awesome-connected-things-sec
A Curated list of Security Resources for all connected things
★ 3.5k⑂ 579 forksMITupdated 2 months ago
visit the demo
git clone https://github.com/V33RU/awesome-connected-things-sec.gitV33RU/awesome-connected-things-secREADME.mdfork it — it’s yours
🔐 Awesome Connected Things Security Resources
A curated repository of IoT, Embedded, Industrial & Automotive, Core Tech security knowledge.
Table of Contents
- Hardware Attacks
- Wireless Protocols
- Firmware Security
- Network and Web Protocols
- Cloud and Backend Security
- Mobile Application Security
- Industrial and Automotive
- Payment Systems
- Tools
- Defensive Security
- Learning Resources
- Labs and CTFs
- Research and Community
- Contributing
- License
Hardware Attacks
Fundamentals
- IoT Hardware Guide
- Intro to Hardware Hacking - Dumping Your First Firmware
- An Introduction to Hardware Hacking
- Hardware Toolkits for IoT Security Analysis
- Hardware Hacking for IoT Devices - Offensive IoT Exploitation
Interface Attacks
UART
- Identifying UART Interface
- Serial Terminal Basics
- Reverse Engineering Serial Ports
- Intro to Embedded RE: UART Discovery and Firmware Extraction via UBoot
- Using UART to Connect to a Chinese IP Cam
- A Journey into IoT Hardware Hacking: UART
- Accessing and Dumping Firmware Through UART
- UART Connections and Dynamic Analysis on Linksys e1000
- UARTBruteForcer
JTAG
- Hardware Hacking 101: Introduction to JTAG
- How to Find the JTAG Interface
- Analyzing JTAG
- Bus Pirate JTAG Connections with OpenOCD
- Extracting Firmware from External Memory via JTAG
- The Hitchhacker's Guide to iPhone Lightning and JTAG Hacking
- Debugging AVR Microcontrollers Through JTAG
SWD (Serial Wire Debug)
- SWD Protocol Overview - HardBreak Wiki
- Unveiling Vulnerabilities: Exploring SWD Attack Surface in Hardware
- Introduction to ARM Serial Wire Debug Protocol
- Serial Wire Debug and CoreSight Architecture
- LibSWD - Serial Wire Debug Open Library
- Hardware Hacking and Exploitation Bootcamp - SWD
SPI
- Hardware Hacking 101: Identifying and Dumping eMMC Flash
- Dumping Firmware from Router Using Bus Pirate - SPI
- Extracting Flash Memory over SPI
- Extracting Firmware from Embedded Devices (SPI NOR Flash)
- How to Flash Chip of a Router with a Programmer
- TPM 2.0: Extracting Bitlocker Keys Through SPI
I2C
- IoT Security Part 16: Hardware Attack Surface I2C
- I2C Exploitation - HackTricks
- Non-invasive I2C Hardware Trojan Attack Vector (PDF)
- Hardware Hacking: I2C Injection with Bus Pirate
- Safeguarding SPI, I2C, and I3C Protocols
TPM
- Introduction to TPM (Trusted Platform Module)
- Trusted Platform Module Security Defeated in 30 Minutes
Memory Extraction
eMMC
- eMMC Protocol
- RPMB: A Secret Place Inside the eMMC
- eMMC Data Recovery from Damaged Smartphone
- Unleash Your Smart-Home Devices: Vacuum Cleaning Robot Hacking
- Hands-On IoT Hacking: Rapid7 at DEF CON 30
Side-Channel and Fault Injection
Fundamentals
- Side Channel Attacks - Yifan Lu
- Attacks on Implementations of Secure Systems
- Fuzzing, Binary Analysis, IoT Security Collection
Glitching Attacks
- NAND Glitching Attack on Wink Hub
- Voltage Glitching with Crowbars Tutorial
- Voltage Glitching Attack using iCEstick Glitcher
- FPGA Glitching and Side Channel Attacks - Samy Kamkar
- Hardware Power Glitch Attack - rhme2
- Keys in Flash - Glitching AES Keys from Arduino
- Implementing Practical Electrical Glitching Attacks
- How to Voltage Fault Injection
- Glitcher Part 1 - Reproducible Voltage Glitching on STM32 Microcontrollers
- STM32L05 Voltage Glitching
Power Analysis
Other Microcontrollers
- Dumping the Amlogic A113X Bootrom
- Retreading The AMLogic A113X TrustZone Exploit Process
- Reverse Engineering an Unknown Microcontroller
- Hacking Microcontroller Firmware Through a USB
- There's A Hole In Your SoC: Glitching The MediaTek BootROM
PCIe and DMA Attacks
- A Practical Tutorial on PCIe for Total Beginners on Windows - Part 1
- A Practical Tutorial on PCIe for Total Beginners on Windows - Part 2
- PCIe DMA Attack against a Secured Jetson Nano (CVE-2022-21819)
Wireless Protocols
RF Fundamentals
- Complete Course in Software Defined Radio - Michael Ossmann
- Awesome SDR - Curated SDR Resources
- Understanding Radio
- Introduction to Software Defined Radio
- Introduction to GNU Radio Companion
- Creating a Flow Graph in GNU Radio Companion
- Analyzing Radio Signals 433MHz
- Recording Specific Radio Signals
- Replay Attacks with Raspberry Pi and rpitx
- Reverse Engineering a Car Key Fob Signal
- GRCON 2021 - Capture the Signal
Bluetooth / BLE
Fundamentals
- Awesome Bluetooth Security
- BLE-NullBlr: Step by Step Guide to BLE Understanding and Exploiting
- Traffic Engineering in a Bluetooth Piconet
- BLE Characteristics: A Beginner's Tutorial
- Intro to Bluetooth Low Energy (PDF)
- Bluetooth LE Security Study Guide
- Reverse Engineering BLE Devices
- My Journey Towards Reverse Engineering a Smart Band — Bluetooth-LE RE
Exploitation Techniques
- Intel Edison as Bluetooth LE Exploit Box
- Reverse Engineering and Exploiting a Smart Massager
- I Hacked MiBand 3
- GATTacking Bluetooth Smart Devices
- Examining the August Smart Lock
- Practical Introduction to BLE GATT Reverse Engineering
- MojoBox - Yet Another Not So Smartlock
- Bluetooth Smartlocks
- Bluetooth Beacon Vulnerability
- Denial of Pleasure: Attacking Unusual BLE Targets with a Flipper Zero
- Grand Theft Auto: A peek of BLE relay attack
- How I Hacked Smart Lights: CVE-2022-47758
- NFC Relay Attack on Tesla Model Y
Vulnerability Research
- Finding Bugs in Bluetooth
- Sweyntooth Vulnerabilities
- BrakTooth: Causing Havoc on Bluetooth Link Manager
- BLUFFS: Bluetooth Forward and Future Secrecy Attacks (CVE-2023-24023)
- AirDrop Leak - Sniffing BLE Traffic from Apple Devices
- BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution
- BRAKTOOTH: Causing Havoc on Bluetooth Link Manager (PDF)
- Norec Attack: Stripping BLE encryption from Nordic's Library (CVE-2020-15509)
- BlueDucky - HID Injection on Unpatched Android (CVE-2023-45866)
- Microsoft Bluetooth Driver Spoofing - CVE-2024-21306
- GATTacker - BLE MITM Proxy
- Bluetooth Auracast / LE Audio Security Analysis
Conference Talks
- Blue2thprinting: WTF Am I Even Looking At?
- Open Wounds: Last 5 Years Have Left Bluetooth to Bleed
- Sniffing Bluetooth Through My Mask During the Pandemic
Tools - Software
- Bluing - Intelligence Gathering for Bluetooth
- BlueToolkit - Bluetooth Classic Vulnerability Testing
- btproxy
- hcitool and bluez
- Testing with GATT Tool
- crackle - Cracking BLE Encryption
- bettercap
- BtleJuice - Bluetooth Smart MITM Framework
- GATTacker
- BTLEjack - BLE Swiss Army Knife
- DEDSEC Bluetooth Exploit
- BrakTooth ESP32 PoC
- SweynTooth BLE Attacks
- ESP32 Bluetooth Classic Sniffer
- Bluetooth Hacking Collection
Tools - Hardware
Tools
Hacking Bluetooth Coffee Machines
- Hacking Bluetooth to Brew Coffee from Github Actions - Part 1
- Hacking Bluetooth to Brew Coffee from Github Actions - Part 2
- Hacking Bluetooth to Brew Coffee from Github Actions - Part 3
Zigbee / Z-Wave
Fundamentals
Exploitation
- Hacking IoT Devices with Attify Zigbee Framework
- Zigator: Analyzing Security of Zigbee-Enabled Smart Homes
- Security Analysis of Zigbee with Zigator and GNU Radio
- Low-Cost ZigBee Selective Jamming
Tools - Software
Tools - Hardware
LoRa / LoRaWAN
- LoRaWAN Security Overview - Tektelic
- Security Vulnerabilities in LoRaWAN
- Low Powered and High Risk: Attacks on LoRaWAN Devices
- LAF - LoRaWAN Auditing Framework
- ChirpOTLE - LoRaWAN Security Framework
Fundamentals
Exploitation
- Millions of Devices Using LoRaWAN Exposed - SecurityWeek
- Do You Blindly Trust LoRaWAN Networks? - IOActive
- LoRaWAN Encryption Keys Easy to Crack - Threatpost
- LoPT: LoRa Penetration Testing Tool (PDF)
Tools
Matter / Thread
Fundamentals
- Matter Standard - CSA-IoT
- Matter Protocol Wikipedia
- Matter Protocol Complete Guide 2025
- How to Secure Smart Home Devices with Matter
- Smart Home Device Solutions for Matter - DigiCert
Security Research
- Security Vulnerabilities and Attack Scenarios in Smart Home with Matter
- Trust Matters: Uncovering Vulnerabilities in Matter Protocol - Nozomi
- Matter over Thread Security
- State-of-the-Art Review on IoT Wireless PAN Protocol Security
- Matter Smart Home - Krasamo
- Threadbare: Practical Attacks on Thread Networks (Black Hat USA 2024)
- Matter Specification 1.3 - Connectivity Standards Alliance
- Thread Group Security Analysis
Cellular (GSM/LTE/5G)
- Awesome Cellular Hacking
- Introduction to GSM Security
- Breaking LTE on Layer Two
- 5Ghoul - 5G NR Attacks and Fuzzing
- Exploiting CSN.1 Bugs in MediaTek Basebands
- SIM Hijacking
- SigPloit - Telecom Signaling Exploitation Framework
- LTE Sniffer
- 5G NR Jamming, Spoofing and Sniffing
- LTrack: Stealthy Tracking of Mobile Phones in LTE
- Open5GS - Open Source 5G/4G Core
- srsRAN 5G - Open Source 5G Stack
- SCAT - Signaling Collection and Analysis Tool for Cellular
Fundamentals
- GSM Security Part 2
- What is Base Transceiver Station
- Introduction to SS7 Signaling
- SS7 Network Architecture
- Introduction to SIGTRAN
Exploitation
- How to Build Your Own Rogue GSM BTS
- GSM Vulnerabilities with USRP B200
- Security Testing 4G (LTE) Networks
- Case Study of SS7/SIGTRAN Assessment
Tools
NFC/RFID
DECT (Digital Enhanced Cordless Telecommunications)
- Real Time Interception of DECT Cordless Telephone
- Eavesdropping on Unencrypted DECT Voice Traffic
- Decoding DECT Voice Traffic: In-depth Explanation
Wi-Fi
Protocol Vulnerabilities
- Framing Frames: Bypassing Wi-Fi Encryption by Manipulating Transmit Queues
- Man-in-the-Middle Attacks without Rogue AP: When WPAs Meet ICMP Redirects
- WPAxFuzz: Sniffing Out Vulnerabilities in Wi-Fi Implementations
- Untangling the Knot: Breaking Access Control in Home Wireless Mesh Networks
Exploitation
- Over The Air: Exploiting Broadcom's Wi-Fi Stack (Part 1)
- Over The Air: Exploiting Broadcom's Wi-Fi Stack (Part 2)
- Over The Air: Exploiting The Wi-Fi Stack on Apple Devices
- Reverse-engineering Broadcom wireless chipsets
- Exploiting Qualcomm WLAN and Modem Over the Air
- Windows Wi-Fi Driver RCE Vulnerability – CVE-2024-30078
- When a Wi-Fi SSID Gives You Root on an MT02 Repeater - Part 1
- When a Wi-Fi SSID Gives You Root on an MT02 Repeater - Part 2
Reverse Engineering WiFi
- Reverse Engineering WiFi on RISC-V BL602
- Unveiling secrets of the ESP32: creating an open-source MAC Layer
- Unveiling secrets of the ESP32: reverse engineering RX
USB
UWB (Ultra-Wideband)
TETRA
- All cops are broadcasting: TETRA under scrutiny
- TETRA:BURST - Five Vulnerabilities in TETRA Standard (Midnight Blue)
- TETRA:BURST 2:ELECTRIC BOOGALOO - End-to-End Encryption Broken (BlackHat USA 2025)
- TETRA Decoder - Open Source TETRA Receiver
- Practical TETRA Sniffing with SDR
Firmware Security
Fundamentals
- Introduction to Firmware Analysis - OWASP
- OWASP Firmware Security Testing Methodology
- IoT Security Verification Standard (ISVS)
- Reversing 101
- Hands-on Firmware Extraction, Exploration, and Emulation
Extraction
- Router Analysis Part 1: UART Discovery and SPI Flash Extraction
- Hardware Hacking Tutorial: Dumping and Reversing Firmware
- Firmware Samples - firmware.center
- BasicFUN Series: Hardware Analysis / SPI Flash Extraction
- BasicFUN Series: Reverse Engineering Firmware / Reflashing SPI Flash
- Retrofitting encrypted firmware is a Bad Idea
Static Analysis Tools
- EMBA - Embedded Linux Firmware Analyzer
- FACT - Firmware Analysis and Comparison Tool
- Binwalk v3
- Firmwalker
- fwanalyzer
- fwhunt-scan - UEFI Firmware Analysis
- ByteSweep
- BINSEC
- unblob - Extraction Framework
- Checksec.sh
- Firmware Modification Kit
Dynamic Analysis and Emulation
- Firmadyne - Automated Firmware Emulation
- FirmAE - Firmware Analysis and Emulation
- QEMU
- PANDA - Architecture-Neutral Dynamic Analysis
- Avatar2 - Dynamic Firmware Analysis
- Renode - Embedded Systems Emulator
- Unicorn Engine - CPU Emulator
- Qiling Framework
- HALucinator
- FirmWire - Baseband Firmware Emulation
- SymQEMU
- S2E - Selective Symbolic Execution
- Bochs - x86 Emulator
- SAME70 Emulator
- Emulate Until You Make it
Emulation Tutorials
- Firmware Emulation with QEMU
- Emulating ARM Router Firmware - Azeria Labs
- Emulating IoT Firmware Made Easy
- IoT Binary Analysis and Emulation Part 1
- Cross Debugging for ARM/MIPS with QEMU
- QEMU + Buildroot 101
- Simulating and Hunting Firmware Vulnerabilities with Qiling
- Qiling and Binary Emulation for Automatic Unpacking
- Debugging D-Link: Emulating Firmware and Hacking Hardware
- Adaptive Emulation Framework for Multi-Architecture IoT
- Automatic Firmware Emulation through Invalidity-guided Knowledge Inference
- Emulating RH850 architecture with Unicorn Engine
- Icicle: A Re-designed Emulator for Grey-Box Firmware Fuzzing
- Challenges and Pitfalls while Emulating Six Current Icelandic Household Routers
- My Emulation Goes to the Moon... Until False Flag
- How to Emulate Android Native Libraries Using Qiling
OTA Update Security
Fundamentals
- IoT Firmware Security and Update Mechanisms
- Implementing OTA Updates for IoT Devices
- Secure OTA Boot Chains and Firmware Verification
- The Key to Firmware Security in Connected IoT Devices
- Security Considerations for OTA Updates - Stack Overflow
Attack Vectors
- Top 10 IoT Vulnerabilities - OTA Update Attacks
- Updating IoT Devices 2025: Best Practices
- Review of IoT Firmware Vulnerabilities and Auditing Techniques
RTOS Security
Zephyr RTOS
- Zephyr RTOS GitHub
- Zephyr Vulnerabilities List
- NCC Group Zephyr and MCUboot Security Assessment
- 26 Flaws in Zephyr and MCUboot
- Tackling Security in Zephyr RTOS
- Enhancing Security with Zephyr RTOS
FreeRTOS
- FreeRTOS 13 Vulnerabilities in TCP/IP Stack
- Exploiting Memory Corruption in FreeRTOS - ShmooCon
- RTOS Security Analysis - USENIX
- Dynamic Vulnerability Patching for RTOS
- AWS FreeRTOS Vulnerabilities
Reverse Engineering Tools
- Ghidra
- IDA Pro
- Radare2
- Cutter - GUI for Radare2
- Binary Ninja
- GDB
- RetDec - Decompiler
- Diaphora - Binary Diffing
- Angr - Binary Analysis
- Frida - Dynamic Instrumentation
- Ret-sync
- OllyDbg
- x64dbg
- Hopper
- Immunity Debugger
- PEiD
- Ghidriff - Ghidra Binary Diffing Engine
- The rev.ng decompiler goes open source
- Intro to Cutter
- pyghidra-mcp: Headless Ghidra MCP Server
- Mindshare: Using Binary Ninja API to Detect Potential Use-after-free Vulnerabilities
Reverse Engineering Tutorials
- Reverse Engineering and Patching with Ghidra
- Reverse Engineering with Ghidra: Breaking Firmware Encryption
- Reversing Firmware with Radare
- Reversing ESP8266 Firmware
- Automating Binary Vulnerability Discovery with Ghidra and Semgrep
- Finding Bugs in Netgear Router
Ghidra Tutorials
- Debugger Ghidra Class
- Ghidra 101: Cursor Text Highlighting
- Ghidra 101: Decoding Stack Strings
- Extending Ghidra Part 1: Setting up a Development Environment
- Expanding the Dragon: Adding an ISA to Ghidra
- Ghidra nanoMIPS ISA module
- Binary type inference in Ghidra
- Writing a Ghidra processor module
Online Assemblers
ARM Exploitation
- Azeria Labs ARM Tutorials
- ARM Exploitation for IoT
- Damn Vulnerable ARM Router (DVAR)
- Exploit Education
- A Guide to ARM64 / AArch64 Assembly on Linux
- ARMv8 AArch64/ARM64 Full Beginner's Assembly Tutorial
- A Noobs Guide to ARM Exploitation
- ARM64 Reversing And Exploitation Series (8ksec) - Parts 1-10
- AArch64 memory and paging
- We are ARMed no more ROPpery Here
Binary Analysis
Secure Boot
Development
Bypasses
- Pwn the ESP32 Secure Boot
- Pwn ESP32 Forever: Flash Encryption and Secure Boot Keys Extraction
- ESP32 Secure Boot Bypass (CVE-2020-13629)
- Amlogic S905 SoC: Bypassing Secure Boot
- Defeating Secure Boot with Symlink Attacks
- PS4 Secure Boot Hacking - Fail0verflow
- Dell BIOS Vulnerabilities - BIOSDisconnect
- U-Boot USB DFU Vulnerability (CVE-2022-2347)
- Breaking Secure Boot on Silicon Labs Gecko
UEFI Security
- Using Symbolic Execution to Detect UEFI Vulnerabilities
- HP Enterprise UEFI Vulnerabilities
- Emulating and Exploiting UEFI Firmware
- The Dark Side of UEFI: A technical Deep-Dive into Cross-Silicon Exploitation
- Inside the LogoFAIL PoC: From Integer Overflow to Arbitrary Code Execution
- PixieFail: Nine vulnerabilities in Tianocore's EDK II IPv6 network stack
- For Science! - Using an Unimpressive Bug in EDK II
- Hydroph0bia: SecureBoot bypass for Insyde H2O
- PKfail: Untrusted Platform Keys in UEFI Firmware (Binarly, 2024)
- LogoFAIL: Image Parsing Vulnerabilities in System Firmware (Binarly)
- BlackLotus UEFI Bootkit Analysis - ESET
- Bootkitty: First UEFI Bootkit for Linux (ESET, 2024)
- UEFI Firmware Rootkits: Myths and Reality (BlackHat 2024)
- CVE-2024-0762 - PixieFail Followup TPM Bypass
Symlink Attacks
Router Firmware Analysis
- A Journey into IoT: Discover Components and Ports
- A Journey into IoT: Firmware Dump and Analysis
- A Journey into IoT: Radio Communications
- A Journey into IoT: Internal Communications
- Dynamic Analysis of Firmware Components in IoT Devices
- RV130X Firmware Analysis
- TP-Link Firmware Decryption C210 V2 cloud camera bootloaders
Router Exploitation
- Hunting for Unauthenticated n-days in Asus Routers
- Pulling MikroTik into the Limelight
- Exploiting MikroTik RouterOS Hardware with CVE-2023-30799
- Rooting Xiaomi WiFi Routers
- Route to Safety: Navigating Router Pitfalls
- ROPing our way to RCE
- ROPing Routers from scratch: Tenda Ac8v4
- PwnAgent: A One-Click WAN-side RCE in Netgear RAX Routers
- Puckungfu 2: Another NETGEAR WAN Command Injection
- Reversing, Discovering, And Exploiting A TP-Link Router Vulnerability — CVE-2024–54887
- Exploiting Zero-Day (CVE-2025–9961) Vulnerability in the TP-Link AX10 Router
- FiberGateway GR241AG - Full Exploit Chain
- Blackbox-Fuzzing of IoT Devices Using the Router TL-WR902AC
- Rooting the TP-Link Tapo C200 Rev.5
Netgear Series
- Netgear Orbi: Introduction, UART Access, Recon
- Netgear Orbi: Crashes in SOAP-API
- Netgear Orbi: NDay Exploit CVE-2020-27861
- The Last Breath of Our Netgear RAX30 Bugs
TP-Link Series
- TP-Link TDDP Buffer Overflow Vulnerability
- Pwn2Own Tokyo 2020: Defeating the TP-Link AC1750
- TP-Link Tapo c200 Camera Unauthenticated RCE (CVE-2021-4045)
Cisco Series
- Patch Diffing a Cisco RV110W Firmware Update - Part 1
- CVE-2024-20356: Jailbreaking a Cisco appliance to run DOOM
- Flashback Connects - Cisco RV340 SSL VPN RCE
Secure Boot Bypasses
- Bypassing Secure Boot using Fault Injection
- Breaking Secure Boot on Google Nest Hub (2nd Gen)
- Booting into Breaches: Hunting Windows SecureBoot's Remote Attack Surfaces
Network and Web Protocols
MQTT
- Introduction to MQTT
- MQTT Broker Security 101
- Hacking the IoT with MQTT
- IoT Security: RCE in MQTT Protocol
- IoXY - MQTT Intercepting Proxy
- MQTT-PWN
Fundamentals
Security and Exploitation
- Are Smart Homes Vulnerable to Hacking?
- Penetration Testing Sesame Smart Door Lock
- Servisnet Tessa - MQTT Credentials Dump (Metasploit)
- Eclipse Mosquitto Unquoted Service Path
Known CVEs
- CVE-2020-13849 - DoS vulnerability (CVSS 7.5)
- CVE-2023-3028 - Insufficient authentication (CVSS 9.8)
- CVE-2021-0229 - Resource consumption (CVSS 5.3)
- CVE-2019-5432 - Malformed packet crash (CVSS 7.5)
Tools
- Mosquitto - Open Source MQTT Broker
- HiveMQ
- MQTT Explorer
- Nmap MQTT Library
- Seven Best MQTT Client Tools
Applications
- Using IoT MQTT for V2V and Connected Cars
- MQTT Hardware Development Projects
- 100,000 Connected Cars with Kubernetes, Kafka, MQTT, TensorFlow
- Authenticating Devices Using MQTT with Auth0
- Deep Learning UDF for MQTT IoT Anomaly Detection
- Guide to MQTT: Hacking a Doorbell
Malware Research
CoAP
Specifications and Security
Tools - Software
- CoAP NSE (Nmap)
- Copper - Firefox CoAP Plugin
- libcoap CLI Tools
- Scapy CoAP Plugin
- Eclipse Californium (Java)
- Peach Fuzzer
Tools - Hardware
Research and Tutorials
mTLS
️ Tools
| Tool | Use | Link |
|---|---|---|
| mtls-intercept | Reverse proxy that dynamically signs client certs to MITM full mTLS sessions | github.com/fungaren/mtls-intercept |
| mitmproxy | Configure client_certs with extracted IoT device cert to impersonate device in mTLS handshake | mitmproxy.org |
| SSLsplit | Transparent mTLS proxy - forward extracted device cert to complete mutual handshake with cloud | github.com/droe/sslsplit |
| eCapture (eBPF) | Hook OpenSSL/BoringSSL on Linux IoT gateways pre-encrypt - decrypts mTLS + TLS 1.3 + PFS | ecapture.cc |
| Wireshark + SSLKEYLOGFILE | Decrypt captured mTLS sessions from IoT gateways using NSS pre-master secret logs | wiki.wireshark.org/TLS |
| Frida | Runtime hook SSLContext, TrustManager, KeyManager in Android IoT companion apps | frida.re |
| Objection | android sslpinning disable - strips mTLS pinning in companion apps | github.com/sensepost/objection |
| apk-mitm | Statically patches IoT companion APK to disable mTLS cert pinning | github.com/shroudedcode/apk-mitm |
| MagiskTrustUserCerts | Moves custom CA to system store on rooted Android POS/kiosk to complete mTLS MITM | github.com/NVISOsecurity/MagiskTrustUserCerts |
| frida-multiple-unpinning | Universal Frida script targeting 20+ mTLS/pinning patterns in hardened IoT apps | github.com/httptoolkit/frida-android-unpinning |
| NEU-SNS/IoTLS | IMC'21 research repo - SSLKEYLOGFILE files to decrypt MITM'd mTLS connections across 32 devices | github.com/NEU-SNS/IoTLS |
| mitmrouter | Linux-based IoT traffic interception router - intercepts device TLS at network level | github.com/nmatt0/mitmrouter |
Blogs & Articles
- mTLS: When Certificate Authentication is Done Wrong
- mTLS Authentication in IoT: Enhancing Security for Connected Devices
- Hands On IoT MitM Part 1 – AWS IoT MQTT + mTLS Interception
- OWASP MASTG-TECH-0012: Bypassing Certificate Pinning in Android IoT Companion Apps
- Theory to Practice: mTLS in Action Part 1
- Firmware Analysis for IoT Penetration Testing
- Configuring mTLS on Mosquitto MQTT Broker
- AWS IoT Docs: X.509 Client Certificates and Fleet Provisioning
- Azure IoT Hub: mTLS X.509 CA Authentication Concept
Research Papers
- Evaluation of TLS and mTLS in Internet of Things Systems - MIUN DiVA, 2024
- Atlas: Enabling Cross-Vendor mTLS Authentication for IoT - arXiv 2025
- TLS in the IoT Ecosystem - IEEE IMC 2021, NEU-SNS
- Lightweight mTLS Authentication for Industrial IoT - PMC/NIH 2023
- Quantum-Enhanced mTLS for IoT Battlefield Networks - IJPSAT
- AI vs. IoT Security: Fingerprinting and Defenses Against TLS Attacks - IEEE Xplore 2025
YouTube
- Intercepting IoT Device Traffic with ARP Poisoning + mitmproxy TLS Intercept
- Using Linux to Intercept IoT Device Traffic with mitmrouter
- Mutual TLS - The Backend Engineering Show Deep Dive
- Intercepting SSL/TLS - Fiddler and MITMProxy Decrypt Walkthrough
- Decrypting Kubernetes mTLS Traffic - eCapture, Custom CA, eBPF Methods
- Mastering mTLS: Stop MITM Attacks and Boost API/IoT Security
- Introduction to IoT Penetration Testing Webinar - CyberWarFare Labs
IoT Protocols Overview
Cloud and Backend Security
AWS IoT Security
- AWS Penetration Testing Policy
- AWS Pentesting Guide - HackerOne
- A few notes on AWS Nitro Enclaves
- Pacu - AWS Exploitation Framework
- ScoutSuite - Multi-cloud Security Auditing
- Prowler - Cloud Security Assessment
Fundamentals
- Comprehensive AWS Pentesting Guide - BreachLock
- AWS Pentest Methodology - MorattiSec
- AWS Penetration Testing Methodology - Rootshell
- AWS Penetration Testing Techniques 2025
Tools
- CloudFox - Cloud Attack Paths
- S3Scanner - Leaky Bucket Discovery
- Cloudfoxable Labs
- AWS Security Pentesting Resources
Vulnerabilities
more like this
