayinitiative.com/blog/category/Pwn2Own)\n- [Synacktiv Publications - Pwn2Own Automotive Writeups](https://www.synacktiv.com/publications)\n- [Awesome CAN Bus - Curated Resources](https://github.com/iDoka/awesome-canbus)\n\n### EV Chargers\n\n- [A Detailed Look at Pwn2own Automotive EV Charger Hardware](https://www.zerodayinitiative.com/blog/2023/11/28/a-detailed-look-at-pwn2own-automotive-ev-charger-hardware)\n- [Pwn2Own Automotive 2024: Hacking the ChargePoint Home Flex](https://sector7.computest.nl/post/2024-08-pwn2own-automotive-chargepoint-home-flex/)\n- [Reverse engineering an EV charger](https://www.mnemonic.io/no/resources/blog/reverse-engineering-an-ev-charger/)\n- [Pwn2Own Automotive 2024: Autel MaxiCharger Analysis (Computest Sector7)](https://sector7.computest.nl/post/2024-04-pwn2own-automotive-autel-maxicharger/)\n- [SaiFlow Blog - OCPP/EV Charging Protocol Vulnerabilities](https://www.saiflow.com/blog/)\n\n---\n\n## Payment Systems\n\n### ATM Hacking\n\n- [Introduction to ATM Penetration Testing](https://www.youtube.com/watch?v=Ff-0zXTYhuA)\n- [Pwning ATMs for Fun and Profit](https://www.youtube.com/watch?v=9cG-JL0LHYw)\n- [Jackpotting ATMs Redux - Barnaby Jack](https://www.youtube.com/watch?v=4StcW9OPpPc)\n- [Root Shell on Credit Card Terminal](https://stefan-gloor.ch/yomani-hack)\n\n### Payment Village\n\n- [Payment Village](https://www.paymentvillage.org/home)\n\n---\n\n## Tools\n\n### Hardware Tools\n\n- [Bus Pirate](https://www.sparkfun.com/products/12942)\n- [Bus Pirate 5: The Swiss ARRRmy Knife of Hardware Hacking](https://eclypsium.com/blog/bus-pirate-5-the-swiss-arrrmy-knife-of-hardware-hacking/)\n- [The Shikra](https://int3.cc/products/the-shikra)\n- [Attify Badge](https://www.attify-store.com/products/attify-badge-assess-security-of-iot-devices)\n- [Flipper Zero](https://flipperzero.one/)\n- [HackRF](https://greatscottgadgets.com/hackrf/)\n- [RTL-SDR](https://www.rtl-sdr.com/)\n- [An In-Depth Look at the ICE-V Wireless FPGA Development Board](https://tomverbeure.github.io/2022/12/27/The-ICE-V-Wireless-FPGA-Board.html)\n\n#### Multi-Purpose\n\n- [Logic Analyzer - Saleae](https://www.saleae.com/)\n- [JTAGulator](https://www.adafruit.com/product/1550)\n- [EEPROM Reader/SOIC Cable](https://www.sparkfun.com/products/13153)\n\n#### Debug Adapters\n\n- [ST-Link](https://www.st.com/en/development-tools/st-link-v2.html)\n- [Segger J-Link](https://www.segger.com/products/debug-probes/j-link/)\n- [FTDI-based Adapters](https://ftdichip.com/)\n- [Black Magic Probe](https://black-magic.org/)\n\n#### USB\n\n- [FaceDancer21](https://int3.cc/products/facedancer21)\n- [RfCat](https://int3.cc/products/rfcat)\n- [NullSec Ducky Payloads](https://github.com/bad-antics/nullsec-ducky-payloads) - Rubber Ducky BadUSB payload collection for Windows, macOS and Linux.\n\n\n#### Flipper Zero\n\n- [NullSec Flipper Suite](https://github.com/bad-antics/nullsec-flipper-suite) - Flipper Zero payload collection for RF, RFID/NFC, BadUSB, infrared and wireless pentesting.\n- [PineFlip](https://github.com/bad-antics/pineflip) - Flipper Zero companion app for Linux with screen mirroring, file manager and firmware management.\n\n#### Hak5\n\n- [Hak5 Field Kits](https://hakshop.com/)\n- [NullSec Pineapple Suite](https://github.com/bad-antics/nullsec-pineapple-suite) - WiFi Pineapple payload collection for deauth, evil twin, handshake capture and network recon.\n\n\n### Software Tools\n\n#### Exploitation Frameworks\n\n- [BlueSploit](https://github.com/V33RU/bluesploit)\n- [IoTSecFuzz](https://gitlab.com/invuls/iot-projects/iotsecfuzz)\n- [PENIOT](https://github.com/yakuza8/peniot)\n- [ISF - Industrial Security Framework](https://github.com/w3h/isf)\n- [HAL - Hardware Analyzer](https://github.com/emsec/hal)\n- [PRET - Printer Exploitation Toolkit](https://github.com/RUB-NDS/PRET)\n- [Expliot Framework](https://gitlab.com/expliot_framework/expliot)\n- [RouterSploit](https://github.com/threat9/routersploit)\n- [HomePwn](https://github.com/ElevenPaths/HomePWN)\n- [Firmware Analysis Toolkit (FAT)](https://github.com/attify/firmware-analysis-toolkit)\n- [Shambles: The Next-Generation IoT Reverse Engineering Tool](https://boschko.ca/shambles/)\n\n#### Firmware Analysis\n\n- [Samsung Firmware Magic](https://github.com/chrivers/samsung-firmware-magic)\n\n---\n\n### Fuzzing Tools\n\n- [The art of Fuzzing: Introduction](https://web.archive.org/web/2024/https://bushido-sec.com/index.php/2023/06/19/the-art-of-fuzzing/)\n- [A LibAFL Introductory Workshop](https://www.atredis.com/blog/2023/12/4/a-libafl-introductory-workshop)\n- [The Blitz Tutorial Lab on Fuzzing with AFL++](https://research.checkpoint.com/2023/the-blitz-tutorial-lab-on-fuzzing-with-afl/)\n- [State of Linux Snapshot Fuzzing](https://fuzzinglabs.com/state-of-linux-snapshot-fuzzing/)\n- [Fuzzing between the lines in popular barcode software](https://blog.trailofbits.com/2024/10/31/fuzzing-between-the-lines-in-popular-barcode-software/)\n- [Boofuzz](https://github.com/jtpereyda/boofuzz)\n- [Syzkaller - Kernel Fuzzer](https://github.com/google/syzkaller)\n- [parking-game-fuzzer](https://github.com/addisoncrump/parking-game-fuzzer)\n\n#### Fundamentals\n\n- [OWASP Fuzzing Info](https://owasp.org/www-community/Fuzzing)\n- [Fuzz Testing of Application Reliability](https://pages.cs.wisc.edu/~bart/fuzz/)\n- [FuzzingPaper Collection](https://github.com/wcventure/FuzzingPaper/tree/master/Paper)\n\n#### IoT-Specific Fuzzing\n\n- [Fuzzing ICS Protocols](https://1modm.github.io/Fuzzing_ICS_protocols.html)\n- [Fuzzowski - Network Protocol Fuzzer](https://hakin9.org/fuzzowski-the-network-protocol-fuzzer-that-we-will-want-to-use/)\n- [FIRM-AFL: High-Throughput IoT Firmware Fuzzing](https://www.usenix.org/conference/usenixsecurity19/presentation/zheng)\n- [Snipuzz: Black-box Fuzzing of IoT Firmware](https://arxiv.org/pdf/2105.05445.pdf)\n- [Fuzzing IoT Binaries Part 1](https://blog.attify.com/fuzzing-iot-devices-part-1/)\n- [Fuzzing IoT Binaries Part 2](https://blog.attify.com/fuzzing-iot-binaries-with-afl-part-ii/)\n- [Awesome Embedded Fuzzing](https://github.com/andreia-oca/awesome-embedded-fuzzing)\n\n#### Tools\n\n- [AFL Training Exercises](https://github.com/mykter/afl-training)\n- [Frankenstein - Broadcom/Cypress Firmware Emulation for Fuzzing](https://github.com/seemoo-lab/frankenstein)\n- [Dr. Memory](https://github.com/DynamoRIO/drmemory)\n\n### Pentesting Operating Systems\n\n- [AttifyOS](https://github.com/adi0x90/attifyos)\n- [IoT Penetration Testing OS v1](https://github.com/IoT-PTv)\n- [EmbedOS](https://github.com/scriptingxss/EmbedOS)\n- [Sigint OS - LTE IMSI Catcher](https://web.archive.org/web/2022/https://www.sigintos.com/)\n- [Instant GNU Radio OS](https://github.com/bastibl/instant-gnuradio)\n- [Dragon OS - SDR Software](https://www.rtl-sdr.com/dragonos-debian-linux-with-preinstalled-open-source-sdr-software/)\n- [Skywave Linux - SDR](https://skywavelinux.com/)\n- [Zephyr RTOS](https://www.zephyrproject.org/)\n- [Ubuntu LTS](https://www.ubuntu.com/)\n\n### Search Engines\n\n- [Shodan](https://www.shodan.io/)\n- [Censys](https://censys.io/)\n- [ZoomEye](https://www.zoomeye.org/)\n- [BinaryEdge](https://www.binaryedge.io/)\n- [Thingful](https://www.thingful.net/)\n- [Wigle](https://wigle.net/)\n- [Hunter.io](https://hunter.io/)\n- [BuiltWith](https://builtwith.com/)\n- [Recon-ng](https://github.com/lanmaster53/recon-ng)\n- [PublicWWW](https://publicwww.com/)\n- [FCC ID Database](https://fccid.io/)\n- [CVE PoC Search](https://labs.jamessawyer.co.uk/cves/) - Search public GitHub PoC repositories by CVE ID.\n\n---\n\n## Defensive Security\n\n### Threat Modeling\n\n- [STRIDE Threat Model Guide - Practical DevSecOps](https://www.practical-devsecops.com/what-is-stride-threat-model/)\n- [OWASP Threat Modeling Process](https://owasp.org/www-community/Threat_Modeling_Process)\n- [STRIDE-based Threat Modeling for IoT Precision Agriculture](https://arxiv.org/pdf/2201.09493)\n\n#### STRIDE Framework\n\n- [What is STRIDE in Threat Modeling - Security Compass](https://www.securitycompass.com/blog/stride-in-threat-modeling/)\n- [Threat Modeling with ATT\u0026CK - MITRE](https://ctid.mitre.org/projects/threat-modeling-with-attack/)\n- [What is Threat Modeling - Fortinet](https://www.fortinet.com/resources/cyberglossary/threat-modeling)\n\n#### IoT-Specific Threat Modeling\n\n- [STRIDE Threat Modeling for IoT Smart Home](https://online-journals.org/index.php/i-jim/article/view/52377)\n- [STRIDE Threat Modeling for Smart Solar Energy Systems](https://www.mdpi.com/2071-1050/17/6/2386)\n- [STRIDE Threat Modeling for IoT Healthcare Systems](https://www.researchgate.net/publication/394711434_STRIDE-Based_Threat_Modeling_and_Risk_Assessment_Framework_for_IoT-enabled_Smart_Healthcare_Systems)\n- [STRIDE for IoT Agriculture - IEEE](https://ieeexplore.ieee.org/document/9732597/)\n\n### Secure Development\n\n- [Compiler Options Hardening Guide for C and C++](https://best.openssf.org/Compiler-Hardening-Guides/Compiler-Options-Hardening-Guide-for-C-and-C++.html)\n- [Linux Hardening Guide](https://madaidans-insecurities.github.io/guides/linux-hardening.html)\n- [Docker Security - Step-by-Step Hardening](https://reynardsec.com/en/docker-platform-security-step-by-step-hardening/)\n- [How To Secure A Linux Server](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server)\n\n#### Guidelines and Standards\n\n- [NIST IoT Cybersecurity Framework](https://www.nist.gov/itl/applied-cybersecurity/nist-cybersecurity-iot-program)\n- [NIST SP 800-213 - IoT Device Cybersecurity Guidance](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-213.pdf)\n- [NISTIR 8259 - Foundational Cybersecurity Activities for IoT Manufacturers](https://nvlpubs.nist.gov/nistpubs/ir/2020/NIST.IR.8259.pdf)\n- [ETSI EN 303 645 - Cyber Security for Consumer IoT](https://www.etsi.org/deliver/etsi_en/303600_303699/303645/02.01.01_60/en_303645v020101p.pdf)\n- [OWASP IoT Top 10 (2018)](https://owasp.org/www-pdf-archive/OWASP-IoT-Top-10-2018-final.pdf)\n- [OWASP IoT Project](https://owasp.org/www-project-internet-of-things/)\n\n#### Hardening Guides\n\n- [IoT Device Hardening Best Practices](https://www.cisa.gov/news-events/news/securing-internet-things-iot)\n- [Embedded Linux Hardening](https://embeddedsecurity.io/)\n- [Zephyr RTOS Security Features](https://docs.zephyrproject.org/latest/security/index.html)\n\n### Incident Response\n\n- [IoT Forensics and Incident Response](https://www.sans.org/white-papers/?focus-area=digital-forensics)\n- [Embedded Device Forensics](https://www.sciencedirect.com/science/article/pii/S2666281720300019)\n\n---\n\n## Learning Resources\n\n### Training Platforms\n\n- [OpenSecurityTraining2](https://p.ost2.fyi/courses)\n- [cryptopals](https://cryptopals.com)\n\n### Cheatsheets\n\n- [Hardware Hacking Cheatsheet](https://github.com/arunmagesh/hw_hacking_cheatsheet)\n- [Nmap Tutorial](https://github.com/gnebbia/nmap_tutorial)\n- [Pentest Hardware Handbook](https://github.com/unprovable/PentestHardware)\n- [THC's favourite Tips, Tricks \u0026 Hacks](https://github.com/hackerschoice/thc-tips-tricks-hacks-cheat-sheet)\n- [Cross Cache Attack CheetSheet](https://u1f383.github.io/linux/2025/01/03/cross-cache-attack-cheatsheet.html)\n\n### Vulnerability Guides\n\n- [OWASP IoT Top 10 2018 Mapping](https://scriptingxss.gitbook.io/owasp-iot-top-10-mapping-project/)\n- [Reflecting on OWASP IoT Top 10](https://web.archive.org/web/2020/https://embedi.org/blog/reflecting-upon-owasp-top-10-iot-vulnerabilities/)\n- [CVE North Stars](https://cve-north-stars.github.io)\n- [IoT Vulnerabilities with CVE and PoC](https://github.com/z1r00/IOT_Vul)\n- [Linux Privilege Escalation](https://tbhaxor.com/linux-privilege-escalation/)\n\n### Pentesting Guides\n\n- [Shodan Pentesting Guide](https://web.archive.org/web/2022/https://community.turgensec.com/shodan-pentesting-guide/)\n- [Modern Vulnerability Research on Embedded Systems](https://breaking-bits.gitbook.io/breaking-bits/vulnerability-discovery/reverse-engineering/modern-approaches-toward-embedded-research)\n- [Awesome Embedded Systems Vulnerability Research](https://github.com/IamAlch3mist/Awesome-Embedded-Systems-Vulnerability-Research)\n\n### YouTube Channels\n\n- [Joe Grand](https://www.youtube.com/@JoeGrand)\n- [LiveOverflow](https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w)\n- [Binary Adventure](https://www.youtube.com/channel/UCSLlgiYtOXZnYPba_W4bHqQ)\n- [EEVBlog](https://www.youtube.com/user/EEVblog)\n- [Craig Smith](https://www.youtube.com/channel/UCxC8G4Oeed4N0-GVeDdFoSA)\n- [IoTSecurity101](https://www.youtube.com/channel/UCe2mJv2FPRFhYJ7dvNdYR4Q)\n- [Besim ALTINOK](https://www.youtube.com/channel/UCnIV7A3kDL4JXJEljpW6TRQ/playlists)\n- [Ghidra Ninja](https://www.youtube.com/channel/UC3S8vxwRfqLBdIhgRlDRVzw)\n- [Cyber Gibbons](https://www.youtube.com/channel/UC_IYERSoSwdR7AA5P41mYTA)\n- [Scanline](https://www.youtube.com/channel/UCaEgw3321ct_PE4PJvdhXEQ)\n- [Aaron Christophel](https://www.youtube.com/c/12002230/videos)\n- [Valerio Di Giampietro](https://www.youtube.com/c/MakeMeHack)\n- [Gamozo Labs - Printer Hacking](https://www.youtube.com/watch?v=2LVtEoQA8Qo)\n\n### Books\n\n#### Hardware Hacking\n\n- [The Hardware Hacking Handbook - Jasper van Woudenberg \u0026 Colin O'Flynn (2021)](https://books.google.co.in/books?id=DEqatAEACAAJ)\n- [Practical Hardware Pentesting - Jean-Georges Valle (2021)](https://www.packtpub.com/product/practical-hardware-pentesting/9781789619133)\n- [Practical Hardware Pentesting 2nd Edition (2023)](https://www.packtpub.com/product/practical-hardware-pentesting-second-edition/9781803249322)\n- [Hardware Hacking: Have Fun While Voiding Your Warranty - Joe Grand (2004)](https://www.elsevier.com/books/hardware-hacking/grand/978-1-932266-83-2)\n- [Hacking the Xbox - Andrew \"bunnie\" Huang (2013)](https://www.nostarch.com/xboxfree)\n- [The Hardware Hacker - Andrew \"bunnie\" Huang (2019)](https://nostarch.com/hardwarehackerpaperback)\n- [The Art of PCB Reverse Engineering - Keng Tiong (2015)](https://www.amazon.in/Art-Pcb-Reverse-Engineering-Unravelling/dp/1499323441)\n- [Manual PCB-RE: The Essentials - Keng Tiong (2021)](https://www.amazon.in/Manual-PCB-RE-Essentials-Keng-Tiong/dp/B0974Z3NDS)\n- [Hardware Security Training, Hands-on! (2023)](https://link.springer.com/book/10.1007/978-3-031-31034-8)\n- [Hardware Security: Challenges and Solutions (2025)](https://www.amazon.in/Hardware-Security-Challenges-Ashutosh-Mishra/dp/3031812123)\n- [Mastering Hardware Hacking (2025)](https://www.amazon.in/Hacking-Machine-Engineering-Hardware-Embedded/dp/B0F29WV5HF)\n- [Ultimate Hardware Hacking Gear Guide](https://github.com/jcldf/ultimate-hardware-hacking-gear-guide-)\n- [Microcontroller Exploits (2024)](https://nostarch.com/microcontroller-exploits)\n- [Engineering Secure Devices - Dominik Merli (2024)](https://nostarch.com/engineering-secure-devices)\n- [Cryptography and Embedded Systems Security - Hou \u0026 Breier (2024)](https://link.springer.com/book/10.1007/978-3-031-62205-2)\n\n#### Firmware and Reverse Engineering\n\n- [The Firmware Handbook - Jack Ganssle (2004)](https://www.amazon.com/Firmware-Handbook-Embedded-Technology/dp/075067606X)\n- [Learning Linux Binary Analysis - Ryan O'Neill (2016)](https://www.packtpub.com/en-bg/product/learning-linux-binary-analysis-9781782167112)\n- [Fuzzing Against the Machine (2023)](https://www.packtpub.com/product/fuzzing-against-the-machine/9781804614976)\n- [Rootkits and Bootkits - Matrosov, Rodionov, Bratus (2019)](https://nostarch.com/rootkits)\n- [Ghidra Software Reverse Engineering 2nd Edition (2025)](https://www.amazon.in/Ghidra-Software-Reverse-Engineering-Beginners-Second/dp/B0DJGQ91R5)\n- [The Ghidra Book 2nd Edition - Nance \u0026 Eagle (2026)](https://nostarch.com/ghidra-book-2e)\n- [The Definitive Handbook on Reverse Engineering Tools (2025)](https://www.amazon.in/Definitive-Handbook-Reverse-Engineering-Tools-ebook/dp/B0F29HLW5B)\n- [x86 Software Reverse-Engineering, Cracking, and Counter-Measures - Domas \u0026 Domas (2024)](https://www.wiley.com/en-us/x86+Software+Reverse-Engineering,+Cracking,+and+Counter-Measures-p-9781394199884)\n- [Fuzzing Android - Zawawy, Rodionov et al. (2026)](https://nostarch.com/fuzzing-android)\n- [From Day Zero to Zero Day - Eugene Lim (2025)](https://nostarch.com/zero-day)\n- [The Spacecraft Hacker's Handbook - Olchawa \u0026 Starcik (2026)](https://nostarch.com/spacecraft-hackers-handbook)\n\n#### IoT Security\n\n- [Abusing the Internet of Things - Nitesh Dhanjani (2015)](https://www.amazon.in/Abusing-Internet-Things-Blackouts-Freakouts-ebook/dp/B013VQ7N36)\n- [IoT Penetration Testing Cookbook - Aaron Guzman \u0026 Aditya Gupta (2017)](https://www.packtpub.com/networking-and-servers/iot-penetration-testing-cookbook)\n- [Practical IoT Hacking: The Definitive Guide (2021)](https://nostarch.com/practical-iot-hacking)\n- [PatrIoT: Practical and Agile Threat Research for IoT (2022)](https://link.springer.com/article/10.1007/s10207-022-00633-3)\n- [The Embedded Linux Security Handbook - St. Onge \u0026 Krishnan (2025)](https://www.packtpub.com/en-us/product/the-embedded-linux-security-handbook-9781835885659)\n- [Securing Smart Things - Massimo Nardone (2026)](https://link.springer.com/book/10.1007/979-8-8688-2367-1)\n\n#### Wireless and RF\n\n- [Inside Radio: An Attack and Defense Guide - Qing Yang, Lin Huang (2018)](https://books.google.co.in/books?id=71NSDwAAQBAJ)\n- [Hack the Airwaves: Advanced BLE Exploitation (2023)](https://www.amazon.in/Hack-Airwaves-Exploitation-Techniques-Cybersecurity/dp/B0CFX2S4ZM)\n- [Practical SDR - David Clark \u0026 Paul Clark (2025)](https://nostarch.com/practical-sdr)\n- [The Art of ARM Assembly, Volume 1 - Randall Hyde (2025)](https://nostarch.com/art-arm-assembly-volume-1)\n- [The Wireless Cookbook - Bill Zimmerman (2026)](https://nostarch.com/wireless-cookbook)\n\n#### Embedded and Mobile\n\n- [Linksys WRT54G Ultimate Hacking - Paul Asadoorian (2007)](https://www.amazon.com/Linksys-WRT54G-Ultimate-Hacking-Asadoorian/dp/1597491667)\n\n#### NFC/RFID\n\n- [Near Field Communication (NFC): From Theory to Practice (2012)](https://www.amazon.in/Near-Field-Communication-NFC-Practice/dp/1119971098)\n- [Security Issues in Mobile NFC Devices - Michael Roland (2024)](https://link.springer.com/book/10.1007/978-3-319-15488-6)\n\n#### Automotive Security\n\n- [The Car Hacker's Handbook - Craig Smith (2016)](https://nostarch.com/carhacking)\n- [Building Secure Automotive IoT Applications - Oka et al. (2024)](https://www.packtpub.com/en-us/product/building-secure-automotive-iot-applications-9781835465509)\n- [Offensive Automotive Cybersecurity - Nasser \u0026 Oka (2025)](https://www.packtpub.com/en-us/product/offensive-automotive-cybersecurity-9781836648628)\n\n#### Industrial and General Security\n\n- [Gray Hat Hacking 5th Edition (2018)](https://www.amazon.in/Gray-Hat-Hacking-Ethical-Handbook-ebook/dp/B07D3J9J4H)\n- [Black Hat Python 2nd Edition (2021)](https://nostarch.com/black-hat-python-2nd-edition)\n- [Attacking Network Protocols - James Forshaw (2017)](https://nostarch.com/networkprotocols)\n- [Securing Industrial Control Systems - Rahman et al. (2026)](https://www.amazon.com/Securing-Industrial-Control-Systems-Technologies/dp/303203017X)\n\n#### White Papers and Reports\n\n- [IOActive: State of Silicon Chip Hacking 2025](https://info.ioactive.com/acton/fs/blocks/showLandingPage/a/34793/p/p-009c/t/page/fm/0)\n\n---\n\n### IoT Series\n\n- [IoT Series I-IV](https://www.artresilia.com/iot-series-i-are-people-ready-to-go/)\n- [Intro to Embedded RE Series](https://voidstarsec.com/blog/intro-to-embedded-part-1)\n\n## Labs and CTFs\n\n### Vulnerable Applications\n\n- [DVID - Damn Vulnerable IoT Device](https://github.com/Vulcainreo/DVID)\n- [IoTGoat - Vulnerable OpenWrt Firmware](https://github.com/scriptingxss/IoTGoat)\n- [BLE CTF](https://github.com/hackgnar/ble_ctf)\n- [Microcorruption](https://microcorruption.com/login)\n- [ARM-X CTF](https://github.com/therealsaumil/armx)\n\n#### Hardware\n\n- [Hardware Hacking 101](https://github.com/rdomanski/hardware_hacking)\n- [Damn Vulnerable Safe](https://insinuator.net/2016/01/damn-vulnerable-safe/)\n- [Sticky Fingers DV-Pi](https://web.archive.org/web/2022/https://whitedome.com.au/re4son/sticky-fingers-dv-pi/)\n\n#### Industrial\n\n- [Damn Vulnerable Chemical Process](https://github.com/satejnik/DVCP-TE)\n- [Damn Vulnerable SS7 Network](https://www.blackhat.com/asia-17/arsenal.html#damn-vulnerable-ss7-network)\n\n#### VoIP\n\n- [Hacklab VulnVoIP](https://www.vulnhub.com/entry/hacklab-vulnvoip,40/)\n\n### CTF Competitions\n\n- [RHme Series (2015-2017)](https://github.com/Riscure/RHme-2015)\n- [IoT Village CTF](https://www.iotvillage.org/)\n  \n---\n\n#### Hardware CTFs\n\n- [RHme-2016](https://github.com/Riscure/Rhme-2016)\n- [RHme-2017](https://github.com/Riscure/Rhme-2017)\n\n#### IoT CTFs\n\n\n#### Embedded/Firmware CTFs\n\n- [Emulate to Exploitate](https://exploitthis.ctfd.io)\n\n#### ARM CTFs\n\n- [Azeria Labs ARM Challenges](https://azeria-labs.com/writing-arm-assembly-part-1/)\n\n### Continuous Learning Platforms\n\n- [Hack The Box](https://www.hackthebox.eu/)\n- [Root Me](https://www.root-me.org/)\n- [Pwnable.kr](https://pwnable.kr/)\n- [CTFtime](https://ctftime.org/)\n\n### Lab Setup\n\n- [Webthings Gateway - Raspberry Pi](https://webthings.io/)\n\n---\n\n## Research and Community\n\n### Technical Research\n\n- [Dropcam Hacking](https://www.defcon.org/images/defcon-22/dc-22-presentations/Moore-Wardle/DEFCON-22-Colby-Moore-Patrick-Wardle-Synack-DropCam-Updated.pdf)\n- [LED Light Hacking](https://youtu.be/Nnb2ct3hc68)\n- [PS4 Jailbreak Status](https://wololo.net/ps4-jailbreak-ps4-cfw4dummies/)\n- [Lenovo Watch X Privacy Issues](https://www.checkmarx.com/blog/lenovo-watch-watching-you/)\n- [Smart Scale Privacy Issues](https://www.checkmarx.com/blog/smart-scale-privacy-issues-iot/)\n- [Besder IP Camera Security Analysis](https://github.com/KostasEreksonas/Besder-6024PB-XMA501-ip-camera-security-investigation)\n\n### Blogs\n\n- [Team82 Research](https://claroty.com/team82/research)\n- [Voidstarsec](https://voidstarsec.com/blog/)\n- [wrongbaud](https://wrongbaud.github.io/)\n- [Firmware Analysis](https://fwanalysis.blogspot.com/)\n- [Exploitee.rs](https://www.exploitee.rs/)\n- [Payatu Blog](https://payatu.com/blog/)\n- [Raelize Blog](https://raelize.com/blog/)\n- [JCJC Dev](https://jcjc-dev.com/)\n- [W00tsec](https://w00tsec.blogspot.in/)\n- [Devttys0](https://www.devttys0.com/)\n- [Embedded Bits](https://embeddedbits.org/)\n- [Keenlab](https://keenlab.tencent.com/en/)\n- [Courk.cc](https://courk.cc/)\n- [IoT Security Wiki](https://iotsecuritywiki.com/)\n- [Cybergibbons](https://cybergibbons.com/)\n- [Firmware.RE](https://firmware.re/)\n- [K3170makan](https://k3170makan.medium.com/)\n- [Tclaverie](https://blog.tclaverie.eu/)\n- [Besimaltinok](https://web.archive.org/web/2022/http://blog.besimaltinok.com/category/iot-pentest/)\n- [Ctrlu](https://ctrlu.net/)\n- [IoT Pentest](https://iotpentest.com/)\n- [Duo Decipher](https://duo.com/decipher/)\n- [Sp3ctr3](https://www.sp3ctr3.me)\n- [0x42424242](https://blog.0x42424242.in/)\n- [Dantheiotman](https://dantheiotman.com/)\n- [Danman](https://blog.danman.eu/)\n- [Quentinkaiser](https://quentinkaiser.be/)\n- [Quarkslab](https://blog.quarkslab.com)\n- [Ice9](https://blog.ice9.us/)\n- [F-Secure Labs](https://labs.f-secure.com/)\n- [MG.lol](https://mgsloan.com/posts/)\n- [CJHackerz](https://cjhackerz.net/)\n- [Bunnie's Blog](https://github.com/sponsors/bunnie/)\n- [Synacktiv Publications](https://www.synacktiv.com/publications.html)\n- [Cr4.sh](https://blog.cr4.sh/)\n- [Ktln2](https://ktln2.org/)\n- [Naehrdine](https://naehrdine.blo","projects_url":"https://awesome.ecosyste.ms/api/v1/lists/v33ru%2Fawesome-connected-things-sec/projects"}