Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
awesome-connected-things-sec — قائمة منسقة من الموارد الأمنية لجميع الأشياء المتصلة | Kitploit
أدوات/GitHubGitHub/v33ru/awesome-connected-things-sec
أمان الأنظمة المدمجةأمان إنترنت الأشياءالهندسة العكسيةأمن SCADA/ICSأمن الشبكات اللاسلكيةاختراق الأجهزةCTFأمن الجوالالتعلم والتعليمموارد منسقةتحليل البرامج الثابتةمختبرات وتدريب عملي
3.5k57920منذ 13 أيامتمت المراجعة من قبل Kitploit

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
GitHubv33ru/awesome-connected-things-sec

awesome-connected-things-sec

قائمة منسقة من الموارد الأمنية لجميع الأشياء المتصلة

عرض المستودعالموقع الإلكتروني

🔐 موارد أمان الأشياء المتصلة الرائعة

أبحاث الأمان وتقنيات الاستغلال لأنظمة إنترنت الأشياء والأنظمة المدمجة والصناعية والسيارات.

Awesome

Typing SVG


       


         


     


المحتويات

  • هجمات العتاد
    • الأساسيات
    • هجمات الواجهات
    • استخراج الذاكرة
    • القنوات الجانبية وحقن الأخطاء
    • هجمات PCIe و DMA
  • البروتوكولات اللاسلكية
    • أساسيات الترددات الراديوية
    • Bluetooth / BLE
    • Zigbee / Z-Wave
    • LoRa / LoRaWAN
    • Matter / Thread
    • الشبكات الخلوية (GSM/LTE/5G)
    • NFC/RFID
    • DECT (الاتصالات اللاسلكية الرقمية المحسّنة)
    • Wi-Fi
    • USB
    • UWB (النطاق العريض الفائق)
    • TETRA
  • أمان البرامج الثابتة
    • الأساسيات
    • الاستخراج
    • أدوات التحليل الساكن
    • التحليل الديناميكي والمحاكاة
    • أمان تحديثات OTA
    • أمان RTOS
    • أدوات الهندسة العكسية
    • المجمّعات عبر الإنترنت
    • استغلال ARM
    • تحليل الملفات الثنائية
    • الإقلاع الآمن
    • أمان UEFI
    • هجمات الروابط الرمزية
    • تحليل البرامج الثابتة للموجّهات
    • استغلال الموجّهات
    • تجاوزات الإقلاع الآمن
  • بروتوكولات الشبكة والويب
    • MQTT
    • CoAP
    • mTLS
    • نظرة عامة على بروتوكولات إنترنت الأشياء

هجمات العتاد

الأساسيات

  • دليل عتاد إنترنت الأشياء
  • مقدمة في اختراق العتاد - استخراج أول برنامج ثابت لك
  • مقدمة في اختراق العتاد
  • مجموعات أدوات العتاد لتحليل أمان إنترنت الأشياء
  • اختراق العتاد لأجهزة إنترنت الأشياء - الاستغلال الهجومي لإنترنت الأشياء

هجمات الواجهات

UART

  • تحديد واجهة UART
  • أساسيات الطرفية التسلسلية
  • الهندسة العكسية للمنافذ التسلسلية
  • مقدمة في الهندسة العكسية المدمجة: اكتشاف UART واستخراج البرامج الثابتة عبر UBoot
  • استخدام UART للاتصال بكاميرا IP صينية
  • رحلة في اختراق عتاد إنترنت الأشياء: UART
  • الوصول إلى البرامج الثابتة واستخراجها عبر UART
  • اتصالات UART والتحليل الديناميكي على Linksys e1000

JTAG

  • أساسيات اختراق العتاد 101: مقدمة في JTAG
  • كيفية العثور على واجهة JTAG
  • تحليل JTAG
  • اتصالات Bus Pirate JTAG مع OpenOCD
  • استخراج البرامج الثابتة من الذاكرة الخارجية عبر JTAG
  • دليل المسافر إلى اختراق iPhone Lightning و JTAG
  • تصحيح أخطاء متحكمات AVR عبر JTAG

SWD (تصحيح الأخطاء السلكي التسلسلي)

  • نظرة عامة على بروتوكول SWD - HardBreak Wiki
  • كشف الثغرات: استكشاف سطح هجوم SWD في العتاد
  • مقدمة في بروتوكول تصحيح الأخطاء السلكي التسلسلي ARM
  • تصحيح الأخطاء السلكي التسلسلي ومعمارية CoreSight
  • LibSWD - مكتبة تصحيح الأخطاء السلكي التسلسلي المفتوحة
  • معسكر اختراق العتاد والاستغلال - SWD

SPI

  • أساسيات اختراق العتاد 101: تحديد واستخراج ذاكرة eMMC الوميضية
  • استخراج البرامج الثابتة من الموجّه باستخدام Bus Pirate - SPI
  • استخراج الذاكرة الوميضية عبر SPI
  • استخراج البرامج الثابتة من الأجهزة المدمجة (SPI NOR Flash)
  • كيفية برمجة شريحة موجّه باستخدام مبرمج
  • TPM 2.0: استخراج مفاتيح Bitlocker عبر SPI

I2C

  • أمان إنترنت الأشياء الجزء 16: سطح هجوم العتاد I2C
  • استغلال I2C - HackTricks
  • ناقل هجوم حصان طروادة العتادي I2C غير التدخلي (PDF)
  • اختراق العتاد: حقن I2C باستخدام Bus Pirate
  • حماية بروتوكولات SPI و I2C و I3C

TPM

  • مقدمة في TPM (وحدة النظام الأساسي الموثوقة)
  • التغلب على أمان وحدة النظام الأساسي الموثوقة في 30 دقيقة

استخراج الذاكرة

eMMC

  • بروتوكول eMMC
  • RPMB: مكان سري داخل eMMC
  • استعادة بيانات eMMC من هاتف ذكي تالف
  • أطلق العنان لأجهزة منزلك الذكية: اختراق روبوت المكنسة الكهربائية
  • اختراق إنترنت الأشياء العملي: Rapid7 في DEF CON 30

القنوات الجانبية وحقن الأخطاء

الأساسيات

  • هجمات القنوات الجانبية - Yifan Lu
  • هجمات على تطبيقات الأنظمة الآمنة
  • مجموعة الفَزْزَة وتحليل الملفات الثنائية وأمان إنترنت الأشياء

هجمات الإرباك

  • هجوم إرباك NAND على Wink Hub
  • درس تعليمي حول إرباك الجهد باستخدام Crowbars
  • هجوم إرباك الجهد باستخدام iCEstick Glitcher
  • إرباك FPGA وهجمات القنوات الجانبية - Samy Kamkar
  • هجوم إرباك الطاقة العتادي - rhme2
  • المفاتيح في الذاكرة الوميضية - إرباك مفاتيح AES من Arduino
  • تنفيذ هجمات الإرباك الكهربائي العملية
  • كيفية حقن أخطاء الجهد
  • Glitcher الجزء 1 - إرباك الجهد القابل للتكرار على متحكمات STM32 الدقيقة
  • إرباك الجهد STM32L05

تحليل الطاقة

  • كسر AES باستخدام ChipWhisperer
  • ChipWhisperer Wiki
  • انقلابات بتات Rowhammer لسرقة مفاتيح التشفير

متحكمات دقيقة أخرى

  • استخراج Amlogic A113X Bootrom
  • إعادة قراءة عملية استغلال TrustZone في AMLogic A113X
  • الهندسة العكسية لمتحكم دقيق غير معروف
  • اختراق البرامج الثابتة للمتحكم الدقيق عبر USB
  • هناك ثقب في SoC الخاص بك: إرباك MediaTek BootROM

هجمات PCIe و DMA

  • درس تعليمي عملي حول PCIe للمبتدئين تمامًا على Windows - الجزء 1
  • درس تعليمي عملي حول PCIe للمبتدئين تمامًا على Windows - الجزء 2
  • هجوم PCIe DMA ضد Jetson Nano المؤمّن (CVE-2022-21819)

البروتوكولات اللاسلكية

أساسيات الترددات الراديوية

  • دورة كاملة في الراديو المعرّف بالبرمجيات - Michael Ossmann
  • فهم الراديو
  • مقدمة في الراديو المعرّف بالبرمجيات
  • مقدمة في GNU Radio Companion
  • إنشاء مخطط تدفق في GNU Radio Companion
  • تحليل الإشارات الراديوية 433MHz
  • تسجيل إشارات راديوية محددة
  • هجمات إعادة التشغيل باستخدام Raspberry Pi و rpitx
  • الهندسة العكسية لإشارة مفتاح سيارة
  • GRCON 2021 - Capture the Signal

Bluetooth / BLE

الأساسيات

  • أمان Bluetooth الرائع
  • هندسة حركة المرور في شبكة Bluetooth Piconet
  • خصائص BLE: درس تعليمي للمبتدئين
  • مقدمة في Bluetooth Low Energy (PDF)
  • دليل دراسة أمان Bluetooth LE
  • الهندسة العكسية لأجهزة BLE
  • رحلتي نحو الهندسة العكسية لسوار ذكي - Bluetooth-LE RE

تقنيات الاستغلال- Intel Edison as Bluetooth LE Exploit Box

  • Reverse Engineering and Exploiting a Smart Massager
  • I Hacked MiBand 3
  • GATTacking Bluetooth Smart Devices
  • Examining the August Smart Lock
  • Practical Introduction to BLE GATT Reverse Engineering
  • MojoBox - Yet Another Not So Smartlock
  • Bluetooth Smartlocks
  • Bluetooth Beacon Vulnerability
  • Denial of Pleasure: Attacking Unusual BLE Targets with a Flipper Zero
  • Grand Theft Auto: A peek of BLE relay attack
  • How I Hacked Smart Lights: CVE-2022-47758

Vulnerability Research

  • Finding Bugs in Bluetooth
  • Sweyntooth Vulnerabilities
  • BrakTooth: Causing Havoc on Bluetooth Link Manager
  • BLUFFS: Bluetooth Forward and Future Secrecy Attacks (CVE-2023-24023)
  • AirDrop Leak - Sniffing BLE Traffic from Apple Devices
  • BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution
  • BRAKTOOTH: Causing Havoc on Bluetooth Link Manager (PDF)
  • Norec Attack: Stripping BLE encryption from Nordic's Library (CVE-2020-15509)
  • BlueDucky - HID Injection on Unpatched Android (CVE-2023-45866)
  • Microsoft Bluetooth Driver Spoofing - CVE-2024-21306
  • Bluetooth Auracast / LE Audio Security Analysis

Conference Talks

  • Blue2thprinting: WTF Am I Even Looking At?
  • Open Wounds: Last 5 Years Have Left Bluetooth to Bleed
  • Sniffing Bluetooth Through My Mask During the Pandemic

Tools - Software

  • Bluing - Intelligence Gathering for Bluetooth
  • BlueToolkit - Bluetooth Classic Vulnerability Testing
  • btproxy
  • hcitool and bluez
  • Testing with GATT Tool
  • crackle - Cracking BLE Encryption
  • bettercap
  • GATTacker
  • BTLEjack - BLE Swiss Army Knife
  • DEDSEC Bluetooth Exploit
  • BrakTooth ESP32 PoC
  • SweynTooth BLE Attacks
  • ESP32 Bluetooth Classic Sniffer
  • Bluetooth Hacking Collection

Tools - Hardware

  • nRF52840 Dongle
  • Ubertooth One
  • CSR 4.0 Bluetooth Dongle
  • ESP32
  • Sena UD100
  • ESP-WROVER-KIT

Tools

  • ice9-bluetooth-sniffer
  • InternalBlue - Bluetooth Experimentation Framework

Hacking Bluetooth Coffee Machines

  • Hacking Bluetooth to Brew Coffee from GitHub Actions - Part 1
  • Hacking Bluetooth to Brew Coffee from GitHub Actions - Part 2
  • Hacking Bluetooth to Brew Coffee from GitHub Actions - Part 3

Zigbee / Z-Wave

Fundamentals

  • Introduction and Protocol Overview
  • ZigBee and Z-Wave Security Brief
  • Hacking ZigBee Networks

Exploitation

  • Hacking IoT Devices with Attify Zigbee Framework
  • Zigator: Analyzing Security of Zigbee-Enabled Smart Homes
  • Security Analysis of Zigbee with Zigator and GNU Radio
  • Low-Cost ZigBee Selective Jamming

Tools - Software

  • Killerbee
  • ZigDiggity
  • Zigator
  • Z3sec
  • zigbear

Tools - Hardware

  • ApiMote
  • RaspBee
  • ATUSB IEEE 802.15.4 Adapter
  • USRP

LoRa / LoRaWAN

  • LoRaWAN Security Overview - Tektelic
  • Security Vulnerabilities in LoRaWAN
  • Low Powered and High Risk: Attacks on LoRaWAN Devices
  • LAF - LoRaWAN Auditing Framework
  • ChirpOTLE - LoRaWAN Security Framework

Fundamentals

  • LoRaWAN Security Survey - ScienceDirect
  • LoRaWAN - Wikipedia

Exploitation

  • Millions of Devices Using LoRaWAN Exposed - SecurityWeek
  • Do You Blindly Trust LoRaWAN Networks? - IOActive
  • LoRaWAN Encryption Keys Easy to Crack - Threatpost
  • LoPT: LoRa Penetration Testing Tool (PDF)

Tools

  • LoRa Craft - Packet Interception
  • Open Source LoRaWAN Hacking Tool
  • LoRaWAN Hackaday Projects

Matter / Thread

Fundamentals

  • Matter Standard - CSA-IoT
  • Matter Protocol Wikipedia
  • Matter Protocol Complete Guide 2025
  • How to Secure Smart Home Devices with Matter
  • Smart Home Device Solutions for Matter - DigiCert

Security Research

  • Security Vulnerabilities and Attack Scenarios in Smart Home with Matter
  • Trust Matters: Uncovering Vulnerabilities in Matter Protocol - Nozomi
  • Matter over Thread Security
  • State-of-the-Art Review on IoT Wireless PAN Protocol Security
  • Matter Smart Home - Krasamo
  • Threadbare: Practical Attacks on Thread Networks (Black Hat USA 2024)
  • Matter Specification 1.3 - Connectivity Standards Alliance
  • Thread Group Security Analysis

Cellular (GSM/LTE/5G)

  • Awesome Cellular Hacking
  • Introduction to GSM Security
  • Breaking LTE on Layer Two
  • 5Ghoul - 5G NR Attacks and Fuzzing
  • Exploiting CSN.1 Bugs in MediaTek Basebands
  • SIM Hijacking
  • SigPloit - Telecom Signaling Exploitation Framework
  • LTE Sniffer
  • 5G NR Jamming, Spoofing and Sniffing
  • LTrack: Stealthy Tracking of Mobile Phones in LTE
  • Open5GS - Open Source 5G/4G Core
  • SCAT - Signaling Collection and Analysis Tool for Cellular

Fundamentals

  • GSM Security Part 2
  • What is Base Transceiver Station
  • Introduction to SS7 Signaling
  • SS7 Network Architecture
  • Introduction to SIGTRAN

Exploitation

  • How to Build Your Own Rogue GSM BTS
  • GSM Vulnerabilities with USRP B200
  • Security Testing 4G (LTE) Networks
  • Case Study of SS7/SIGTRAN Assessment

Tools

  • ss7MAPer - SS7 Pentesting Toolkit
  • Fake BTS Detector (SCL-8521)

NFC/RFID

  • Awesome RFID/NFC Security Talks
  • RFID Discord Group
  • SoK: Security of EMV Contactless Payment Systems
  • NFC Relay Attack on Tesla Model Y

DECT (Digital Enhanced Cordless Telecommunications)

  • Real Time Interception of DECT Cordless Telephone
  • Eavesdropping on Unencrypted DECT Voice Traffic
  • Decoding DECT Voice Traffic: In-depth Explanation

Wi-Fi

Protocol Vulnerabilities

  • Framing Frames: Bypassing Wi-Fi Encryption by Manipulating Transmit Queues
  • Man-in-the-Middle Attacks without Rogue AP: When WPAs Meet ICMP Redirects
  • WPAxFuzz: Sniffing Out Vulnerabilities in Wi-Fi Implementations
  • Untangling the Knot: Breaking Access Control in Home Wireless Mesh Networks

Exploitation

  • Over The Air: Exploiting Broadcom's Wi-Fi Stack (Part 1)
  • Over The Air: Exploiting Broadcom's Wi-Fi Stack (Part 2)
  • Over The Air: Exploiting The Wi-Fi Stack on Apple Devices
  • Reverse-engineering Broadcom wireless chipsets
  • Exploiting Qualcomm WLAN and Modem Over the Air
  • Windows Wi-Fi Driver RCE Vulnerability - CVE-2024-30078
  • When a Wi-Fi SSID Gives You Root on an MT02 Repeater - Part 1
  • When a Wi-Fi SSID Gives You Root on an MT02 Repeater - Part 2

Reverse Engineering WiFi

  • Reverse Engineering WiFi on RISC-V BL602
  • Unveiling secrets of the ESP32: creating an open-source MAC Layer
  • Unveiling secrets of the ESP32: reverse engineering RX

USB

  • ALL ABOUT USB-C: INTRODUCTION FOR HACKERS
  • Hi, My Name is Keyboard
  • How to Weaponize the Yubikey

UWB (Ultra-Wideband)

  • UWB Real Time Locating Systems: How Secure Radio Communications May Fail in Practice

TETRA

  • All cops are broadcasting: TETRA under scrutiny
  • TETRA:BURST - Five Vulnerabilities in TETRA Standard (Midnight Blue)
  • TETRA:BURST 2:ELECTRIC BOOGALOO - End-to-End Encryption Broken (BlackHat USA 2025)
  • TETRA Decoder - Open Source TETRA Receiver
  • Practical TETRA Sniffing with SDR

Firmware Security

Fundamentals

  • Introduction to Firmware Analysis - OWASP
  • OWASP Firmware Security Testing Methodology
  • IoT Security Verification Standard (ISVS)
  • Reversing 101
  • Hands-on Firmware Extraction, Exploration, and Emulation

Extraction

  • Router Analysis Part 1: UART Discovery and SPI Flash Extraction
  • Hardware Hacking Tutorial: Dumping and Reversing Firmware
  • Firmware Samples - firmware.center
  • BasicFUN Series: Hardware Analysis / SPI Flash Extraction
  • BasicFUN Series: Reverse Engineering Firmware / Reflashing SPI Flash
  • Retrofitting encrypted firmware is a Bad Idea

Static Analysis Tools

  • EMBA - Embedded Linux Firmware Analyzer
  • FACT - Firmware Analysis and Comparison Tool
  • Binwalk v3
  • Firmwalker
  • fwanalyzer
  • fwhunt-scan - UEFI Firmware Analysis
  • ByteSweep
  • BINSEC
  • unblob - Extraction Framework
  • Checksec.sh
  • Firmware Modification Kit

Dynamic Analysis and Emulation

  • Firmadyne - Automated Firmware Emulation
  • FirmAE - Firmware Analysis and Emulation
  • QEMU
  • PANDA - Architecture-Neutral Dynamic Analysis
  • Avatar2 - Dynamic Firmware Analysis
  • Renode - Embedded Systems Emulator
  • Unicorn Engine - CPU Emulator
  • Qiling Framework
  • HALucinator
  • FirmWire - Baseband Firmware Emulation
  • SymQEMU
  • S2E - Selective Symbolic Execution
  • Bochs - x86 Emulator
  • SAME70 Emulator
  • Emulate Until You Make it

Emulation Tutorials- محاكاة البرامج الثابتة باستخدام QEMU

  • محاكاة البرامج الثابتة لموجهات ARM - Azeria Labs
  • محاكاة البرامج الثابتة لإنترنت الأشياء بسهولة
  • تحليل ومحاكاة ثنائيات إنترنت الأشياء الجزء 1
  • التنقيح المتقاطع لـ ARM/MIPS باستخدام QEMU
  • QEMU + Buildroot 101
  • محاكاة ثغرات البرامج الثابتة واصطيادها باستخدام Qiling
  • Qiling ومحاكاة الثنائيات لفك التغليف التلقائي
  • تنقيح D-Link: محاكاة البرامج الثابتة واختراق العتاد
  • إطار محاكاة تكيفي لإنترنت الأشياء متعدد المعماريات
  • محاكاة البرامج الثابتة التلقائية من خلال استنتاج المعرفة الموجه بالصلاحية
  • محاكاة معمارية RH850 باستخدام Unicorn Engine
  • Icicle: محاكي معاد تصميمه لاختبار البرامج الثابتة بالصندوق الرمادي
  • التحديات والمزالق أثناء محاكاة ستة موجهات منزلية آيسلندية حالية
  • محاكاتي تذهب إلى القمر... حتى العلم المزيف
  • كيفية محاكاة مكتبات Android الأصلية باستخدام Qiling

أمان تحديثات OTA

الأساسيات

  • أمان البرامج الثابتة لإنترنت الأشياء وآليات التحديث
  • تنفيذ تحديثات OTA لأجهزة إنترنت الأشياء
  • سلاسل إقلاع OTA الآمنة والتحقق من البرامج الثابتة
  • مفتاح أمان البرامج الثابتة في أجهزة إنترنت الأشياء المتصلة
  • اعتبارات الأمان لتحديثات OTA - Stack Overflow

نواقل الهجوم

  • أهم 10 ثغرات في إنترنت الأشياء - هجمات تحديث OTA
  • تحديث أجهزة إنترنت الأشياء 2025: أفضل الممارسات
  • مراجعة ثغرات البرامج الثابتة لإنترنت الأشياء وتقنيات التدقيق

أمان أنظمة التشغيل في الوقت الحقيقي (RTOS)

Zephyr RTOS

  • Zephyr RTOS على GitHub
  • قائمة ثغرات Zephyr
  • تقييم NCC Group الأمني لـ Zephyr و MCUboot
  • 26 عيبًا في Zephyr و MCUboot
  • معالجة الأمان في Zephyr RTOS
  • تعزيز الأمان باستخدام Zephyr RTOS

FreeRTOS

  • 13 ثغرة في FreeRTOS في مكدس TCP/IP
  • استغلال تلف الذاكرة في FreeRTOS - ShmooCon
  • تحليل أمان RTOS - USENIX
  • ترقيع الثغرات الديناميكي لـ RTOS
  • ثغرات AWS FreeRTOS

أدوات الهندسة العكسية

  • Ghidra
  • IDA Pro
  • Radare2
  • Cutter - واجهة رسومية لـ Radare2
  • Binary Ninja
  • GDB
  • RetDec - مفكك الترجمة
  • Diaphora - مقارنة الثنائيات
  • Angr - تحليل الثنائيات
  • Frida - الأدوات الديناميكية
  • Ret-sync
  • OllyDbg
  • x64dbg
  • Hopper
  • Immunity Debugger
  • PEiD
  • Ghidriff - محرك مقارنة الثنائيات لـ Ghidra
  • مفكك الترجمة rev.ng يصبح مفتوح المصدر
  • مقدمة إلى Cutter
  • pyghidra-mcp: خادم Ghidra MCP بدون واجهة
  • Mindshare: استخدام Binary Ninja API لاكتشاف ثغرات الاستخدام بعد التحرير المحتملة

دروس الهندسة العكسية

  • الهندسة العكسية والترقيع باستخدام Ghidra
  • الهندسة العكسية باستخدام Ghidra: كسر تشفير البرامج الثابتة
  • عكس هندسة البرامج الثابتة باستخدام Radare
  • عكس هندسة برامج ESP8266 الثابتة
  • أتمتة اكتشاف ثغرات الثنائيات باستخدام Ghidra و Semgrep
  • إيجاد الأخطاء في موجه Netgear

دروس Ghidra

  • فصل المنقح Ghidra
  • Ghidra 101: تمييز نص المؤشر
  • Ghidra 101: فك تشفير سلاسل المكدس
  • توسيع Ghidra الجزء 1: إعداد بيئة تطوير
  • توسيع التنين: إضافة ISA إلى Ghidra
  • وحدة Ghidra nanoMIPS ISA
  • استنتاج نوع الثنائي في Ghidra
  • كتابة وحدة معالج Ghidra

المجمعات عبر الإنترنت

  • AZM مجمع ARM عبر الإنترنت - Azeria Labs
  • مفكك الترجمة عبر الإنترنت
  • Compiler Explorer

استغلال ARM

  • دروس ARM من Azeria Labs
  • استغلال ARM لإنترنت الأشياء
  • موجه ARM الضعيف (DVAR)
  • Exploit Education
  • دليل لتجميع ARM64 / AArch64 على Linux
  • درس تجميع ARMv8 AArch64/ARM64 الكامل للمبتدئين
  • دليل المبتدئين لاستغلال ARM
  • سلسلة عكس هندسة واستغلال ARM64 (8ksec) - الأجزاء 1-10
  • ذاكرة وترحيل AArch64
  • نحن مسلحون بـ ARM لا مزيد من ROP هنا

تحليل الثنائيات

  • تحليل الثنائيات العملي

الإقلاع الآمن

التطوير

  • كتابة محمل إقلاع

تجاوزات

  • اختراق الإقلاع الآمن لـ ESP32
  • اختراق ESP32 للأبد: استخراج مفاتيح تشفير الفلاش والإقلاع الآمن
  • تجاوز الإقلاع الآمن لـ ESP32 (CVE-2020-13629)
  • Amlogic S905 SoC: تجاوز الإقلاع الآمن
  • إفشال الإقلاع الآمن بهجمات الروابط الرمزية
  • اختراق الإقلاع الآمن لـ PS4 - Fail0verflow
  • ثغرات Dell BIOS - BIOSDisconnect
  • ثغرة U-Boot USB DFU (CVE-2022-2347)
  • كسر الإقلاع الآمن على Silicon Labs Gecko

أمان UEFI

  • استخدام التنفيذ الرمزي لاكتشاف ثغرات UEFI
  • ثغرات UEFI في أجهزة HP Enterprise
  • محاكاة واستغلال البرامج الثابتة UEFI
  • الجانب المظلم لـ UEFI: تحليل تقني معمق للاستغلال عبر الشرائح
  • داخل إثبات مفهوم LogoFAIL: من تجاوز الحد الصحيح إلى تنفيذ تعليمات برمجية عشوائية
  • PixieFail: تسع ثغرات في مكدس شبكة IPv6 لـ EDK II من Tianocore
  • من أجل العلم! - استخدام خطأ غير مبهر في EDK II
  • Hydroph0bia: تجاوز SecureBoot لـ Insyde H2O
  • PKfail: مفاتيح منصة غير موثوقة في البرامج الثابتة UEFI (Binarly, 2024)
  • LogoFAIL: ثغرات تحليل الصور في برامج ثابتة النظام (Binarly)
  • تحليل BlackLotus UEFI Bootkit - ESET
  • Bootkitty: أول UEFI Bootkit لـ Linux (ESET, 2024)
  • جذور خفية في البرامج الثابتة UEFI: الأساطير والواقع (BlackHat 2024)
  • CVE-2024-0762 - متابعة PixieFail تجاوز TPM

هجمات الروابط الرمزية

  • ثغرة Zip Slip

تحليل البرامج الثابتة للموجهات

  • رحلة إلى إنترنت الأشياء: اكتشاف المكونات والمنافذ
  • رحلة إلى إنترنت الأشياء: استخراج البرامج الثابتة وتحليلها
  • رحلة إلى إنترنت الأشياء: الاتصالات اللاسلكية
  • رحلة إلى إنترنت الأشياء: الاتصالات الداخلية
  • التحليل الديناميكي لمكونات البرامج الثابتة في أجهزة إنترنت الأشياء
  • تحليل البرامج الثابتة RV130X
  • فك تشفير البرامج الثابتة لـ TP-Link C210 V2 محملات إقلاع كاميرا سحابية

استغلال الموجهات

  • البحث عن ثغرات n-days غير مصادق عليها في موجهات Asus
  • إبراز MikroTik في دائرة الضوء
  • استغلال عتاد MikroTik RouterOS باستخدام CVE-2023-30799
  • الحصول على صلاحيات الجذر في موجهات Xiaomi WiFi
  • الطريق إلى الأمان: التنقل في مزالق الموجهات
  • ROPing our way to RCE
  • ROPing Routers من الصفر: Tenda Ac8v4
  • PwnAgent: تنفيذ تعليمات برمجية عن بُعد من جانب WAN بنقرة واحدة في موجهات Netgear RAX
  • Puckungfu 2: حقن أوامر آخر من جانب WAN في NETGEAR
  • عكس هندسة واكتشاف واستغلال ثغرة في موجه TP-Link - CVE-2024-54887
  • استغلال ثغرة يوم الصفر (CVE-2025-9961) في موجه TP-Link AX10
  • FiberGateway GR241AG - سلسلة استغلال كاملة
  • اختبار الصندوق الأسود لأجهزة إنترنت الأشياء باستخدام الموجه TL-WR902AC
  • الحصول على صلاحيات الجذر في TP-Link Tapo C200 Rev.5

سلسلة Netgear

  • Netgear Orbi: مقدمة، الوصول إلى UART، الاستطلاع
  • Netgear Orbi: أعطال في SOAP-API
  • Netgear Orbi: استغلال NDay CVE-2020-27861
  • الأنفاس الأخيرة لأخطاء Netgear RAX30 لدينا

سلسلة TP-Link

  • ثغرة تجاوز سعة المخزن المؤقت في TP-Link TDDP
  • Pwn2Own Tokyo 2020: إفشال TP-Link AC1750
  • تنفيذ تعليمات برمجية عن بُعد غير مصادق عليه في كاميرا TP-Link Tapo c200 (CVE-2021-4045)

سلسلة Cisco

  • مقارنة ترقيع تحديث البرامج الثابتة لـ Cisco RV110W - الجزء 1
  • CVE-2024-20356: كسر حماية جهاز Cisco لتشغيل DOOM
  • Flashback Connects - تنفيذ تعليمات برمجية عن بُعد عبر Cisco RV340 SSL VPN

تجاوزات الإقلاع الآمن

  • تجاوز الإقلاع الآمن باستخدام حقن الأخطاء
  • كسر الإقلاع الآمن على Google Nest Hub (الجيل الثاني)
  • الإقلاع نحو الاختراقات: اصطياد أسطح الهجوم عن بُعد في Windows SecureBoot

بروتوكولات الشبكة والويب

MQTT

  • مقدمة إلى MQTT
  • أساسيات أمان وسيط MQTT
  • اختراق إنترنت الأشياء باستخدام MQTT
  • أمان إنترنت الأشياء: تنفيذ تعليمات برمجية عن بُعد في بروتوكول MQTT
  • IoXY - وسيط اعتراض MQTT
  • MQTT-PWN

الأساسيات

  • فهم بنية حزم بروتوكول MQTT

الأمان والاستغلال

  • هل المنازل الذكية عرضة للاختراق؟
  • اختبار اختراق قفل الباب الذكي Sesame
  • Servisnet Tessa - استخراج بيانات اعتماد MQTT (Metasploit)
  • مسار خدمة غير محاط بعلامات اقتباس في Eclipse Mosquitto

ثغرات CVE المعروفة

  • CVE-2020-13849 - ثغرة حجب الخدمة (CVSS 7.5)
  • CVE-2023-3028 - مصادقة غير كافية (CVSS 9.8)
  • CVE-2021-0229 - استهلاك الموارد (CVSS 5.3)
  • CVE-2019-5432 - انهيار بسبب حزمة مشوهة (CVSS 7.5)

الأدوات

  • Mosquitto - وسيط MQTT مفتوح المصدر
  • HiveMQ
  • MQTT Explorer
  • MQTT Topic ACL Linter - تحليل ثابت محلي فقط لقواعد ACL لمرشحات مواضيع MQTT غير الصالحة والواسعة والمكررة والمتداخلة؛ لا يتصل بوسيط ولا يحل محل تدقيق أمني.
  • مكتبة Nmap MQTT
  • أفضل سبع أدوات عميل MQTT

التطبيقات- Using IoT MQTT for V2V and Connected Cars

  • MQTT Hardware Development Projects
  • 100,000 Connected Cars with Kubernetes, Kafka, MQTT, TensorFlow
  • Authenticating Devices Using MQTT with Auth0
  • Deep Learning UDF for MQTT IoT Anomaly Detection
  • Guide to MQTT: Hacking a Doorbell

أبحاث البرمجيات الخبيثة

  • WailingCrab Malware Using MQTT for C2
  • Alert: New WailingCrab Malware Loader
  • MQTT on Snapcraft

CoAP

  • IETF Security Protocol Comparison
  • RFC 8613 - OSCORE
  • Radware - CoAP Protocol Overview

المواصفات والأمان

  • EMQX on CoAP and IoT Security (2024)
  • RFC 8323 - CoAP over TCP
  • RFC 8824 - SCHC Header Compression

الأدوات - البرمجيات

  • CoAP NSE (Nmap)
  • Copper4Cr - CoAP User-Agent for Chrome
  • libcoap CLI Tools
  • Scapy CoAP Plugin
  • Eclipse Californium (Java)
  • Peach Fuzzer

الأدوات - العتاد

  • Raspberry Pi / Arduino + 6LoWPAN
  • Zolertia
  • OpenMote
  • Nordic Boards

الأبحاث والدروس التعليمية

  • SpectralOps - Top IoT Protocol Security Issues
  • CoAP Exposure Study (2024)

mTLS

الأدوات

| الأداة | الاستخدام | الرابط | | ───────────────────────── | ─────────────────────────────────────────────────────────────────────────────────────────────── | ──────────────────────────────────────────────────────────────────────────────────────────────────────── | | mtls-intercept | Reverse proxy that dynamically signs client certs to MITM full mTLS sessions | github.com/fungaren/mtls-intercept | | mitmproxy | Configure client_certs with extracted IoT device cert to impersonate device in mTLS handshake | mitmproxy.org | | SSLsplit | Transparent mTLS proxy - forward extracted device cert to complete mutual handshake with cloud | github.com/droe/sslsplit | | eCapture (eBPF) | Hook OpenSSL/BoringSSL on Linux IoT gateways pre-encrypt - decrypts mTLS + TLS 1.3 + PFS | ecapture.cc | | Wireshark + SSLKEYLOGFILE | Decrypt captured mTLS sessions from IoT gateways using NSS pre-master secret logs | wiki.wireshark.org/TLS | | Frida | Runtime hook SSLContext, TrustManager, KeyManager in Android IoT companion apps | frida.re | | Objection | Android sslpinning disable - strips mTLS pinning in companion apps | github.com/sensepost/objection | | apk-mitm | Statically patches IoT companion APK to disable mTLS cert pinning | github.com/shroudedcode/apk-mitm | | MagiskTrustUserCerts | Moves custom CA to system store on rooted Android POS/kiosk to complete mTLS MITM | github.com/NVISOsecurity/MagiskTrustUserCerts | | frida-multiple-unpinning | Universal Frida script targeting 20+ mTLS/pinning patterns in hardened IoT apps | | | NEU-SNS/IoTLS | IMC'21 research repo - SSLKEYLOGFILE files to decrypt MITM'd mTLS connections across 32 devices | | | mitmrouter | Linux-based IoT traffic interception router - intercepts device TLS at network level | |

المدونات والمقالات

  • mTLS: When Certificate Authentication is Done Wrong
  • mTLS Authentication in IoT: Enhancing Security for Connected Devices
  • Hands On IoT MitM Part 1 - AWS IoT MQTT + mTLS Interception
  • OWASP MASTG-TECH-0012: Bypassing Certificate Pinning in Android IoT Companion Apps
  • Theory to Practice: mTLS in Action Part 1
  • Configuring mTLS on Mosquitto MQTT Broker
  • AWS IoT Docs: X.509 Client Certificates and Fleet Provisioning
  • Azure IoT Hub: mTLS X.509 CA Authentication Concept

الأوراق البحثية

  • Evaluation of TLS and mTLS in Internet of Things Systems - MIUN DiVA, 2024
  • Atlas: Enabling Cross-Vendor mTLS Authentication for IoT - arXiv 2025
  • Lightweight mTLS Authentication for Industrial IoT - PMC/NIH 2023
  • Quantum-Enhanced mTLS for IoT Battlefield Networks - IJPSAT
  • AI vs. IoT Security: Fingerprinting and Defenses Against TLS Attacks - IEEE Xplore 2025

يوتيوب

  • Intercepting IoT Device Traffic with ARP Poisoning + mitmproxy TLS Intercept
  • Using Linux to Intercept IoT Device Traffic with mitmrouter
  • Mutual TLS - The Backend Engineering Show Deep Dive
  • Intercepting SSL/TLS - Fiddler and MITMProxy Decrypt Walkthrough
  • Decrypting Kubernetes mTLS Traffic - eCapture, Custom CA, eBPF Methods
  • Mastering mTLS: Stop MITM Attacks and Boost API/IoT Security
  • Introduction to IoT Penetration Testing Webinar - CyberWarFare Labs

نظرة عامة على بروتوكولات إنترنت الأشياء

  • IoT Protocols Overview
  • IoT Architecture
  • Attacking IoT Devices from Web Perspective
  • Awesome Industrial Protocols

أمان السحابة والأنظمة الخلفية

أمان AWS IoT

  • AWS Penetration Testing Policy
  • AWS Pentesting Guide - HackerOne
  • A few notes on AWS Nitro Enclaves

الأساسيات

  • Comprehensive AWS Pentesting Guide - BreachLock
  • AWS Pentest Methodology - MorattiSec
  • AWS Penetration Testing Methodology - Rootshell
  • AWS Penetration Testing Techniques 2025

الأدوات

  • CloudFox - Cloud Attack Paths
  • S3Scanner - Leaky Bucket Discovery
  • Cloudfoxable Labs
  • AWS Security Pentesting Resources
  • Pacu - AWS Exploitation Framework
  • ScoutSuite - Multi-cloud Security Auditing
  • Prowler - Cloud Security Assessment

الثغرات الأمنية

  • 7 Best AWS Pentesting Tools 2026
  • PayloadsAllTheThings - AWS Pentest

Firebase / أخطاء إعداد السحابة

  • Firebase Security Rules Testing
  • Misconfigured Firebase Databases

أمان تطبيقات الهواتف المحمولة

أندرويد

  • Android App Reverse Engineering 101
  • Android Application Pentesting Book
  • Android Pentest Video Course - TutorialsPoint
  • Android Tamer
  • Android Hacker's Handbook
  • A first look at Android 14 forensics
  • Deobfuscating Android ARM64 strings with Ghidra
  • Introduction to Fuzzing Android Native Components
  • Hacking Android Games
  • Intercepting HTTPS Communication in Flutter

استغلال نواة أندرويد

  • Android Kernel Exploitation
  • Attacking Android Binder: Analysis and Exploitation of CVE-2023-20938
  • Attacking the Android kernel using the Qualcomm TrustZone
  • Driving forward in Android drivers
  • Analyzing a Modern In-the-wild Android Exploit
  • Exploiting Android's Hardened Memory Allocator
  • GPUAF - Two ways of Rooting All Qualcomm based Android phones
  • The Qualcomm DSP Driver - Unexpectedly Excavating an Exploit
  • Qualcomm DSP Kernel Internals
  • Binder Fuzzing

مخصص الذاكرة Scudo في أندرويد

  • Android: Scudo
  • Behind the Shield: Unmasking Scudo's Defenses
  • scudo Hardened Allocator - Unofficial Internals Documentation

iOS

  • iOS Pentesting Guide
  • OWASP Mobile Security Testing Guide
  • An iOS hacker tries Android
  • Analyzing iOS Kernel Panic Logs
  • Blasting Past iOS 18
  • Emulating an iPhone in QEMU
  • First analysis of Apple's USB Restricted Mode bypass (CVE-2025-24200)
  • Exploring UNIX pipes for iOS kernel exploit primitives

الأنظمة الصناعية والسيارات

ICS/SCADA

  • ICS Village
  • ICS Discord Group
  • Controlthings.io Platform
  • Applied Cyber Security and the Smart Grid
  • Deep Lateral Movement in OT Networks
  • Hacking ICS Historians: The Pivot Point from IT to OT
  • OPC UA Deep Dive Series - Parts 1-5
  • Inside a New OT/IoT Cyberweapon: IOCONTROL
  • Attention, High Voltage: Exploring the Attack Surface of the Rockwell Automation PowerMonitor 1000

أمان السيارات

  • Awesome Vehicle Security
  • Car Hacking Village
  • Jeep Hack
  • Subaru Head Unit Jailbreak
  • Car Hacking Practical Guide 101
  • CAN Injection: keyless car theft
  • How I Hacked my Car Series - Parts 1-6
  • How I Also Hacked my Car
  • Extracting Secure Onboard Communication (SecOC) keys from a 2021 Toyota RAV4 Prime
  • Recovering an ECU firmware using disassembler and branches
  • Automotive Memory Protection Units: Uncovering Hidden Vulnerabilities
  • Web Hackers vs The Auto Industry: Critical Vulnerabilities in Cars (Sam Curry, 2023)
  • Hacking Kia: Remotely Controlling Cars With Just a License Plate (Sam Curry, 2024)
  • Hacking Subaru: Tracking and Controlling Cars via the STARLINK Admin Panel (Sam Curry, 2025)
  • Pwn2Own Automotive (ZDI Blog Category - 2024 & 2025 Tokyo)
  • Synacktiv Publications - Pwn2Own Automotive Writeups
  • Awesome CAN Bus - Curated Resources

شواحن السيارات الكهربائية

  • A Detailed Look at Pwn2own Automotive EV Charger Hardware
  • Pwn2Own Automotive 2024: Hacking the ChargePoint Home Flex
  • Reverse engineering an EV charger
  • Pwn2Own Automotive 2024: Autel MaxiCharger Analysis (Computest Sector7)
  • SaiFlow Blog - OCPP/EV Charging Protocol Vulnerabilities

أنظمة الدفع

اختراق أجهزة الصراف الآلي

  • Introduction to ATM Penetration Testing
  • Pwning ATMs for Fun and Profit
  • Jackpotting ATMs Redux - Barnaby Jack
  • Root Shell on Credit Card Terminal

Payment Village

  • Payment Village

الأدوات

أدوات العتاد

  • Bus Pirate
  • Bus Pirate 5: The Swiss ARRRmy Knife of Hardware Hacking
  • The Shikra
  • Attify Badge
  • Flipper Zero
  • HackRF
  • RTL-SDR
  • An In-Depth Look at the ICE-V Wireless FPGA Development Board

متعددة الأغراض

  • Logic Analyzer - Saleae
  • JTAGulator
  • EEPROM Reader/SOIC Cable

محولات التنقيح- ST-Link

  • Segger J-Link
  • FTDI-based Adapters
  • Black Magic Probe

USB

  • FaceDancer21
  • RfCat
  • NullSec Ducky Payloads - مجموعة حمولات Rubber Ducky BadUSB لأنظمة Windows وmacOS وLinux.

Flipper Zero

  • NullSec Flipper Suite - مجموعة حمولات Flipper Zero لاختبار اختراق RF وRFID/NFC وBadUSB والأشعة تحت الحمراء واللاسلكي.
  • PineFlip - تطبيق مرافق لـ Flipper Zero على Linux مع عكس الشاشة ومدير الملفات وإدارة البرامج الثابتة.

Hak5

  • Hak5 Field Kits
  • NullSec Pineapple Suite - مجموعة حمولات WiFi Pineapple لـ deauth وevil twin والتقاط handshake واستطلاع الشبكة.

أدوات البرمجيات

أطر الاستغلال

  • BlueSploit
  • IoTSecFuzz
  • PENIOT
  • ISF - Industrial Security Framework
  • HAL - Hardware Analyzer
  • PRET - Printer Exploitation Toolkit
  • Expliot Framework
  • RouterSploit
  • HomePwn
  • Firmware Analysis Toolkit (FAT)
  • Shambles: The Next-Generation IoT Reverse Engineering Tool

تحليل البرامج الثابتة

  • Samsung Firmware Magic

أدوات Fuzzing

  • The art of Fuzzing: Introduction
  • A LibAFL Introductory Workshop
  • The Blitz Tutorial Lab on Fuzzing with AFL++
  • State of Linux Snapshot Fuzzing
  • Fuzzing between the lines in popular barcode software
  • Boofuzz
  • Syzkaller - Kernel Fuzzer
  • parking-game-fuzzer

الأساسيات

  • OWASP Fuzzing Info
  • Fuzz Testing of Application Reliability
  • FuzzingPaper Collection

Fuzzing الخاص بإنترنت الأشياء

  • Fuzzing ICS Protocols
  • Fuzzowski - Network Protocol Fuzzer
  • FIRM-AFL: High-Throughput IoT Firmware Fuzzing
  • Snipuzz: Black-box Fuzzing of IoT Firmware
  • Fuzzing IoT Binaries Part 1
  • Fuzzing IoT Binaries Part 2
  • Awesome Embedded Fuzzing

الأدوات

  • AFL Training Exercises
  • Frankenstein - Broadcom/Cypress Firmware Emulation for Fuzzing
  • Dr. Memory

أنظمة تشغيل اختبار الاختراق

  • AttifyOS
  • IoT Penetration Testing OS v1
  • EmbedOS
  • Sigint OS - LTE IMSI Catcher
  • Instant GNU Radio OS
  • Dragon OS - SDR Software
  • Skywave Linux - SDR
  • Zephyr RTOS
  • Ubuntu LTS

محركات البحث

  • Shodan
  • Censys
  • ZoomEye
  • BinaryEdge
  • Thingful
  • Wigle
  • Hunter.io
  • BuiltWith
  • Recon-ng
  • PublicWWW
  • FCC ID Database
  • CVE PoC Search - ابحث في مستودعات PoC العامة على GitHub حسب معرّف CVE.

الأمن الدفاعي

نمذجة التهديدات

  • STRIDE Threat Model Guide - Practical DevSecOps
  • OWASP Threat Modeling Process
  • STRIDE-based Threat Modeling for IoT Precision Agriculture

إطار STRIDE

  • What is STRIDE in Threat Modeling - Security Compass
  • Threat Modeling with ATT&CK - MITRE
  • What is Threat Modeling - Fortinet

نمذجة التهديدات الخاصة بإنترنت الأشياء

  • STRIDE Threat Modeling for IoT Smart Home
  • STRIDE Threat Modeling for Smart Solar Energy Systems
  • STRIDE Threat Modeling for IoT Healthcare Systems
  • STRIDE for IoT Agriculture - IEEE

التطوير الآمن

  • Compiler Options Hardening Guide for C and C++
  • Linux Hardening Guide
  • Docker Security - Step-by-Step Hardening
  • How To Secure A Linux Server

الإرشادات والمعايير

  • NIST IoT Cybersecurity Framework
  • NIST SP 800-213 - IoT Device Cybersecurity Guidance
  • NISTIR 8259 - Foundational Cybersecurity Activities for IoT Manufacturers
  • ETSI EN 303 645 - Cyber Security for Consumer IoT
  • OWASP IoT Top 10 (2018)
  • OWASP IoT Project

أدلة التحصين

  • IoT Device Hardening Best Practices
  • Embedded Linux Hardening
  • Zephyr RTOS Security Features

الاستجابة للحوادث

  • IoT Forensics and Incident Response
  • Embedded Device Forensics

موارد التعلم

منصات التدريب

  • OpenSecurityTraining2
  • cryptopals

أوراق الغش

  • Hardware Hacking Cheatsheet
  • Nmap Tutorial
  • Pentest Hardware Handbook
  • THC's favourite Tips, Tricks & Hacks
  • Cross Cache Attack CheetSheet

أدلة الثغرات

  • OWASP IoT Top 10 2018 Mapping
  • Reflecting on OWASP IoT Top 10
  • CVE North Stars
  • IoT Vulnerabilities with CVE and PoC
  • Linux Privilege Escalation

أدلة اختبار الاختراق

  • Shodan Pentesting Guide
  • Modern Vulnerability Research on Embedded Systems
  • Awesome Embedded Systems Vulnerability Research

قنوات YouTube

  • Joe Grand
  • LiveOverflow
  • Binary Adventure
  • EEVBlog
  • Craig Smith
  • IoTSecurity101
  • Besim ALTINOK
  • Ghidra Ninja
  • Cyber Gibbons
  • Scanline
  • Aaron Christophel
  • Valerio Di Giampietro
  • Gamozo Labs - Printer Hacking

الكتب

اختراق الأجهزة

  • The Hardware Hacking Handbook - Jasper van Woudenberg & Colin O'Flynn (2021)
  • Practical Hardware Pentesting - Jean-Georges Valle (2021)
  • Practical Hardware Pentesting 2nd Edition (2023)
  • Hardware Hacking: Have Fun While Voiding Your Warranty - Joe Grand (2004)
  • Hacking the Xbox - Andrew "bunnie" Huang (2013)
  • The Hardware Hacker - Andrew "bunnie" Huang (2019)
  • The Art of PCB Reverse Engineering - Keng Tiong (2015)
  • Manual PCB-RE: The Essentials - Keng Tiong (2021)
  • Hardware Security Training, Hands-on! (2023)
  • Hardware Security: Challenges and Solutions (2025)
  • Mastering Hardware Hacking (2025)
  • Ultimate Hardware Hacking Gear Guide
  • Microcontroller Exploits (2024)
  • Engineering Secure Devices - Dominik Merli (2024)
  • Cryptography and Embedded Systems Security - Hou & Breier (2024)

البرامج الثابتة والهندسة العكسية

  • The Firmware Handbook - Jack Ganssle (2004)
  • Learning Linux Binary Analysis - Ryan O'Neill (2016)
  • Fuzzing Against the Machine (2023)
  • Rootkits and Bootkits - Matrosov, Rodionov, Bratus (2019)
  • Ghidra Software Reverse Engineering 2nd Edition (2025)
  • The Ghidra Book 2nd Edition - Nance & Eagle (2026)
  • The Definitive Handbook on Reverse Engineering Tools (2025)
  • x86 Software Reverse-Engineering, Cracking, and Counter-Measures - Domas & Domas (2024)
  • Fuzzing Android - Zawawy, Rodionov et al. (2026)
  • From Day Zero to Zero Day - Eugene Lim (2025)
  • The Spacecraft Hacker's Handbook - Olchawa & Starcik (2026)

أمن إنترنت الأشياء

  • Abusing the Internet of Things - Nitesh Dhanjani (2015)
  • IoT Penetration Testing Cookbook - Aaron Guzman & Aditya Gupta (2017)
  • Practical IoT Hacking: The Definitive Guide (2021)
  • PatrIoT: Practical and Agile Threat Research for IoT (2022)
  • The Embedded Linux Security Handbook - St. Onge & Krishnan (2025)
  • Securing Smart Things - Massimo Nardone (2026)

اللاسلكي وRF

  • Inside Radio: An Attack and Defense Guide - Qing Yang, Lin Huang (2018)
  • Hack the Airwaves: Advanced BLE Exploitation (2023)
  • Practical SDR - David Clark & Paul Clark (2025)
  • The Art of ARM Assembly, Volume 1 - Randall Hyde (2025)
  • The Wireless Cookbook - Bill Zimmerman (2026)

الأنظمة المدمجة والجوالة

  • Linksys WRT54G Ultimate Hacking - Paul Asadoorian (2007)

NFC/RFID

  • Near Field Communication (NFC): From Theory to Practice (2012)
  • Security Issues in Mobile NFC Devices - Michael Roland (2024)

أمن السيارات

  • The Car Hacker's Handbook - Craig Smith (2016)
  • Building Secure Automotive IoT Applications - Oka et al. (2024)
  • Offensive Automotive Cybersecurity - Nasser & Oka (2025)

الأمن الصناعي والعام

  • Gray Hat Hacking 5th Edition (2018)
  • Black Hat Python 2nd Edition (2021)
  • Attacking Network Protocols - James Forshaw (2017)
  • Securing Industrial Control Systems - Rahman et al. (2026)

الأوراق البيضاء والتقارير

  • IOActive: State of Silicon Chip Hacking 2025

سلسلة إنترنت الأشياء

  • IoT Series I-IV
  • Intro to Embedded RE Series

المختبرات وCTFs

التطبيقات القابلة للاستغلال

  • DVID - Damn Vulnerable IoT Device
  • IoTGoat - Vulnerable OpenWrt Firmware
  • BLE CTF
  • Microcorruption
  • ARM-X CTF

الأجهزة

  • Hardware Hacking 101
  • Damn Vulnerable Safe
  • Sticky Fingers DV-Pi

الصناعي

  • Damn Vulnerable Chemical Process
  • Damn Vulnerable SS7 Network

VoIP

  • Hacklab VulnVoIP

مسابقات CTF

  • RHme Series (2015-2017)
  • IoT Village CTF

تحديات CTF للأجهزة

  • RHme-2016
  • RHme-2017

تحديات CTF لإنترنت الأشياء

تحديات CTF للأنظمة المدمجة/البرامج الثابتة

  • Emulate to Exploitate

تحديات CTF لـ ARM

  • Azeria Labs ARM Challenges

منصات التعلم المستمر

  • Hack The Box
  • Root Me
  • Pwnable.kr
  • CTFtime

إعداد المختبر

  • Webthings Gateway - Raspberry Pi

البحث والمجتمع

البحث التقني

  • Dropcam Hacking
  • LED Light Hacking
  • PS4 Jailbreak Status
  • Lenovo Watch X Privacy Issues
  • Smart Scale Privacy Issues
  • Besder IP Camera Security Analysis

المدونات- Team82 Research

  • Voidstarsec
  • wrongbaud
  • Firmware Analysis
  • Exploitee.rs
  • Payatu Blog
  • Raelize Blog
  • JCJC Dev
  • W00tsec
  • Devttys0
  • Embedded Bits
  • Keenlab
  • Courk.cc
  • IoT Security Wiki
  • Cybergibbons
  • Firmware.RE
  • K3170makan
  • Tclaverie
  • Besimaltinok
  • Ctrlu
  • IoT Pentest
  • Duo Decipher
  • Sp3ctr3
  • 0x42424242
  • Dantheiotman
  • Danman
  • Quentinkaiser
  • Quarkslab
  • Ice9

منصات المجتمع

  • IoTSecurity101 Telegram
  • IoTSecurity101 Reddit
  • Hardware Hacking Telegram

Villages

  • RF Hackers

باحثون للمتابعة

  • Jilles
  • Joe Fitz
  • Aseem Jakhar
  • Cybergibbons
  • Jasper
  • Dave Jones
  • bunnie
  • Ilya Shaposhnikov
  • Mark C.
  • Aaron Guzman
  • Yashin Mehaboobe
  • Arun Magesh
  • Mr-IoT
  • QKaiser
  • 9lyph

أبحاث خاصة بالأجهزة

الكاميرات

  • ARLO: I'M WATCHING YOU
  • Hacking a Tapo TC60 Camera
  • Rooting a Hive Camera
  • Pwn2Own: Synology BC500 IP Camera
  • Turning Camera Surveillance on its Axis
  • Pwn2Own Ireland 2024 - Ubiquiti AI Bullet

أجهزة المنزل الذكي

  • Hacking a Smart Home Device
  • The Silent Spy Among Us: Smart Intercom Attacks
  • Pwnassistant - Home Assistant RCE
  • Hacking Sonoff Smart Home IoT Device

مكبرات الصوت الذكية

  • Turning Google smart speakers into wiretaps for $100k
  • Smart Speaker Shenanigans: Making the Sonos ONE Sing its Secrets
  • Listen Up: Sonos Over-The-Air Remote Kernel Exploitation and Covert Wiretap
  • Streaming Zero-Fi Shells to Your Smart Speaker

الطابعات

  • Pwning a Brother labelmaker, for fun and interop!
  • lexmark printer haxx
  • Pwn2Own Ireland 2024: Canon imageCLASS MF656Cdw
  • Print Scan Hacks: Brother devices

الطائرات بدون طيار

  • DJI Mavic 3 Drone Research: Firmware Analysis
  • DJI Mavic 3 Drone Research: Vulnerability Analysis
  • DJI - The ART of obfuscation
  • Local Privilege Escalation on the DJI RM500 Smart Controller

أجهزة المطبخ

  • Let Me Cook You a Vulnerability: Exploiting the Thermomix TM5

أجهزة NAS

  • A Pain in the NAS: Synology DS920+ Edition
  • Weekend Destroyer - RCE in Western Digital PR4100 NAS
  • Exploiting the Synology TC500 at Pwn2Own Ireland 2024

أجهزة الألعاب

  • Hacking the Nintendo DSi Browser
  • mast1c0re: Exploiting the PS4 and PS5 through a game save
  • Being Overlord on the Steam Deck with 1 Byte
  • Hacking the XBox 360 Hypervisor

الهواتف/الأجهزة اللوحية

  • Pixel 6 Bootloader Series
  • Solo: A Pixel 6 Pro Story
  • Gaining kernel code execution on an MTE-enabled Pixel 8
  • Bypassing MTE with CVE-2025-0072
  • Debugging the Pixel 8 kernel via KGDB
  • A First Glimpse of the Starlink User Terminal
  • Diving into Starlink's User Terminal Firmware

أبحاث TrustZone و TEE

  • ARM TrustZone: pivoting to the secure world
  • TEE Reversing
  • A Deep Dive into Samsung's TrustZone - Parts 1-3
  • Researching Xiaomi's TEE
  • Kinibi TEE: Trusted Application Exploitation
  • Reversing Samsung's H-Arx Hypervisor Framework
  • EL3vated Privileges: Glitching Google WiFi Pro from Root to EL3

أبحاث Pwn2Own

  • Your not so "Home Office" - SOHO Hacking at Pwn2Own
  • Pwn2Own Toronto 2023 Series - Parts 1-5
  • Pwn2Own: WAN-to-LAN Exploit Showcase

MCP / AI Agent

هندسة عكسية للبلوتوث

  • bt-re-mad-skillz - مهارات LLM لهندسة عكسية لبرامج ثابتة لوحدة تحكم البلوتوث على طبقة HCI، لـ Claude Code و ChatGPT/Codex.

المساهمة

المساهمات مرحب بها. أرسل PR مع موارد جديدة تتبع البنية الموجودة.

تنزيل الأداة
  • أمان السحابة والأنظمة الخلفية
    • أمان AWS IoT
    • Firebase / الأخطاء الإعدادية السحابية
  • أمان تطبيقات الهاتف المحمول
    • Android
    • iOS
  • الأنظمة الصناعية والسيارات
    • ICS/SCADA
    • أمان السيارات
    • شواحن السيارات الكهربائية
  • أنظمة الدفع
    • اختراق أجهزة الصراف الآلي
    • قرية الدفع
  • الأدوات
    • أدوات العتاد
    • أدوات البرمجيات
    • أدوات الفَزْزَة
    • أنظمة تشغيل اختبار الاختراق
    • محركات البحث
  • الأمان الدفاعي
    • نمذجة التهديدات
    • التطوير الآمن
    • الاستجابة للحوادث
  • موارد التعلّم
    • منصات التدريب
    • أوراق الغش
    • أدلة الثغرات
    • أدلة اختبار الاختراق
    • قنوات YouTube
    • الكتب
    • سلسلة إنترنت الأشياء
  • المعامل ومسابقات CTF
    • التطبيقات القابلة للاستغلال
    • مسابقات CTF
    • منصات التعلّم المستمر
    • إعداد المعمل
  • الأبحاث والمجتمع
    • الأبحاث التقنية
    • المدونات
    • منصات المجتمع
    • القرى
    • باحثون للمتابعة
    • أبحاث خاصة بالأجهزة
    • أبحاث TrustZone و TEE
    • أبحاث Pwn2Own
  • MCP / وكيل الذكاء الاصطناعي
    • الهندسة العكسية لـ Bluetooth
  • github.com/httptoolkit/frida-android-unpinning
    github.com/NEU-SNS/IoTLS
    github.com/nmatt0/mitmrouter
  • F-Secure Labs
  • MG.lol
  • CJHackerz
  • Bunnie's Blog
  • Synacktiv Publications
  • Cr4.sh
  • Ktln2
  • Naehrdine
  • Limited Results
  • Fail0verflow
  • Exploit Security
  • Attify Blog
  • Jilles.com
  • Syss Tech Blog
  • HardBreak Wiki
  • 8ksec
  • Starlabs
  • boschko.ca
  • 0xtriboulet
  • Nozomi Networks