awesome-connected-things-sec
A Curated list of Security Resources for all connected things
https://github.com/V33RU/awesome-connected-things-sec
Last synced: 1 day ago
JSON representation
-
Cloud and Backend Security
-
AWS IoT Security
- AWS Penetration Testing Policy
- AWS Pentesting Guide - HackerOne
- A few notes on AWS Nitro Enclaves
- Pacu - AWS Exploitation Framework
- ScoutSuite - Multi-cloud Security Auditing
- Prowler - Cloud Security Assessment
- Comprehensive AWS Pentesting Guide - BreachLock
- AWS Pentest Methodology - MorattiSec
- AWS Penetration Testing Methodology - Rootshell
- AWS Penetration Testing Techniques 2025
- CloudFox - Cloud Attack Paths
- S3Scanner - Leaky Bucket Discovery
- Cloudfoxable Labs
- AWS Security Pentesting Resources
- 7 Best AWS Pentesting Tools 2026
- PayloadsAllTheThings - AWS Pentest
- 7 Best AWS Pentesting Tools 2026
-
Firebase / Cloud Misconfigurations
-
-
Defensive Security
-
Incident Response
-
Secure Development
- Embedded Linux Hardening
- OWASP IoT Project
- ETSI EN 303 645 - Cyber Security for Consumer IoT
- Compiler Options Hardening Guide for C and C++
- Linux Hardening Guide
- Docker Security - Step-by-Step Hardening
- How To Secure A Linux Server
- Zephyr RTOS Security Features
- IoT Device Hardening Best Practices
- NIST IoT Cybersecurity Framework
- NIST IoT Cybersecurity Framework
- NIST SP 800-213 - IoT Device Cybersecurity Guidance
- NISTIR 8259 - Foundational Cybersecurity Activities for IoT Manufacturers
- OWASP IoT Top 10 (2018)
- IoT Device Hardening Best Practices
- OWASP IoT Top 10 (2018)
- OWASP IoT Top 10 (2018)
-
Threat Modeling
- STRIDE Threat Model Guide - Practical DevSecOps
- OWASP Threat Modeling Process
- STRIDE-based Threat Modeling for IoT Precision Agriculture
- What is STRIDE in Threat Modeling - Security Compass
- Threat Modeling with ATT&CK - MITRE
- What is Threat Modeling - Fortinet
- STRIDE Threat Modeling for IoT Smart Home
- STRIDE Threat Modeling for Smart Solar Energy Systems
- STRIDE Threat Modeling for IoT Healthcare Systems
- STRIDE for IoT Agriculture - IEEE
- Threat Modeling with ATT&CK - MITRE
-
-
Firmware Security
-
ARM Exploitation
- Azeria Labs ARM Tutorials
- ARM Exploitation for IoT
- Damn Vulnerable ARM Router (DVAR)
- Exploit Education
- ARMv8 AArch64/ARM64 Full Beginner's Assembly Tutorial
- A Noobs Guide to ARM Exploitation
- ARM64 Reversing And Exploitation Series (8ksec) - Parts 1-10
- AArch64 memory and paging
- We are ARMed no more ROPpery Here
- A Guide to ARM64 / AArch64 Assembly on Linux
- A Guide to ARM64 / AArch64 Assembly on Linux
- A Guide to ARM64 / AArch64 Assembly on Linux
-
Binary Analysis
-
Dynamic Analysis and Emulation
- Firmadyne - Automated Firmware Emulation
- QEMU
- PANDA - Architecture-Neutral Dynamic Analysis
- Avatar2 - Dynamic Firmware Analysis
- Renode - Embedded Systems Emulator
- Unicorn Engine - CPU Emulator
- S2E - Selective Symbolic Execution
- FirmWire - Baseband Firmware Emulation
- Qiling Framework
- Firmware Emulation with QEMU
- Emulating ARM Router Firmware - Azeria Labs
- Qiling and Binary Emulation for Automatic Unpacking
- IoT Binary Analysis and Emulation Part 1
- Cross Debugging for ARM/MIPS with QEMU
- QEMU + Buildroot 101
- Emulating IoT Firmware Made Easy
- Adaptive Emulation Framework for Multi-Architecture IoT
- Automatic Firmware Emulation through Invalidity-guided Knowledge Inference
- Debugging D-Link: Emulating Firmware and Hacking Hardware
- SAME70 Emulator
- Emulating RH850 architecture with Unicorn Engine
- Icicle: A Re-designed Emulator for Grey-Box Firmware Fuzzing
- Challenges and Pitfalls while Emulating Six Current Icelandic Household Routers
- My Emulation Goes to the Moon... Until False Flag
- How to Emulate Android Native Libraries Using Qiling
- FirmAE - Firmware Analysis and Emulation
- HALucinator
- SymQEMU
- Bochs - x86 Emulator
- Emulate Until You Make it
- Simulating and Hunting Firmware Vulnerabilities with Qiling
- FirmAE - Firmware Analysis and Emulation
- HALucinator
- SymQEMU
- Bochs - x86 Emulator
- Emulate Until You Make it
- Icicle: A Re-designed Emulator for Grey-Box Firmware Fuzzing
- How to Emulate Android Native Libraries Using Qiling
-
Extraction
- Firmware Samples - firmware.center
- Hardware Hacking Tutorial: Dumping and Reversing Firmware
- Router Analysis Part 1: UART Discovery and SPI Flash Extraction
- BasicFUN Series: Hardware Analysis / SPI Flash Extraction
- BasicFUN Series: Reverse Engineering Firmware / Reflashing SPI Flash
- Retrofitting encrypted firmware is a Bad Idea
-
Fundamentals
-
Online Assemblers
-
OTA Update Security
- IoT Firmware Security and Update Mechanisms
- Implementing OTA Updates for IoT Devices
- Secure OTA Boot Chains and Firmware Verification
- The Key to Firmware Security in Connected IoT Devices
- Security Considerations for OTA Updates - Stack Overflow
- Top 10 IoT Vulnerabilities - OTA Update Attacks
- Updating IoT Devices 2025: Best Practices
- Review of IoT Firmware Vulnerabilities and Auditing Techniques
- Secure OTA Firmware Update Mechanism (PDF)
- Security Considerations for OTA Updates - Stack Overflow
-
Reverse Engineering Tools
- GDB
- Radare2
- Binary Ninja
- OllyDbg
- x64dbg
- Hopper
- Immunity Debugger
- PEiD
- Ghidra
- Cutter - GUI for Radare2
- RetDec - Decompiler
- Diaphora - Binary Diffing
- Angr - Binary Analysis
- Frida - Dynamic Instrumentation
- Ret-sync
- Reversing ESP8266 Firmware
- Reversing Firmware with Radare
- Finding Bugs in Netgear Router
- Automating Binary Vulnerability Discovery with Ghidra and Semgrep
- Ghidriff - Ghidra Binary Diffing Engine
- The rev.ng decompiler goes open source
- Intro to Cutter
- pyghidra-mcp: Headless Ghidra MCP Server
- Mindshare: Using Binary Ninja API to Detect Potential Use-after-free Vulnerabilities
- Reverse Engineering with Ghidra: Breaking Firmware Encryption
- Ghidra 101: Cursor Text Highlighting
- Ghidra 101: Decoding Stack Strings
- Extending Ghidra Part 1: Setting up a Development Environment
- Binary type inference in Ghidra
- Writing a Ghidra processor module
- Debugger Ghidra Class
- Expanding the Dragon: Adding an ISA to Ghidra
- Immunity Debugger
- Debugger Ghidra Class
- Expanding the Dragon: Adding an ISA to Ghidra
- Immunity Debugger
- Expanding the Dragon: Adding an ISA to Ghidra
- Reverse Engineering and Patching with Ghidra
- Ghidra nanoMIPS ISA module
-
Router Exploitation
- Hunting for Unauthenticated n-days in Asus Routers
- Pulling MikroTik into the Limelight
- Exploiting MikroTik RouterOS Hardware with CVE-2023-30799
- Rooting Xiaomi WiFi Routers
- Route to Safety: Navigating Router Pitfalls
- ROPing our way to RCE
- ROPing Routers from scratch: Tenda Ac8v4
- PwnAgent: A One-Click WAN-side RCE in Netgear RAX Routers
- Reversing, Discovering, And Exploiting A TP-Link Router Vulnerability - CVE-2024-54887
- Exploiting Zero-Day (CVE-2025-9961) Vulnerability in the TP-Link AX10 Router
- FiberGateway GR241AG - Full Exploit Chain
- Blackbox-Fuzzing of IoT Devices Using the Router TL-WR902AC
- Rooting the TP-Link Tapo C200 Rev.5
- Netgear Orbi: Introduction, UART Access, Recon
- Netgear Orbi: Crashes in SOAP-API
- Netgear Orbi: NDay Exploit CVE-2020-27861
- The Last Breath of Our Netgear RAX30 Bugs
- TP-Link TDDP Buffer Overflow Vulnerability
- Pwn2Own Tokyo 2020: Defeating the TP-Link AC1750
- TP-Link Tapo c200 Camera Unauthenticated RCE (CVE-2021-4045)
- Patch Diffing a Cisco RV110W Firmware Update - Part 1
- CVE-2024-20356: Jailbreaking a Cisco appliance to run DOOM
- Flashback Connects - Cisco RV340 SSL VPN RCE
- Netgear Orbi: Introduction, UART Access, Recon
- Netgear Orbi: Crashes in SOAP-API
- Route to Safety: Navigating Router Pitfalls
- Netgear Orbi: NDay Exploit CVE-2020-27861
- Exploiting MikroTik RouterOS Hardware with CVE-2023-30799
- Puckungfu 2: Another NETGEAR WAN Command Injection
-
Router Firmware Analysis
-
Categories
Firmware Security
221
Wireless Protocols
178
Research and Community
124
Network and Web Protocols
106
Learning Resources
91
Hardware Attacks
87
Tools
80
🗂️ Resource Index
45
Mobile Application Security
38
Defensive Security
31
Industrial and Automotive
30
Labs and CTFs
29
Cloud and Backend Security
20
Payment Systems
5
MCP / AI Agent
1
Sub Categories
Bluetooth / BLE
63
Books
62
Blogs
58
Interface Attacks
45
Reverse Engineering Tools
41
Device-Specific Research
39
Dynamic Analysis and Emulation
38
mTLS
37
MQTT
34
CoAP
30
Router Exploitation
29
Android
29
Cellular (GSM/LTE/5G)
28
Side-Channel and Fault Injection
24
Fuzzing Tools
24
Hardware Tools
22
Books for IoT Penetration Testing
18
RTOS Security
18
AWS IoT Security
17
Secure Development
17
UEFI Security
17
Zigbee / Z-Wave
17
Automotive Security
16
Fundamentals
16
Secure Boot
15
Wi-Fi
15
Vulnerable Applications
15
Matter / Thread
14
LoRa / LoRaWAN
14
Search Engines
13
Static Analysis Tools
13
ARM Exploitation
12
RF Fundamentals
11
Software Tools
11
Threat Modeling
11
OTA Update Security
10
Router Firmware Analysis
10
Pentesting Operating Systems
10
ICS/SCADA
9
IoT Web and Message Services
9
iOS
9
YouTube Channels
8
Vulnerability Guides
8
Technical Research
7
TrustZone and TEE Research
7
CTF Competitions
7
Extraction
6
IoT hardware Overview and Hacking
6
TETRA
5
IoT Protocols Overview
5
Cheatsheets
5
Memory Extraction
5
EV Chargers
5
Pentesting Guides
4
NFC/RFID
4
Lab Setup
4
Online Assemblers
4
ATM Hacking
4
Pwn2Own Research
4
Researchers to Follow
4
USB
3
Firebase / Cloud Misconfigurations
3
Incident Response
3
Continuous Learning Platforms
3
DECT (Digital Enhanced Cordless Telecommunications)
3
Secure Boot Bypasses
3
Community Platforms
3
Training Platforms
2
Cellular Hacking GSM BTS
2
IoT Series
2
Villages
2
PCIe and DMA Attacks
2
BLE Intro and SW-HW Tools to pentest
1
Payment Village
1
Blogs for IoT Pentest
1
Storage Medium
1
Introduction
1
Pentesting Firmwares and emulating and analyzing
1
Binary Analysis
1
Exploitation Tools
1
UWB (Ultra-Wideband)
1
Symlink Attacks
1
Zigbee ALL Stuff
1
Bluetooth Reverse Engineering
1
Technical Research and Hacking
1
Keywords
security
25
reverse-engineering
12
python
11
iot
10
fuzzing
7
hacking
6
linux
6
bluetooth
6
embedded
6
aws
5
ble
5
android
5
security-tools
5
qemu
4
framework
4
firmware
4
awesome
4
analysis
4
binary-analysis
3
disassembler
3
exploitation
3
sdr
3
5g
3
penetration-testing
3
gcp
3
cloud
3
hardware
3
mqtt
3
x86
3
testing
3
firmware-analysis
3
firmware-tools
3
arm
3
awesome-list
3
debugger
2
wireless
2
binary
2
azure
2
sniffer
2
uefi
2
lorawan
2
lora
2
emulator
2
cypress
2
lte
2
broadcom
2
spoofing
2
embedded-systems
2
infosec
2
filesystem
2