dorkhub

awesome-connected-things-sec

A Curated list of Security Resources for all connected things

V33RU
3.5k579 forksMITupdated 2 months ago
visit the demogit clone https://github.com/V33RU/awesome-connected-things-sec.gitV33RU/awesome-connected-things-sec

🔐 Awesome Connected Things Security Resources

A curated repository of IoT, Embedded, Industrial & Automotive, Core Tech security knowledge.

Awesome

Typing SVG


     


         


     


Table of Contents

Hardware Attacks

Fundamentals

Interface Attacks

UART

JTAG

SWD (Serial Wire Debug)

SPI

I2C

TPM

Memory Extraction

eMMC

Side-Channel and Fault Injection

Fundamentals

Glitching Attacks

Power Analysis

Other Microcontrollers

PCIe and DMA Attacks


Wireless Protocols

RF Fundamentals

Bluetooth / BLE

Fundamentals

Exploitation Techniques

Vulnerability Research

Conference Talks

Tools - Software

Tools - Hardware

Tools

Hacking Bluetooth Coffee Machines

Zigbee / Z-Wave

Fundamentals

Exploitation

Tools - Software

Tools - Hardware

LoRa / LoRaWAN

Fundamentals

Exploitation

Tools

Matter / Thread

Fundamentals

Security Research

Cellular (GSM/LTE/5G)

Fundamentals

Exploitation

Tools

NFC/RFID

DECT (Digital Enhanced Cordless Telecommunications)


Wi-Fi

Protocol Vulnerabilities

Exploitation

Reverse Engineering WiFi

USB

UWB (Ultra-Wideband)

TETRA


Firmware Security

Fundamentals

Extraction

Static Analysis Tools

Dynamic Analysis and Emulation

Emulation Tutorials

OTA Update Security

Fundamentals

Attack Vectors

RTOS Security

Zephyr RTOS

FreeRTOS

Reverse Engineering Tools

Reverse Engineering Tutorials

Ghidra Tutorials

Online Assemblers

ARM Exploitation

Binary Analysis

Secure Boot

Development

Bypasses

UEFI Security


Symlink Attacks


Router Firmware Analysis

Router Exploitation

Netgear Series

TP-Link Series

Cisco Series

Secure Boot Bypasses

Network and Web Protocols

MQTT

Fundamentals

Security and Exploitation

Known CVEs

Tools

Applications

Malware Research

CoAP

Specifications and Security

Tools - Software

Tools - Hardware

Research and Tutorials

mTLS

️ Tools

Tool Use Link
mtls-intercept Reverse proxy that dynamically signs client certs to MITM full mTLS sessions github.com/fungaren/mtls-intercept
mitmproxy Configure client_certs with extracted IoT device cert to impersonate device in mTLS handshake mitmproxy.org
SSLsplit Transparent mTLS proxy - forward extracted device cert to complete mutual handshake with cloud github.com/droe/sslsplit
eCapture (eBPF) Hook OpenSSL/BoringSSL on Linux IoT gateways pre-encrypt - decrypts mTLS + TLS 1.3 + PFS ecapture.cc
Wireshark + SSLKEYLOGFILE Decrypt captured mTLS sessions from IoT gateways using NSS pre-master secret logs wiki.wireshark.org/TLS
Frida Runtime hook SSLContext, TrustManager, KeyManager in Android IoT companion apps frida.re
Objection android sslpinning disable - strips mTLS pinning in companion apps github.com/sensepost/objection
apk-mitm Statically patches IoT companion APK to disable mTLS cert pinning github.com/shroudedcode/apk-mitm
MagiskTrustUserCerts Moves custom CA to system store on rooted Android POS/kiosk to complete mTLS MITM github.com/NVISOsecurity/MagiskTrustUserCerts
frida-multiple-unpinning Universal Frida script targeting 20+ mTLS/pinning patterns in hardened IoT apps github.com/httptoolkit/frida-android-unpinning
NEU-SNS/IoTLS IMC'21 research repo - SSLKEYLOGFILE files to decrypt MITM'd mTLS connections across 32 devices github.com/NEU-SNS/IoTLS
mitmrouter Linux-based IoT traffic interception router - intercepts device TLS at network level github.com/nmatt0/mitmrouter

Blogs & Articles

Research Papers

YouTube

IoT Protocols Overview


Cloud and Backend Security

AWS IoT Security


Fundamentals

Tools

Vulnerabilities

more like this

anne-key

Firmware for Anne Pro Keyboard written in Rust

Rust572

search

search projects, people, and tags