
awesome-connected-things-sec — Updated!
Eine kuratierte Liste von Sicherheitsressourcen für alle vernetzten Dinge
🔐 Awesome Connected Things Security Resources
Sicherheitsforschung und Exploitation-Techniken für IoT-, Embedded-, Industrie- und Automobilsysteme.
Inhalt
- Hardware-Angriffe
- Drahtlose Protokolle
- Firmware-Sicherheit
- Netzwerk- und Webprotokolle
- Cloud- und Backend-Sicherheit
- Sicherheit mobiler Anwendungen
- Industrie und Automotive
- Zahlungssysteme
- Tools
- Defensive Sicherheit
- Lernressourcen
- Labs und CTFs
- Forschung und Community
- MCP / KI-Agent
Hardware-Angriffe
Grundlagen
- IoT Hardware Guide
- Intro to Hardware Hacking - Dumping Your First Firmware
- An Introduction to Hardware Hacking
- Hardware Toolkits for IoT Security Analysis
- Hardware Hacking for IoT Devices - Offensive IoT Exploitation
Schnittstellenangriffe
UART
- Identifying UART Interface
- Serial Terminal Basics
- Reverse Engineering Serial Ports
- Intro to Embedded RE: UART Discovery and Firmware Extraction via UBoot
- Using UART to Connect to a Chinese IP Cam
- A Journey into IoT Hardware Hacking: UART
- Accessing and Dumping Firmware Through UART
- UART Connections and Dynamic Analysis on Linksys e1000
JTAG
- Hardware Hacking 101: Introduction to JTAG
- How to Find the JTAG Interface
- Analyzing JTAG
- Bus Pirate JTAG Connections with OpenOCD
- Extracting Firmware from External Memory via JTAG
- The Hitchhacker's Guide to iPhone Lightning and JTAG Hacking
- Debugging AVR Microcontrollers Through JTAG
SWD (Serial Wire Debug)
- SWD Protocol Overview - HardBreak Wiki
- Unveiling Vulnerabilities: Exploring SWD Attack Surface in Hardware
- Introduction to ARM Serial Wire Debug Protocol
- Serial Wire Debug and CoreSight Architecture
- LibSWD - Serial Wire Debug Open Library
- Hardware Hacking and Exploitation Bootcamp - SWD
SPI
- Hardware Hacking 101: Identifying and Dumping eMMC Flash
- Dumping Firmware from Router Using Bus Pirate - SPI
- Extracting Flash Memory over SPI
- Extracting Firmware from Embedded Devices (SPI NOR Flash)
- How to Flash Chip of a Router with a Programmer
- TPM 2.0: Extracting Bitlocker Keys Through SPI
I2C
- IoT Security Part 16: Hardware Attack Surface I2C
- I2C Exploitation - HackTricks
- Non-invasive I2C Hardware Trojan Attack Vector (PDF)
- Hardware Hacking: I2C Injection with Bus Pirate
- Safeguarding SPI, I2C, and I3C Protocols
TPM
- Introduction to TPM (Trusted Platform Module)
- Trusted Platform Module Security Defeated in 30 Minutes
Speicherextraktion
eMMC
- eMMC Protocol
- RPMB: A Secret Place Inside the eMMC
- eMMC Data Recovery from Damaged Smartphone
- Unleash Your Smart-Home Devices: Vacuum Cleaning Robot Hacking
- Hands-On IoT Hacking: Rapid7 at DEF CON 30
Seitenkanal- und Fehlerinjektion
Grundlagen
- Side Channel Attacks - Yifan Lu
- Attacks on Implementations of Secure Systems
- Fuzzing, Binary Analysis, IoT Security Collection
Glitching-Angriffe
- NAND Glitching Attack on Wink Hub
- Voltage Glitching with Crowbars Tutorial
- Voltage Glitching Attack using iCEstick Glitcher
- FPGA Glitching and Side Channel Attacks - Samy Kamkar
- Hardware Power Glitch Attack - rhme2
- Keys in Flash - Glitching AES Keys from Arduino
- Implementing Practical Electrical Glitching Attacks
- How to Voltage Fault Injection
- Glitcher Part 1 - Reproducible Voltage Glitching on STM32 Microcontrollers
- STM32L05 Voltage Glitching
Leistungsanalyse
Weitere Mikrocontroller
- Dumping the Amlogic A113X Bootrom
- Retreading The AMLogic A113X TrustZone Exploit Process
- Reverse Engineering an Unknown Microcontroller
- Hacking Microcontroller Firmware Through a USB
- There's A Hole In Your SoC: Glitching The MediaTek BootROM
PCIe- und DMA-Angriffe
- A Practical Tutorial on PCIe for Total Beginners on Windows - Part 1
- A Practical Tutorial on PCIe for Total Beginners on Windows - Part 2
- PCIe DMA Attack against a Secured Jetson Nano (CVE-2022-21819)
Drahtlose Protokolle
RF-Grundlagen
- Complete Course in Software Defined Radio - Michael Ossmann
- Understanding Radio
- Introduction to Software Defined Radio
- Introduction to GNU Radio Companion
- Creating a Flow Graph in GNU Radio Companion
- Analyzing Radio Signals 433MHz
- Recording Specific Radio Signals
- Replay Attacks with Raspberry Pi and rpitx
- Reverse Engineering a Car Key Fob Signal
- GRCON 2021 - Capture the Signal
Bluetooth / BLE
Grundlagen
- Awesome Bluetooth Security
- Traffic Engineering in a Bluetooth Piconet
- BLE Characteristics: A Beginner's Tutorial
- Intro to Bluetooth Low Energy (PDF)
- Bluetooth LE Security Study Guide
- Reverse Engineering BLE Devices
- My Journey Towards Reverse Engineering a Smart Band - Bluetooth-LE RE
Exploitation-Techniken- Intel Edison als Bluetooth LE Exploit Box
- Reverse Engineering und Ausnutzen eines Smart Massagers
- Ich habe MiBand 3 gehackt
- GATTacking Bluetooth Smart Devices
- Untersuchung des August Smart Lock
- Praktische Einführung in BLE GATT Reverse Engineering
- MojoBox - Noch ein nicht so smartes Schloss
- Bluetooth Smartlocks
- Bluetooth Beacon Schwachstelle
- Denial of Pleasure: Angriff auf ungewöhnliche BLE-Ziele mit einem Flipper Zero
- Grand Theft Auto: Ein Blick auf BLE-Relay-Angriffe
- Wie ich Smart Lights gehackt habe: CVE-2022-47758
Schwachstellenforschung
- Bugs in Bluetooth finden
- Sweyntooth-Schwachstellen
- BrakTooth: Chaos im Bluetooth Link Manager verursachen
- BLUFFS: Bluetooth Forward and Future Secrecy Attacks (CVE-2023-24023)
- AirDrop Leak - Sniffing von BLE-Verkehr von Apple-Geräten
- BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution
- BRAKTOOTH: Chaos im Bluetooth Link Manager verursachen (PDF)
- Norec Attack: BLE-Verschlüsselung aus Nordics Bibliothek entfernen (CVE-2020-15509)
- BlueDucky - HID-Injection auf ungepatchtem Android (CVE-2023-45866)
- Microsoft Bluetooth-Treiber-Spoofing - CVE-2024-21306
- Bluetooth Auracast / LE Audio Sicherheitsanalyse
Konferenzvorträge
- Blue2thprinting: WTF schaue ich mir hier überhaupt an?
- Open Wounds: Die letzten 5 Jahre haben Bluetooth bluten lassen
- Bluetooth durch meine Maske während der Pandemie sniffen
Tools - Software
- Bluing - Intelligence Gathering für Bluetooth
- BlueToolkit - Bluetooth Classic Schwachstellentests
- btproxy
- hcitool und bluez
- Testen mit GATT Tool
- crackle - BLE-Verschlüsselung knacken
- bettercap
- GATTacker
- BTLEjack - BLE Schweizer Taschenmesser
- DEDSEC Bluetooth Exploit
- BrakTooth ESP32 PoC
- SweynTooth BLE Attacks
- ESP32 Bluetooth Classic Sniffer
- Bluetooth Hacking Sammlung
Tools - Hardware
Tools
Bluetooth-Kaffeemaschinen hacken
- Bluetooth hacken, um Kaffee über GitHub Actions zu brühen - Teil 1
- Bluetooth hacken, um Kaffee über GitHub Actions zu brühen - Teil 2
- Bluetooth hacken, um Kaffee über GitHub Actions zu brühen - Teil 3
Zigbee / Z-Wave
Grundlagen
Ausnutzung
- IoT-Geräte mit dem Attify Zigbee Framework hacken
- Zigator: Analyse der Sicherheit Zigbee-fähiger Smart Homes
- Sicherheitsanalyse von Zigbee mit Zigator und GNU Radio
- Kostengünstiges selektives ZigBee-Jamming
Tools - Software
Tools - Hardware
LoRa / LoRaWAN
- LoRaWAN Sicherheitsübersicht - Tektelic
- Sicherheitsschwachstellen in LoRaWAN
- Wenig Strom, hohes Risiko: Angriffe auf LoRaWAN-Geräte
- LAF - LoRaWAN Auditing Framework
- ChirpOTLE - LoRaWAN Security Framework
Grundlagen
Ausnutzung
- Millionen von Geräten mit LoRaWAN exponiert - SecurityWeek
- Vertrauen Sie LoRaWAN-Netzwerken blind? - IOActive
- LoRaWAN-Verschlüsselungsschlüssel leicht zu knacken - Threatpost
- LoPT: LoRa Penetration Testing Tool (PDF)
Tools
Matter / Thread
Grundlagen
- Matter Standard - CSA-IoT
- Matter Protokoll Wikipedia
- Matter Protokoll Komplettanleitung 2025
- Wie man Smart-Home-Geräte mit Matter absichert
- Smart-Home-Gerätelösungen für Matter - DigiCert
Sicherheitsforschung
- Sicherheitsschwachstellen und Angriffsszenarien in Smart Homes mit Matter
- Trust Matters: Aufdeckung von Schwachstellen im Matter-Protokoll - Nozomi
- Matter over Thread Sicherheit
- State-of-the-Art-Review zur Sicherheit von IoT Wireless PAN Protokollen
- Matter Smart Home - Krasamo
- Threadbare: Praktische Angriffe auf Thread-Netzwerke (Black Hat USA 2024)
- Matter Spezifikation 1.3 - Connectivity Standards Alliance
- Thread Group Sicherheitsanalyse
Mobilfunk (GSM/LTE/5G)
- Awesome Cellular Hacking
- Einführung in die GSM-Sicherheit
- LTE auf Layer Two brechen
- 5Ghoul - 5G NR Angriffe und Fuzzing
- Ausnutzung von CSN.1-Bugs in MediaTek Basebands
- SIM Hijacking
- SigPloit - Telecom Signaling Exploitation Framework
- LTE Sniffer
- 5G NR Jamming, Spoofing und Sniffing
- LTrack: Stealthy Tracking von Mobiltelefonen in LTE
- Open5GS - Open Source 5G/4G Core
- SCAT - Signaling Collection and Analysis Tool für Mobilfunk
Grundlagen
- GSM-Sicherheit Teil 2
- Was ist eine Base Transceiver Station
- Einführung in SS7-Signalisierung
- SS7 Netzwerkarchitektur
- Einführung in SIGTRAN
Ausnutzung
- Wie man seine eigene Rogue GSM BTS baut
- GSM-Schwachstellen mit USRP B200
- Sicherheitstests von 4G (LTE) Netzwerken
- Fallstudie einer SS7/SIGTRAN-Bewertung
Tools
NFC/RFID
- Awesome RFID/NFC Security Talks
- RFID Discord Gruppe
- SoK: Sicherheit von EMV Contactless Payment Systems
- NFC-Relay-Angriff auf Tesla Model Y
DECT (Digital Enhanced Cordless Telecommunications)
- Echtzeit-Abfangen von DECT-Schnurlostelefonen
- Abhören von unverschlüsseltem DECT-Sprachverkehr
- DECT-Sprachverkehr dekodieren: Ausführliche Erklärung
Wi-Fi
Protokollschwachstellen
- Framing Frames: Umgehung der Wi-Fi-Verschlüsselung durch Manipulation von Transmit Queues
- Man-in-the-Middle-Angriffe ohne Rogue AP: Wenn WPAs auf ICMP Redirects treffen
- WPAxFuzz: Schwachstellen in Wi-Fi-Implementierungen aufspüren
- Untangling the Knot: Zugriffskontrolle in drahtlosen Heim-Mesh-Netzwerken brechen
Ausnutzung
- Over The Air: Ausnutzung von Broadcoms Wi-Fi-Stack (Teil 1)
- Over The Air: Ausnutzung von Broadcoms Wi-Fi-Stack (Teil 2)
- Over The Air: Ausnutzung des Wi-Fi-Stacks auf Apple-Geräten
- Reverse Engineering von Broadcom Wireless-Chipsätzen
- Ausnutzung von Qualcomm WLAN und Modem Over the Air
- Windows Wi-Fi-Treiber RCE-Schwachstelle - CVE-2024-30078
- Wenn eine Wi-Fi-SSID Root auf einem MT02 Repeater verschafft - Teil 1
- Wenn eine Wi-Fi-SSID Root auf einem MT02 Repeater verschafft - Teil 2
Reverse Engineering von WiFi
- Reverse Engineering von WiFi auf RISC-V BL602
- Geheimnisse des ESP32 enthüllen: Erstellung eines Open-Source MAC Layer
- Geheimnisse des ESP32 enthüllen: Reverse Engineering von RX
USB
UWB (Ultra-Wideband)
TETRA
- All cops are broadcasting: TETRA unter der Lupe
- TETRA:BURST - Fünf Schwachstellen im TETRA-Standard (Midnight Blue)
- TETRA:BURST 2:ELECTRIC BOOGALOO - Ende-zu-Ende-Verschlüsselung gebrochen (BlackHat USA 2025)
- TETRA Decoder - Open Source TETRA-Empfänger
- Praktisches TETRA-Sniffing mit SDR
Firmware-Sicherheit
Grundlagen
- Einführung in die Firmware-Analyse - OWASP
- OWASP Firmware Security Testing Methodology
- IoT Security Verification Standard (ISVS)
- Reversing 101
- Praktische Firmware-Extraktion, -Erkundung und -Emulation
Extraktion
- Router-Analyse Teil 1: UART-Erkennung und SPI-Flash-Extraktion
- Hardware-Hacking-Tutorial: Firmware dumpen und reversen
- Firmware-Beispiele - firmware.center
- BasicFUN-Serie: Hardware-Analyse / SPI-Flash-Extraktion
- BasicFUN-Serie: Reverse Engineering von Firmware / SPI-Flash neu flashen
- Nachrüsten verschlüsselter Firmware ist eine schlechte Idee
Statische Analysetools
- EMBA - Embedded Linux Firmware Analyzer
- FACT - Firmware Analysis and Comparison Tool
- Binwalk v3
- Firmwalker
- fwanalyzer
- fwhunt-scan - UEFI Firmware-Analyse
- ByteSweep
- BINSEC
- unblob - Extraktions-Framework
- Checksec.sh
- Firmware Modification Kit
Dynamische Analyse und Emulation
- Firmadyne - Automatisierte Firmware-Emulation
- FirmAE - Firmware-Analyse und -Emulation
- QEMU
- PANDA - Architekturneutrale dynamische Analyse
- Avatar2 - Dynamische Firmware-Analyse
- Renode - Emulator für eingebettete Systeme
- Unicorn Engine - CPU-Emulator
- Qiling Framework
- HALucinator
- FirmWire - Baseband-Firmware-Emulation
- SymQEMU
- S2E - Selektive symbolische Ausführung
- Bochs - x86-Emulator
- SAME70 Emulator
- Emulate Until You Make it
Emulations-Tutorials- Firmware-Emulation mit QEMU
- ARM-Router-Firmware emulieren - Azeria Labs
- IoT-Firmware einfach emulieren
- IoT-Binäranalyse und -Emulation Teil 1
- Cross-Debugging für ARM/MIPS mit QEMU
- QEMU + Buildroot 101
- Simulieren und Aufspüren von Firmware-Schwachstellen mit Qiling
- Qiling und Binäremulation zum automatischen Entpacken
- D-Link debuggen: Firmware emulieren und Hardware hacken
- Adaptives Emulations-Framework für Multi-Architektur-IoT
- Automatische Firmware-Emulation durch invaliditätsgestützte Wissensinferenz
- Emulation der RH850-Architektur mit Unicorn Engine
- Icicle: Ein neu gestalteter Emulator für Grey-Box-Firmware-Fuzzing
- Herausforderungen und Fallstricke bei der Emulation von sechs aktuellen isländischen Haushaltsroutern
- Meine Emulation fliegt zum Mond... bis zur False Flag
- Wie man Android Native Libraries mit Qiling emuliert
OTA-Update-Sicherheit
Grundlagen
- IoT-Firmware-Sicherheit und Update-Mechanismen
- Implementierung von OTA-Updates für IoT-Geräte
- Sichere OTA-Boot-Ketten und Firmware-Verifikation
- Der Schlüssel zur Firmware-Sicherheit in vernetzten IoT-Geräten
- Sicherheitsüberlegungen für OTA-Updates - Stack Overflow
Angriffsvektoren
- Top 10 IoT-Schwachstellen - OTA-Update-Angriffe
- IoT-Geräte aktualisieren 2025: Best Practices
- Überblick über IoT-Firmware-Schwachstellen und Auditierungstechniken
RTOS-Sicherheit
Zephyr RTOS
- Zephyr RTOS GitHub
- Zephyr-Schwachstellenliste
- NCC Group Zephyr und MCUboot Sicherheitsbewertung
- 26 Schwachstellen in Zephyr und MCUboot
- Sicherheit im Zephyr RTOS angehen
- Sicherheit mit Zephyr RTOS verbessern
FreeRTOS
- FreeRTOS 13 Schwachstellen im TCP/IP-Stack
- Ausnutzung von Speicherkorruption in FreeRTOS - ShmooCon
- RTOS-Sicherheitsanalyse - USENIX
- Dynamisches Schwachstellen-Patching für RTOS
- AWS FreeRTOS Schwachstellen
Reverse-Engineering-Tools
- Ghidra
- IDA Pro
- Radare2
- Cutter - GUI für Radare2
- Binary Ninja
- GDB
- RetDec - Decompiler
- Diaphora - Binary Diffing
- Angr - Binäranalyse
- Frida - Dynamische Instrumentierung
- Ret-sync
- OllyDbg
- x64dbg
- Hopper
- Immunity Debugger
- PEiD
- Ghidriff - Ghidra Binary Diffing Engine
- Der rev.ng-Decompiler wird Open Source
- Einführung in Cutter
- pyghidra-mcp: Headless Ghidra MCP Server
- Mindshare: Verwendung der Binary Ninja API zur Erkennung potenzieller Use-after-free-Schwachstellen
Reverse-Engineering-Tutorials
- Reverse Engineering und Patchen mit Ghidra
- Reverse Engineering mit Ghidra: Firmware-Verschlüsselung knacken
- Firmware-Reversing mit Radare
- ESP8266-Firmware reversen
- Automatisierung der Binär-Schwachstellenerkennung mit Ghidra und Semgrep
- Bugs im Netgear-Router finden
Ghidra-Tutorials
- Debugger Ghidra Class
- Ghidra 101: Cursor-Text-Hervorhebung
- Ghidra 101: Stack-Strings dekodieren
- Ghidra erweitern Teil 1: Einrichten einer Entwicklungsumgebung
- Expanding the Dragon: Hinzufügen einer ISA zu Ghidra
- Ghidra nanoMIPS ISA-Modul
- Binäre Typinferenz in Ghidra
- Ein Ghidra-Prozessormodul schreiben
Online-Assembler
ARM-Exploitation
- Azeria Labs ARM-Tutorials
- ARM-Exploitation für IoT
- Damn Vulnerable ARM Router (DVAR)
- Exploit Education
- Ein Leitfaden zu ARM64 / AArch64 Assembly unter Linux
- ARMv8 AArch64/ARM64 Vollständiges Assembler-Tutorial für Anfänger
- Ein Noobs-Leitfaden zur ARM-Exploitation
- ARM64 Reversing And Exploitation Series (8ksec) - Teile 1-10
- AArch64-Speicher und Paging
- We are ARMed no more ROPpery Here
Binäranalyse
Secure Boot
Entwicklung
Umgehungen
- Pwn the ESP32 Secure Boot
- Pwn ESP32 Forever: Flash-Verschlüsselung und Secure-Boot-Schlüsselextraktion
- ESP32 Secure Boot Bypass (CVE-2020-13629)
- Amlogic S905 SoC: Secure Boot umgehen
- Secure Boot mit Symlink-Angriffen besiegen
- PS4 Secure Boot Hacking - Fail0verflow
- Dell BIOS-Schwachstellen - BIOSDisconnect
- U-Boot USB DFU-Schwachstelle (CVE-2022-2347)
- Secure Boot auf Silicon Labs Gecko knacken
UEFI-Sicherheit
- Verwendung symbolischer Ausführung zur Erkennung von UEFI-Schwachstellen
- HP Enterprise UEFI-Schwachstellen
- UEFI-Firmware emulieren und ausnutzen
- Die dunkle Seite von UEFI: Ein technischer Deep-Dive in Cross-Silicon-Exploitation
- Inside the LogoFAIL PoC: Vom Integer Overflow zur beliebigen Codeausführung
- PixieFail: Neun Schwachstellen im IPv6-Netzwerkstack von Tianocore's EDK II
- For Science! - Einen unspektakulären Bug in EDK II für etwas Spaß-Exploitation nutzen
- Hydroph0bia: SecureBoot-Bypass für Insyde H2O
- PKfail: Nicht vertrauenswürdige Plattformschlüssel in UEFI-Firmware (Binarly, 2024)
- LogoFAIL: Bildparsing-Schwachstellen in System-Firmware (Binarly)
- BlackLotus UEFI-Bootkit-Analyse - ESET
- Bootkitty: Erster UEFI-Bootkit für Linux (ESET, 2024)
- UEFI-Firmware-Rootkits: Mythen und Realität (BlackHat 2024)
- CVE-2024-0762 - PixieFail Followup TPM-Bypass
Symlink-Angriffe
Router-Firmware-Analyse
- Eine Reise in IoT: Komponenten und Ports entdecken
- Eine Reise in IoT: Firmware-Dump und -Analyse
- Eine Reise in IoT: Funkkommunikation
- Eine Reise in IoT: Interne Kommunikation
- Dynamische Analyse von Firmware-Komponenten in IoT-Geräten
- RV130X Firmware-Analyse
- TP-Link Firmware-Entschlüsselung C210 V2 Cloud-Kamera-Bootloader
Router-Exploitation
- Jagd nach unauthentifizierten n-days in Asus-Routern
- MikroTik ins Rampenlicht rücken
- MikroTik RouterOS-Hardware mit CVE-2023-30799 ausnutzen
- Xiaomi WiFi-Router rooten
- Route to Safety: Navigieren durch Router-Fallstricke
- ROPing our way to RCE
- Router von Grund auf ROPen: Tenda Ac8v4
- PwnAgent: Ein One-Click WAN-seitiges RCE in Netgear RAX-Routern
- Puckungfu 2: Eine weitere NETGEAR WAN Command Injection
- Reversing, Discovering, And Exploiting A TP-Link Router Vulnerability - CVE-2024-54887
- Ausnutzung der Zero-Day-Schwachstelle (CVE-2025-9961) im TP-Link AX10-Router
- FiberGateway GR241AG - Vollständige Exploit-Kette
- Blackbox-Fuzzing von IoT-Geräten am Beispiel des Routers TL-WR902AC
- Den TP-Link Tapo C200 Rev.5 rooten
Netgear-Serie
- Netgear Orbi: Einführung, UART-Zugriff, Recon
- Netgear Orbi: Abstürze in der SOAP-API
- Netgear Orbi: NDay-Exploit CVE-2020-27861
- Der letzte Atemzug unserer Netgear RAX30-Bugs
TP-Link-Serie
- TP-Link TDDP Buffer-Overflow-Schwachstelle
- Pwn2Own Tokyo 2020: Den TP-Link AC1750 besiegen
- TP-Link Tapo c200 Kamera unauthentifiziertes RCE (CVE-2021-4045)
Cisco-Serie
- Patch-Diffing eines Cisco RV110W Firmware-Updates - Teil 1
- CVE-2024-20356: Jailbreaking eines Cisco-Geräts, um DOOM auszuführen
- Flashback Connects - Cisco RV340 SSL VPN RCE
Secure-Boot-Umgehungen
- Secure Boot mit Fault Injection umgehen
- Secure Boot auf Google Nest Hub (2. Gen) knacken
- Booting into Breaches: Die Remote-Angriffsflächen von Windows SecureBoot aufspüren
Netzwerk- und Web-Protokolle
MQTT
- Einführung in MQTT
- MQTT-Broker-Sicherheit 101
- Das IoT mit MQTT hacken
- IoT-Sicherheit: RCE im MQTT-Protokoll
- IoXY - MQTT-Intercepting-Proxy
- MQTT-PWN
Grundlagen
Sicherheit und Exploitation
- Sind Smart Homes anfällig für Hacking?
- Penetrationstest des Sesame Smart Door Lock
- Servisnet Tessa - MQTT-Anmeldedaten-Dump (Metasploit)
- Eclipse Mosquitto Unquoted Service Path
Bekannte CVEs
- CVE-2020-13849 - DoS-Schwachstelle (CVSS 7.5)
- CVE-2023-3028 - Unzureichende Authentifizierung (CVSS 9.8)
- CVE-2021-0229 - Ressourcenverbrauch (CVSS 5.3)
- CVE-2019-5432 - Absturz durch fehlerhaftes Paket (CVSS 7.5)
Tools
- Mosquitto - Open-Source-MQTT-Broker
- HiveMQ
- MQTT Explorer
- MQTT Topic ACL Linter - Nur lokale statische Analyse für ungültige, zu breite, doppelte und überlappende MQTT-Topic-Filter-ACL-Regeln; verbindet sich nicht mit einem Broker und ersetzt kein Sicherheitsaudit.
- Nmap MQTT Library
- Sieben beste MQTT-Client-Tools
Anwendungen- Using IoT MQTT for V2V and Connected Cars
- MQTT Hardware Development Projects
- 100,000 Connected Cars with Kubernetes, Kafka, MQTT, TensorFlow
- Authenticating Devices Using MQTT with Auth0
- Deep Learning UDF for MQTT IoT Anomaly Detection
- Guide to MQTT: Hacking a Doorbell
Malware-Forschung
CoAP
Spezifikationen und Sicherheit
Tools - Software
- CoAP NSE (Nmap)
- Copper4Cr - CoAP User-Agent for Chrome
- libcoap CLI Tools
- Scapy CoAP Plugin
- Eclipse Californium (Java)
- Peach Fuzzer
Tools - Hardware
Forschung und Tutorials
mTLS
Tools
| Tool | Verwendung | Link | | ───────────────────────── | ─────────────────────────────────────────────────────────────────────────────────────────────── | ──────────────────────────────────────────────────────────────────────────────────────────────────────── | | mtls-intercept | Reverse Proxy, der dynamisch Client-Zertifikate signiert, um vollständige mTLS-Sitzungen zu MITM'en | github.com/fungaren/mtls-intercept | | mitmproxy | client_certs mit extrahiertem IoT-Gerätezertifikat konfigurieren, um Gerät im mTLS-Handshake zu imitieren | mitmproxy.org | | SSLsplit | Transparenter mTLS-Proxy - extrahiertes Gerätezertifikat weiterleiten, um gegenseitigen Handshake mit Cloud abzuschließen | github.com/droe/sslsplit | | eCapture (eBPF) | OpenSSL/BoringSSL auf Linux-IoT-Gateways vor der Verschlüsselung hooken - entschlüsselt mTLS + TLS 1.3 + PFS | ecapture.cc | | Wireshark + SSLKEYLOGFILE | Aufgezeichnete mTLS-Sitzungen von IoT-Gateways mithilfe von NSS-Pre-Master-Secret-Logs entschlüsseln | wiki.wireshark.org/TLS | | Frida | SSLContext, TrustManager, KeyManager zur Laufzeit in Android-IoT-Begleit-Apps hooken | frida.re | | Objection | Android sslpinning disable - entfernt mTLS-Pinning in Begleit-Apps | github.com/sensepost/objection | | apk-mitm | IoT-Begleit-APK statisch patchen, um mTLS-Zertifikats-Pinning zu deaktivieren | github.com/shroudedcode/apk-mitm | | MagiskTrustUserCerts | Benutzerdefinierte CA in den System-Speicher auf gerootetem Android-POS/Kiosk verschieben, um mTLS-MITM abzuschließen | github.com/NVISOsecurity/MagiskTrustUserCerts | | frida-multiple-unpinning | Universelles Frida-Skript, das auf 20+ mTLS-/Pinning-Muster in gehärteten IoT-Apps abzielt | github.com/httptoolkit/frida-android-unpinning | | NEU-SNS/IoTLS | IMC'21-Forschungs-Repo - SSLKEYLOGFILE-Dateien zur Entschlüsselung von MITM'ten mTLS-Verbindungen über 32 Geräte | github.com/NEU-SNS/IoTLS | | mitmrouter | Linux-basierter IoT-Traffic-Interception-Router - fängt Geräte-TLS auf Netzwerkebene ab | github.com/nmatt0/mitmrouter |
Blogs & Artikel
- mTLS: When Certificate Authentication is Done Wrong
- mTLS Authentication in IoT: Enhancing Security for Connected Devices
- Hands On IoT MitM Part 1 - AWS IoT MQTT + mTLS Interception
- OWASP MASTG-TECH-0012: Bypassing Certificate Pinning in Android IoT Companion Apps
- Theory to Practice: mTLS in Action Part 1
- Configuring mTLS on Mosquitto MQTT Broker
- AWS IoT Docs: X.509 Client Certificates and Fleet Provisioning
- Azure IoT Hub: mTLS X.509 CA Authentication Concept
Forschungsarbeiten
- Evaluation of TLS and mTLS in Internet of Things Systems - MIUN DiVA, 2024
- Atlas: Enabling Cross-Vendor mTLS Authentication for IoT - arXiv 2025
- Lightweight mTLS Authentication for Industrial IoT - PMC/NIH 2023
- Quantum-Enhanced mTLS for IoT Battlefield Networks - IJPSAT
- AI vs. IoT Security: Fingerprinting and Defenses Against TLS Attacks - IEEE Xplore 2025
YouTube
- Intercepting IoT Device Traffic with ARP Poisoning + mitmproxy TLS Intercept
- Using Linux to Intercept IoT Device Traffic with mitmrouter
- Mutual TLS - The Backend Engineering Show Deep Dive
- Intercepting SSL/TLS - Fiddler and MITMProxy Decrypt Walkthrough
- Decrypting Kubernetes mTLS Traffic - eCapture, Custom CA, eBPF Methods
- Mastering mTLS: Stop MITM Attacks and Boost API/IoT Security
- Introduction to IoT Penetration Testing Webinar - CyberWarFare Labs
IoT-Protokolle im Überblick
- IoT Protocols Overview
- IoT Architecture
- Attacking IoT Devices from Web Perspective
- Awesome Industrial Protocols
Cloud- und Backend-Sicherheit
AWS IoT-Sicherheit
Grundlagen
- Comprehensive AWS Pentesting Guide - BreachLock
- AWS Pentest Methodology - MorattiSec
- AWS Penetration Testing Methodology - Rootshell
- AWS Penetration Testing Techniques 2025
Tools
- CloudFox - Cloud Attack Paths
- S3Scanner - Leaky Bucket Discovery
- Cloudfoxable Labs
- AWS Security Pentesting Resources
- Pacu - AWS Exploitation Framework
- ScoutSuite - Multi-cloud Security Auditing
- Prowler - Cloud Security Assessment
Schwachstellen
Firebase / Cloud-Fehlkonfigurationen
Mobile-Anwendungssicherheit
Android
- Android App Reverse Engineering 101
- Android Application Pentesting Book
- Android Pentest Video Course - TutorialsPoint
- Android Tamer
- Android Hacker's Handbook
- A first look at Android 14 forensics
- Deobfuscating Android ARM64 strings with Ghidra
- Introduction to Fuzzing Android Native Components
- Hacking Android Games
- Intercepting HTTPS Communication in Flutter
Android-Kernel-Exploitation
- Android Kernel Exploitation
- Attacking Android Binder: Analysis and Exploitation of CVE-2023-20938
- Attacking the Android kernel using the Qualcomm TrustZone
- Driving forward in Android drivers
- Analyzing a Modern In-the-wild Android Exploit
- Exploiting Android's Hardened Memory Allocator
- GPUAF - Two ways of Rooting All Qualcomm based Android phones
- The Qualcomm DSP Driver - Unexpectedly Excavating an Exploit
- Qualcomm DSP Kernel Internals
- Binder Fuzzing
Android Scudo Allocator
- Android: Scudo
- Behind the Shield: Unmasking Scudo's Defenses
- scudo Hardened Allocator - Unofficial Internals Documentation
iOS
- iOS Pentesting Guide
- OWASP Mobile Security Testing Guide
- An iOS hacker tries Android
- Analyzing iOS Kernel Panic Logs
- Blasting Past iOS 18
- Emulating an iPhone in QEMU
- First analysis of Apple's USB Restricted Mode bypass (CVE-2025-24200)
- Exploring UNIX pipes for iOS kernel exploit primitives
Industrie und Automotive
ICS/SCADA
- ICS Village
- ICS Discord Group
- Controlthings.io Platform
- Applied Cyber Security and the Smart Grid
- Deep Lateral Movement in OT Networks
- Hacking ICS Historians: The Pivot Point from IT to OT
- OPC UA Deep Dive Series - Parts 1-5
- Inside a New OT/IoT Cyberweapon: IOCONTROL
- Attention, High Voltage: Exploring the Attack Surface of the Rockwell Automation PowerMonitor 1000
Automotive-Sicherheit
- Awesome Vehicle Security
- Car Hacking Village
- Jeep Hack
- Subaru Head Unit Jailbreak
- Car Hacking Practical Guide 101
- CAN Injection: keyless car theft
- How I Hacked my Car Series - Parts 1-6
- How I Also Hacked my Car
- Extracting Secure Onboard Communication (SecOC) keys from a 2021 Toyota RAV4 Prime
- Recovering an ECU firmware using disassembler and branches
- Automotive Memory Protection Units: Uncovering Hidden Vulnerabilities
- Web Hackers vs The Auto Industry: Critical Vulnerabilities in Cars (Sam Curry, 2023)
- Hacking Kia: Remotely Controlling Cars With Just a License Plate (Sam Curry, 2024)
- Hacking Subaru: Tracking and Controlling Cars via the STARLINK Admin Panel (Sam Curry, 2025)
- Pwn2Own Automotive (ZDI Blog Category - 2024 & 2025 Tokyo)
- Synacktiv Publications - Pwn2Own Automotive Writeups
- Awesome CAN Bus - Curated Resources
EV-Ladegeräte
- A Detailed Look at Pwn2own Automotive EV Charger Hardware
- Pwn2Own Automotive 2024: Hacking the ChargePoint Home Flex
- Reverse engineering an EV charger
- Pwn2Own Automotive 2024: Autel MaxiCharger Analysis (Computest Sector7)
- SaiFlow Blog - OCPP/EV Charging Protocol Vulnerabilities
Zahlungssysteme
ATM-Hacking
- Introduction to ATM Penetration Testing
- Pwning ATMs for Fun and Profit
- Jackpotting ATMs Redux - Barnaby Jack
- Root Shell on Credit Card Terminal
Payment Village
Tools
Hardware-Tools
- Bus Pirate
- Bus Pirate 5: The Swiss ARRRmy Knife of Hardware Hacking
- The Shikra
- Attify Badge
- Flipper Zero
- HackRF
- RTL-SDR
- An In-Depth Look at the ICE-V Wireless FPGA Development Board
Mehrzweck
Debug-Adapter- ST-Link
USB
- FaceDancer21
- RfCat
- NullSec Ducky Payloads - Rubber Ducky BadUSB-Payload-Sammlung für Windows, macOS und Linux.
Flipper Zero
- NullSec Flipper Suite - Flipper Zero Payload-Sammlung für RF, RFID/NFC, BadUSB, Infrarot und Wireless-Pentesting.
- PineFlip - Flipper Zero Companion-App für Linux mit Screen Mirroring, Dateimanager und Firmware-Verwaltung.
Hak5
- Hak5 Field Kits
- NullSec Pineapple Suite - WiFi Pineapple Payload-Sammlung für Deauth, Evil Twin, Handshake Capture und Netzwerk-Recon.
Software-Tools
Exploitation-Frameworks
- BlueSploit
- IoTSecFuzz
- PENIOT
- ISF - Industrial Security Framework
- HAL - Hardware Analyzer
- PRET - Printer Exploitation Toolkit
- Expliot Framework
- RouterSploit
- HomePwn
- Firmware Analysis Toolkit (FAT)
- Shambles: The Next-Generation IoT Reverse Engineering Tool
Firmware-Analyse
Fuzzing-Tools
- The art of Fuzzing: Introduction
- A LibAFL Introductory Workshop
- The Blitz Tutorial Lab on Fuzzing with AFL++
- State of Linux Snapshot Fuzzing
- Fuzzing between the lines in popular barcode software
- Boofuzz
- Syzkaller - Kernel Fuzzer
- parking-game-fuzzer
Grundlagen
IoT-spezifisches Fuzzing
- Fuzzing ICS Protocols
- Fuzzowski - Network Protocol Fuzzer
- FIRM-AFL: High-Throughput IoT Firmware Fuzzing
- Snipuzz: Black-box Fuzzing of IoT Firmware
- Fuzzing IoT Binaries Part 1
- Fuzzing IoT Binaries Part 2
- Awesome Embedded Fuzzing
Tools
Pentesting-Betriebssysteme
- AttifyOS
- IoT Penetration Testing OS v1
- EmbedOS
- Sigint OS - LTE IMSI Catcher
- Instant GNU Radio OS
- Dragon OS - SDR Software
- Skywave Linux - SDR
- Zephyr RTOS
- Ubuntu LTS
Suchmaschinen
- Shodan
- Censys
- ZoomEye
- BinaryEdge
- Thingful
- Wigle
- Hunter.io
- BuiltWith
- Recon-ng
- PublicWWW
- FCC ID Database
- CVE PoC Search - Durchsuche öffentliche GitHub-PoC-Repositories nach CVE-ID.
Defensive Sicherheit
Threat Modeling
- STRIDE Threat Model Guide - Practical DevSecOps
- OWASP Threat Modeling Process
- STRIDE-based Threat Modeling for IoT Precision Agriculture
STRIDE-Framework
- What is STRIDE in Threat Modeling - Security Compass
- Threat Modeling with ATT&CK - MITRE
- What is Threat Modeling - Fortinet
IoT-spezifisches Threat Modeling
- STRIDE Threat Modeling for IoT Smart Home
- STRIDE Threat Modeling for Smart Solar Energy Systems
- STRIDE Threat Modeling for IoT Healthcare Systems
- STRIDE for IoT Agriculture - IEEE
Sichere Entwicklung
- Compiler Options Hardening Guide for C and C++
- Linux Hardening Guide
- Docker Security - Step-by-Step Hardening
- How To Secure A Linux Server
Richtlinien und Standards
- NIST IoT Cybersecurity Framework
- NIST SP 800-213 - IoT Device Cybersecurity Guidance
- NISTIR 8259 - Foundational Cybersecurity Activities for IoT Manufacturers
- ETSI EN 303 645 - Cyber Security for Consumer IoT
- OWASP IoT Top 10 (2018)
- OWASP IoT Project
Hardening-Leitfäden
Incident Response
Lernressourcen
Trainingsplattformen
Cheatsheets
- Hardware Hacking Cheatsheet
- Nmap Tutorial
- Pentest Hardware Handbook
- THC's favourite Tips, Tricks & Hacks
- Cross Cache Attack CheetSheet
Vulnerability-Guides
- OWASP IoT Top 10 2018 Mapping
- Reflecting on OWASP IoT Top 10
- CVE North Stars
- IoT Vulnerabilities with CVE and PoC
- Linux Privilege Escalation
Pentesting-Guides
- Shodan Pentesting Guide
- Modern Vulnerability Research on Embedded Systems
- Awesome Embedded Systems Vulnerability Research
YouTube-Kanäle
- Joe Grand
- LiveOverflow
- Binary Adventure
- EEVBlog
- Craig Smith
- IoTSecurity101
- Besim ALTINOK
- Ghidra Ninja
- Cyber Gibbons
- Scanline
- Aaron Christophel
- Valerio Di Giampietro
- Gamozo Labs - Printer Hacking
Bücher
Hardware-Hacking
- The Hardware Hacking Handbook - Jasper van Woudenberg & Colin O'Flynn (2021)
- Practical Hardware Pentesting - Jean-Georges Valle (2021)
- Practical Hardware Pentesting 2nd Edition (2023)
- Hardware Hacking: Have Fun While Voiding Your Warranty - Joe Grand (2004)
- Hacking the Xbox - Andrew "bunnie" Huang (2013)
- The Hardware Hacker - Andrew "bunnie" Huang (2019)
- The Art of PCB Reverse Engineering - Keng Tiong (2015)
- Manual PCB-RE: The Essentials - Keng Tiong (2021)
- Hardware Security Training, Hands-on! (2023)
- Hardware Security: Challenges and Solutions (2025)
- Mastering Hardware Hacking (2025)
- Ultimate Hardware Hacking Gear Guide
- Microcontroller Exploits (2024)
- Engineering Secure Devices - Dominik Merli (2024)
- Cryptography and Embedded Systems Security - Hou & Breier (2024)
Firmware und Reverse Engineering
- The Firmware Handbook - Jack Ganssle (2004)
- Learning Linux Binary Analysis - Ryan O'Neill (2016)
- Fuzzing Against the Machine (2023)
- Rootkits and Bootkits - Matrosov, Rodionov, Bratus (2019)
- Ghidra Software Reverse Engineering 2nd Edition (2025)
- The Ghidra Book 2nd Edition - Nance & Eagle (2026)
- The Definitive Handbook on Reverse Engineering Tools (2025)
- x86 Software Reverse-Engineering, Cracking, and Counter-Measures - Domas & Domas (2024)
- Fuzzing Android - Zawawy, Rodionov et al. (2026)
- From Day Zero to Zero Day - Eugene Lim (2025)
- The Spacecraft Hacker's Handbook - Olchawa & Starcik (2026)
IoT-Sicherheit
- Abusing the Internet of Things - Nitesh Dhanjani (2015)
- IoT Penetration Testing Cookbook - Aaron Guzman & Aditya Gupta (2017)
- Practical IoT Hacking: The Definitive Guide (2021)
- PatrIoT: Practical and Agile Threat Research for IoT (2022)
- The Embedded Linux Security Handbook - St. Onge & Krishnan (2025)
- Securing Smart Things - Massimo Nardone (2026)
Wireless und RF
- Inside Radio: An Attack and Defense Guide - Qing Yang, Lin Huang (2018)
- Hack the Airwaves: Advanced BLE Exploitation (2023)
- Practical SDR - David Clark & Paul Clark (2025)
- The Art of ARM Assembly, Volume 1 - Randall Hyde (2025)
- The Wireless Cookbook - Bill Zimmerman (2026)
Embedded und Mobil
NFC/RFID
- Near Field Communication (NFC): From Theory to Practice (2012)
- Security Issues in Mobile NFC Devices - Michael Roland (2024)
Automotive-Sicherheit
- The Car Hacker's Handbook - Craig Smith (2016)
- Building Secure Automotive IoT Applications - Oka et al. (2024)
- Offensive Automotive Cybersecurity - Nasser & Oka (2025)
Industrie- und allgemeine Sicherheit
- Gray Hat Hacking 5th Edition (2018)
- Black Hat Python 2nd Edition (2021)
- Attacking Network Protocols - James Forshaw (2017)
- Securing Industrial Control Systems - Rahman et al. (2026)
White Papers und Berichte
IoT-Serie
Labs und CTFs
Verwundbare Anwendungen
- DVID - Damn Vulnerable IoT Device
- IoTGoat - Vulnerable OpenWrt Firmware
- BLE CTF
- Microcorruption
- ARM-X CTF
Hardware
Industrie
VoIP
CTF-Wettbewerbe
Hardware-CTFs
IoT-CTFs
Embedded/Firmware-CTFs
ARM-CTFs
Kontinuierliche Lernplattformen
Lab-Aufbau
Forschung und Community
Technische Forschung
- Dropcam Hacking
- LED Light Hacking
- PS4 Jailbreak Status
- Lenovo Watch X Privacy Issues
- Smart Scale Privacy Issues
- Besder IP Camera Security Analysis
Blogs- Team82 Research
- Voidstarsec
- wrongbaud
- Firmware Analysis
- Exploitee.rs
- Payatu Blog
- Raelize Blog
- JCJC Dev
- W00tsec
- Devttys0
- Embedded Bits
- Keenlab
- Courk.cc
- IoT Security Wiki
- Cybergibbons
- Firmware.RE
- K3170makan
- Tclaverie
- Besimaltinok
- Ctrlu
- IoT Pentest
- Duo Decipher
- Sp3ctr3
- 0x42424242
- Dantheiotman
- Danman
- Quentinkaiser
- Quarkslab
- Ice9
- F-Secure Labs
- MG.lol
- CJHackerz
- Bunnie's Blog
- Synacktiv Publications
- Cr4.sh
- Ktln2
- Naehrdine
- Limited Results
- Fail0verflow
- Exploit Security
- Attify Blog
- Jilles.com
- Syss Tech Blog
- HardBreak Wiki
- 8ksec
- Starlabs
- boschko.ca
- 0xtriboulet
- Nozomi Networks
Community-Plattformen
Villages
Forscher, denen man folgen sollte
- Jilles
- Joe Fitz
- Aseem Jakhar
- Cybergibbons
- Jasper
- Dave Jones
- bunnie
- Ilya Shaposhnikov
- Mark C.
- Aaron Guzman
- Yashin Mehaboobe
- Arun Magesh
- Mr-IoT
- QKaiser
- 9lyph
Gerätespezifische Forschung
Kameras
- ARLO: I'M WATCHING YOU
- Hacking a Tapo TC60 Camera
- Rooting a Hive Camera
- Pwn2Own: Synology BC500 IP Camera
- Turning Camera Surveillance on its Axis
- Pwn2Own Ireland 2024 - Ubiquiti AI Bullet
Smart-Home-Geräte
- Hacking a Smart Home Device
- The Silent Spy Among Us: Smart Intercom Attacks
- Pwnassistant - Home Assistant RCE
- Hacking Sonoff Smart Home IoT Device
Smart Speaker
- Turning Google smart speakers into wiretaps for $100k
- Smart Speaker Shenanigans: Making the Sonos ONE Sing its Secrets
- Listen Up: Sonos Over-The-Air Remote Kernel Exploitation and Covert Wiretap
- Streaming Zero-Fi Shells to Your Smart Speaker
Drucker
- Pwning a Brother labelmaker, for fun and interop!
- lexmark printer haxx
- Pwn2Own Ireland 2024: Canon imageCLASS MF656Cdw
- Print Scan Hacks: Brother devices
Drohnen
- DJI Mavic 3 Drone Research: Firmware Analysis
- DJI Mavic 3 Drone Research: Vulnerability Analysis
- DJI - The ART of obfuscation
- Local Privilege Escalation on the DJI RM500 Smart Controller
Küchengeräte
NAS-Geräte
- A Pain in the NAS: Synology DS920+ Edition
- Weekend Destroyer - RCE in Western Digital PR4100 NAS
- Exploiting the Synology TC500 at Pwn2Own Ireland 2024
Spielkonsolen
- Hacking the Nintendo DSi Browser
- mast1c0re: Exploiting the PS4 and PS5 through a game save
- Being Overlord on the Steam Deck with 1 Byte
- Hacking the XBox 360 Hypervisor
Telefone/Tablets
- Pixel 6 Bootloader Series
- Solo: A Pixel 6 Pro Story
- Gaining kernel code execution on an MTE-enabled Pixel 8
- Bypassing MTE with CVE-2025-0072
- Debugging the Pixel 8 kernel via KGDB
- A First Glimpse of the Starlink User Terminal
- Diving into Starlink's User Terminal Firmware
TrustZone- und TEE-Forschung
- ARM TrustZone: pivoting to the secure world
- TEE Reversing
- A Deep Dive into Samsung's TrustZone - Parts 1-3
- Researching Xiaomi's TEE
- Kinibi TEE: Trusted Application Exploitation
- Reversing Samsung's H-Arx Hypervisor Framework
- EL3vated Privileges: Glitching Google WiFi Pro from Root to EL3
Pwn2Own-Forschung
- Your not so "Home Office" - SOHO Hacking at Pwn2Own
- Pwn2Own Toronto 2023 Series - Parts 1-5
- Pwn2Own: WAN-to-LAN Exploit Showcase
MCP / KI-Agent
Bluetooth-Reverse-Engineering
- bt-re-mad-skillz - LLM-Skills für Bluetooth-Controller-Firmware-RE auf der HCI-Ebene, für Claude Code und ChatGPT/Codex.
Mitwirken
Beiträge sind willkommen. Reiche einen PR mit neuen Ressourcen ein, der der bestehenden Struktur folgt.