
awesome-connected-things-sec — Updated!
接続されたすべてのモノのための厳選セキュリティリソースリスト
🔐 Awesome Connected Things Security Resources
IoT、組み込み、産業、自動車システムのセキュリティ研究とエクスプロイト手法。
目次
- ハードウェア攻撃
- 無線プロトコル
- ファームウェアセキュリティ
- ネットワークと Web プロトコル
- クラウドとバックエンドセキュリティ
- モバイルアプリケーションセキュリティ
- 産業と自動車
- 決済システム
- ツール
- 防御的セキュリティ
- 学習リソース
- ラボと CTF
- 研究とコミュニティ
- MCP / AI エージェント
ハードウェア攻撃
基礎
- IoT Hardware Guide
- Intro to Hardware Hacking - Dumping Your First Firmware
- An Introduction to Hardware Hacking
- Hardware Toolkits for IoT Security Analysis
- Hardware Hacking for IoT Devices - Offensive IoT Exploitation
インターフェース攻撃
UART
- Identifying UART Interface
- Serial Terminal Basics
- Reverse Engineering Serial Ports
- Intro to Embedded RE: UART Discovery and Firmware Extraction via UBoot
- Using UART to Connect to a Chinese IP Cam
- A Journey into IoT Hardware Hacking: UART
- Accessing and Dumping Firmware Through UART
- UART Connections and Dynamic Analysis on Linksys e1000
JTAG
- Hardware Hacking 101: Introduction to JTAG
- How to Find the JTAG Interface
- Analyzing JTAG
- Bus Pirate JTAG Connections with OpenOCD
- Extracting Firmware from External Memory via JTAG
- The Hitchhacker's Guide to iPhone Lightning and JTAG Hacking
- Debugging AVR Microcontrollers Through JTAG
SWD (Serial Wire Debug)
- SWD Protocol Overview - HardBreak Wiki
- Unveiling Vulnerabilities: Exploring SWD Attack Surface in Hardware
- Introduction to ARM Serial Wire Debug Protocol
- Serial Wire Debug and CoreSight Architecture
- LibSWD - Serial Wire Debug Open Library
- Hardware Hacking and Exploitation Bootcamp - SWD
SPI
- Hardware Hacking 101: Identifying and Dumping eMMC Flash
- Dumping Firmware from Router Using Bus Pirate - SPI
- Extracting Flash Memory over SPI
- Extracting Firmware from Embedded Devices (SPI NOR Flash)
- How to Flash Chip of a Router with a Programmer
- TPM 2.0: Extracting Bitlocker Keys Through SPI
I2C
- IoT Security Part 16: Hardware Attack Surface I2C
- I2C Exploitation - HackTricks
- Non-invasive I2C Hardware Trojan Attack Vector (PDF)
- Hardware Hacking: I2C Injection with Bus Pirate
- Safeguarding SPI, I2C, and I3C Protocols
TPM
- Introduction to TPM (Trusted Platform Module)
- Trusted Platform Module Security Defeated in 30 Minutes
メモリ抽出
eMMC
- eMMC Protocol
- RPMB: A Secret Place Inside the eMMC
- eMMC Data Recovery from Damaged Smartphone
- Unleash Your Smart-Home Devices: Vacuum Cleaning Robot Hacking
- Hands-On IoT Hacking: Rapid7 at DEF CON 30
サイドチャネルとフォールトインジェクション
基礎
- Side Channel Attacks - Yifan Lu
- Attacks on Implementations of Secure Systems
- Fuzzing, Binary Analysis, IoT Security Collection
グリッチ攻撃
- NAND Glitching Attack on Wink Hub
- Voltage Glitching with Crowbars Tutorial
- Voltage Glitching Attack using iCEstick Glitcher
- FPGA Glitching and Side Channel Attacks - Samy Kamkar
- Hardware Power Glitch Attack - rhme2
- Keys in Flash - Glitching AES Keys from Arduino
- Implementing Practical Electrical Glitching Attacks
- How to Voltage Fault Injection
- Glitcher Part 1 - Reproducible Voltage Glitching on STM32 Microcontrollers
- STM32L05 Voltage Glitching
電力解析
その他のマイクロコントローラ
- Dumping the Amlogic A113X Bootrom
- Retreading The AMLogic A113X TrustZone Exploit Process
- Reverse Engineering an Unknown Microcontroller
- Hacking Microcontroller Firmware Through a USB
- There's A Hole In Your SoC: Glitching The MediaTek BootROM
PCIe と DMA 攻撃
- A Practical Tutorial on PCIe for Total Beginners on Windows - Part 1
- A Practical Tutorial on PCIe for Total Beginners on Windows - Part 2
- PCIe DMA Attack against a Secured Jetson Nano (CVE-2022-21819)
無線プロトコル
RF の基礎
- Complete Course in Software Defined Radio - Michael Ossmann
- Understanding Radio
- Introduction to Software Defined Radio
- Introduction to GNU Radio Companion
- Creating a Flow Graph in GNU Radio Companion
- Analyzing Radio Signals 433MHz
- Recording Specific Radio Signals
- Replay Attacks with Raspberry Pi and rpitx
- Reverse Engineering a Car Key Fob Signal
- GRCON 2021 - Capture the Signal
Bluetooth / BLE
基礎
- Awesome Bluetooth Security
- Traffic Engineering in a Bluetooth Piconet
- BLE Characteristics: A Beginner's Tutorial
- Intro to Bluetooth Low Energy (PDF)
- Bluetooth LE Security Study Guide
- Reverse Engineering BLE Devices
- My Journey Towards Reverse Engineering a Smart Band - Bluetooth-LE RE
エクスプロイト手法- Intel Edison as Bluetooth LE Exploit Box
- Reverse Engineering and Exploiting a Smart Massager
- I Hacked MiBand 3
- GATTacking Bluetooth Smart Devices
- Examining the August Smart Lock
- Practical Introduction to BLE GATT Reverse Engineering
- MojoBox - Yet Another Not So Smartlock
- Bluetooth Smartlocks
- Bluetooth Beacon Vulnerability
- Denial of Pleasure: Attacking Unusual BLE Targets with a Flipper Zero
- Grand Theft Auto: A peek of BLE relay attack
- How I Hacked Smart Lights: CVE-2022-47758
脆弱性リサーチ
- Finding Bugs in Bluetooth
- Sweyntooth Vulnerabilities
- BrakTooth: Causing Havoc on Bluetooth Link Manager
- BLUFFS: Bluetooth Forward and Future Secrecy Attacks (CVE-2023-24023)
- AirDrop Leak - Sniffing BLE Traffic from Apple Devices
- BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution
- BRAKTOOTH: Causing Havoc on Bluetooth Link Manager (PDF)
- Norec Attack: Stripping BLE encryption from Nordic's Library (CVE-2020-15509)
- BlueDucky - HID Injection on Unpatched Android (CVE-2023-45866)
- Microsoft Bluetooth Driver Spoofing - CVE-2024-21306
- Bluetooth Auracast / LE Audio Security Analysis
カンファレンス講演
- Blue2thprinting: WTF Am I Even Looking At?
- Open Wounds: Last 5 Years Have Left Bluetooth to Bleed
- Sniffing Bluetooth Through My Mask During the Pandemic
ツール - ソフトウェア
- Bluing - Intelligence Gathering for Bluetooth
- BlueToolkit - Bluetooth Classic Vulnerability Testing
- btproxy
- hcitool and bluez
- Testing with GATT Tool
- crackle - Cracking BLE Encryption
- bettercap
- GATTacker
- BTLEjack - BLE Swiss Army Knife
- DEDSEC Bluetooth Exploit
- BrakTooth ESP32 PoC
- SweynTooth BLE Attacks
- ESP32 Bluetooth Classic Sniffer
- Bluetooth Hacking Collection
ツール - ハードウェア
ツール
Bluetooth コーヒーマシンのハッキング
- Hacking Bluetooth to Brew Coffee from GitHub Actions - Part 1
- Hacking Bluetooth to Brew Coffee from GitHub Actions - Part 2
- Hacking Bluetooth to Brew Coffee from GitHub Actions - Part 3
Zigbee / Z-Wave
基礎
エクスプロイト
- Hacking IoT Devices with Attify Zigbee Framework
- Zigator: Analyzing Security of Zigbee-Enabled Smart Homes
- Security Analysis of Zigbee with Zigator and GNU Radio
- Low-Cost ZigBee Selective Jamming
ツール - ソフトウェア
ツール - ハードウェア
LoRa / LoRaWAN
- LoRaWAN Security Overview - Tektelic
- Security Vulnerabilities in LoRaWAN
- Low Powered and High Risk: Attacks on LoRaWAN Devices
- LAF - LoRaWAN Auditing Framework
- ChirpOTLE - LoRaWAN Security Framework
基礎
エクスプロイト
- Millions of Devices Using LoRaWAN Exposed - SecurityWeek
- Do You Blindly Trust LoRaWAN Networks? - IOActive
- LoRaWAN Encryption Keys Easy to Crack - Threatpost
- LoPT: LoRa Penetration Testing Tool (PDF)
ツール
Matter / Thread
基礎
- Matter Standard - CSA-IoT
- Matter Protocol Wikipedia
- Matter Protocol Complete Guide 2025
- How to Secure Smart Home Devices with Matter
- Smart Home Device Solutions for Matter - DigiCert
セキュリティリサーチ
- Security Vulnerabilities and Attack Scenarios in Smart Home with Matter
- Trust Matters: Uncovering Vulnerabilities in Matter Protocol - Nozomi
- Matter over Thread Security
- State-of-the-Art Review on IoT Wireless PAN Protocol Security
- Matter Smart Home - Krasamo
- Threadbare: Practical Attacks on Thread Networks (Black Hat USA 2024)
- Matter Specification 1.3 - Connectivity Standards Alliance
- Thread Group Security Analysis
セルラー (GSM/LTE/5G)
- Awesome Cellular Hacking
- Introduction to GSM Security
- Breaking LTE on Layer Two
- 5Ghoul - 5G NR Attacks and Fuzzing
- Exploiting CSN.1 Bugs in MediaTek Basebands
- SIM Hijacking
- SigPloit - Telecom Signaling Exploitation Framework
- LTE Sniffer
- 5G NR Jamming, Spoofing and Sniffing
- LTrack: Stealthy Tracking of Mobile Phones in LTE
- Open5GS - Open Source 5G/4G Core
- SCAT - Signaling Collection and Analysis Tool for Cellular
基礎
- GSM Security Part 2
- What is Base Transceiver Station
- Introduction to SS7 Signaling
- SS7 Network Architecture
- Introduction to SIGTRAN
エクスプロイト
- How to Build Your Own Rogue GSM BTS
- GSM Vulnerabilities with USRP B200
- Security Testing 4G (LTE) Networks
- Case Study of SS7/SIGTRAN Assessment
ツール
NFC/RFID
- Awesome RFID/NFC Security Talks
- RFID Discord Group
- SoK: Security of EMV Contactless Payment Systems
- NFC Relay Attack on Tesla Model Y
DECT (Digital Enhanced Cordless Telecommunications)
- Real Time Interception of DECT Cordless Telephone
- Eavesdropping on Unencrypted DECT Voice Traffic
- Decoding DECT Voice Traffic: In-depth Explanation
Wi-Fi
プロトコル脆弱性
- Framing Frames: Bypassing Wi-Fi Encryption by Manipulating Transmit Queues
- Man-in-the-Middle Attacks without Rogue AP: When WPAs Meet ICMP Redirects
- WPAxFuzz: Sniffing Out Vulnerabilities in Wi-Fi Implementations
- Untangling the Knot: Breaking Access Control in Home Wireless Mesh Networks
エクスプロイト
- Over The Air: Exploiting Broadcom's Wi-Fi Stack (Part 1)
- Over The Air: Exploiting Broadcom's Wi-Fi Stack (Part 2)
- Over The Air: Exploiting The Wi-Fi Stack on Apple Devices
- Reverse-engineering Broadcom wireless chipsets
- Exploiting Qualcomm WLAN and Modem Over the Air
- Windows Wi-Fi Driver RCE Vulnerability - CVE-2024-30078
- When a Wi-Fi SSID Gives You Root on an MT02 Repeater - Part 1
- When a Wi-Fi SSID Gives You Root on an MT02 Repeater - Part 2
WiFi のリバースエンジニアリング
- Reverse Engineering WiFi on RISC-V BL602
- Unveiling secrets of the ESP32: creating an open-source MAC Layer
- Unveiling secrets of the ESP32: reverse engineering RX
USB
UWB (Ultra-Wideband)
TETRA
- All cops are broadcasting: TETRA under scrutiny
- TETRA:BURST - Five Vulnerabilities in TETRA Standard (Midnight Blue)
- TETRA:BURST 2:ELECTRIC BOOGALOO - End-to-End Encryption Broken (BlackHat USA 2025)
- TETRA Decoder - Open Source TETRA Receiver
- Practical TETRA Sniffing with SDR
ファームウェアセキュリティ
基礎
- Introduction to Firmware Analysis - OWASP
- OWASP Firmware Security Testing Methodology
- IoT Security Verification Standard (ISVS)
- Reversing 101
- Hands-on Firmware Extraction, Exploration, and Emulation
抽出
- Router Analysis Part 1: UART Discovery and SPI Flash Extraction
- Hardware Hacking Tutorial: Dumping and Reversing Firmware
- Firmware Samples - firmware.center
- BasicFUN Series: Hardware Analysis / SPI Flash Extraction
- BasicFUN Series: Reverse Engineering Firmware / Reflashing SPI Flash
- Retrofitting encrypted firmware is a Bad Idea
静的解析ツール
- EMBA - Embedded Linux Firmware Analyzer
- FACT - Firmware Analysis and Comparison Tool
- Binwalk v3
- Firmwalker
- fwanalyzer
- fwhunt-scan - UEFI Firmware Analysis
- ByteSweep
- BINSEC
- unblob - Extraction Framework
- Checksec.sh
- Firmware Modification Kit
動的解析とエミュレーション
- Firmadyne - Automated Firmware Emulation
- FirmAE - Firmware Analysis and Emulation
- QEMU
- PANDA - Architecture-Neutral Dynamic Analysis
- Avatar2 - Dynamic Firmware Analysis
- Renode - Embedded Systems Emulator
- Unicorn Engine - CPU Emulator
- Qiling Framework
- HALucinator
- FirmWire - Baseband Firmware Emulation
- SymQEMU
- S2E - Selective Symbolic Execution
- Bochs - x86 Emulator
- SAME70 Emulator
- Emulate Until You Make it
エミュレーションチュートリアル- QEMUによるファームウェアエミュレーション
- ARMルーターファームウェアのエミュレーション - Azeria Labs
- IoTファームウェアのエミュレーションを簡単に
- IoTバイナリ解析とエミュレーション Part 1
- QEMUを使用したARM/MIPSのクロスデバッグ
- QEMU + Buildroot 101
- Qilingによるファームウェア脆弱性のシミュレーションとハンティング
- Qilingと自動アンパックのためのバイナリエミュレーション
- D-Linkのデバッグ: ファームウェアのエミュレーションとハードウェアハッキング
- マルチアーキテクチャIoT向け適応型エミュレーションフレームワーク
- 無効性誘導知識推論による自動ファームウェアエミュレーション
- Unicorn EngineによるRH850アーキテクチャのエミュレーション
- Icicle: グレーボックスファームウェアファジング向けに再設計されたエミュレータ
- 現行のアイスランド家庭用ルーター6機種をエミュレートする際の課題と落とし穴
- 私のエミュレーションは月へ行く... 偽旗まで
- Qilingを使用してAndroidネイティブライブラリをエミュレートする方法
OTAアップデートセキュリティ
基礎
- IoTファームウェアのセキュリティとアップデートメカニズム
- IoTデバイス向けOTAアップデートの実装
- セキュアOTAブートチェーンとファームウェア検証
- コネクテッドIoTデバイスにおけるファームウェアセキュリティの鍵
- OTAアップデートのセキュリティ考慮事項 - Stack Overflow
攻撃ベクトル
RTOSセキュリティ
Zephyr RTOS
- Zephyr RTOS GitHub
- Zephyr脆弱性リスト
- NCC GroupによるZephyrとMCUbootのセキュリティ評価
- ZephyrとMCUbootの26件の欠陥
- Zephyr RTOSにおけるセキュリティへの取り組み
- Zephyr RTOSによるセキュリティ強化
FreeRTOS
- FreeRTOSのTCP/IPスタックにおける13件の脆弱性
- FreeRTOSにおけるメモリ破壊の悪用 - ShmooCon
- RTOSセキュリティ分析 - USENIX
- RTOS向け動的脆弱性パッチ適用
- AWS FreeRTOSの脆弱性
リバースエンジニアリングツール
- Ghidra
- IDA Pro
- Radare2
- Cutter - Radare2のGUI
- Binary Ninja
- GDB
- RetDec - デコンパイラ
- Diaphora - バイナリ差分解析
- Angr - バイナリ解析
- Frida - 動的インストルメンテーション
- Ret-sync
- OllyDbg
- x64dbg
- Hopper
- Immunity Debugger
- PEiD
- Ghidriff - Ghidraバイナリ差分解析エンジン
- rev.ngデコンパイラがオープンソース化
- Cutter入門
- pyghidra-mcp: ヘッドレスGhidra MCPサーバー
- Mindshare: Binary Ninja APIを使用した潜在的なuse-after-free脆弱性の検出
リバースエンジニアリングチュートリアル
- Ghidraによるリバースエンジニアリングとパッチ適用
- Ghidraによるリバースエンジニアリング: ファームウェア暗号化の突破
- Radareによるファームウェアのリバース
- ESP8266ファームウェアのリバース
- GhidraとSemgrepによるバイナリ脆弱性発見の自動化
- Netgearルーターのバグ発見
Ghidraチュートリアル
- デバッガー Ghidraクラス
- Ghidra 101: カーソルテキストのハイライト
- Ghidra 101: スタック文字列のデコード
- Ghidraの拡張 Part 1: 開発環境のセットアップ
- ドラゴンを拡張する: GhidraへのISA追加
- Ghidra nanoMIPS ISAモジュール
- Ghidraにおけるバイナリ型推論
- Ghidraプロセッサモジュールの作成
オンラインアセンブラ
ARMエクスプロイト
- Azeria Labs ARMチュートリアル
- IoT向けARMエクスプロイト
- Damn Vulnerable ARM Router (DVAR)
- Exploit Education
- LinuxにおけるARM64 / AArch64アセンブリガイド
- ARMv8 AArch64/ARM64 完全初心者向けアセンブリチュートリアル
- ARMエクスプロイトの初心者ガイド
- ARM64リバース&エクスプロイトシリーズ (8ksec) - Part 1-10
- AArch64のメモリとページング
- We are ARMed no more ROPpery Here
バイナリ解析
セキュアブート
開発
バイパス
- ESP32セキュアブートを攻略する
- Pwn ESP32 Forever: フラッシュ暗号化とセキュアブートキーの抽出
- ESP32セキュアブートバイパス (CVE-2020-13629)
- Amlogic S905 SoC: セキュアブートのバイパス
- シンボリックリンク攻撃によるセキュアブートの突破
- PS4セキュアブートハッキング - Fail0verflow
- Dell BIOSの脆弱性 - BIOSDisconnect
- U-Boot USB DFU脆弱性 (CVE-2022-2347)
- Silicon Labs Geckoにおけるセキュアブートの突破
UEFIセキュリティ
- シンボリック実行を使用したUEFI脆弱性の検出
- HP Enterprise UEFIの脆弱性
- UEFIファームウェアのエミュレーションと悪用
- UEFIのダークサイド: クロスシリコンエクスプロイトの技術的深掘り
- LogoFAIL PoCの内部: 整数オーバーフローから任意コード実行まで
- PixieFail: TianocoreのEDK II IPv6ネットワークスタックにおける9件の脆弱性
- For Science! - EDK IIの地味なバグを使って
- Hydroph0bia: Insyde H2OのSecureBootバイパス
- PKfail: UEFIファームウェアにおける信頼されていないプラットフォームキー (Binarly, 2024)
- LogoFAIL: システムファームウェアにおける画像解析の脆弱性 (Binarly)
- BlackLotus UEFIブートキット解析 - ESET
- Bootkitty: Linux向け初のUEFIブートキット (ESET, 2024)
- UEFIファームウェアルートキット: 神話と現実 (BlackHat 2024)
- CVE-2024-0762 - PixieFailフォローアップ TPMバイパス
シンボリックリンク攻撃
ルーターファームウェア解析
- IoTへの旅: コンポーネントとポートの発見
- IoTへの旅: ファームウェアダンプと解析
- IoTへの旅: 無線通信
- IoTへの旅: 内部通信
- IoTデバイスにおけるファームウェアコンポーネントの動的解析
- RV130Xファームウェア解析
- TP-Linkファームウェアの復号 C210 V2クラウドカメラのブートローダー
ルーターエクスプロイト
- Asusルーターにおける未認証n-dayのハンティング
- MikroTikを脚光へ
- CVE-2023-30799によるMikroTik RouterOSハードウェアの悪用
- Xiaomi WiFiルーターのルート化
- 安全への道: ルーターの落とし穴をナビゲートする
- ROPでRCEへの道を切り開く
- ゼロから始めるルーターROP: Tenda Ac8v4
- PwnAgent: Netgear RAXルーターにおけるワンクリックWAN側RCE
- Puckungfu 2: もう一つのNETGEAR WANコマンドインジェクション
- TP-Linkルーター脆弱性のリバース、発見、悪用 - CVE-2024-54887
- TP-Link AX10ルーターにおけるゼロデイ (CVE-2025-9961) 脆弱性の悪用
- FiberGateway GR241AG - 完全エクスプロイトチェーン
- ルーターTL-WR902ACを使用したIoTデバイスのブラックボックスファジング
- TP-Link Tapo C200 Rev.5のルート化
Netgearシリーズ
- Netgear Orbi: イントロダクション、UARTアクセス、偵察
- Netgear Orbi: SOAP-APIにおけるクラッシュ
- Netgear Orbi: NDayエクスプロイト CVE-2020-27861
- Netgear RAX30バグの最後の息吹
TP-Linkシリーズ
- TP-Link TDDPバッファオーバーフロー脆弱性
- Pwn2Own Tokyo 2020: TP-Link AC1750の攻略
- TP-Link Tapo c200カメラの未認証RCE (CVE-2021-4045)
Ciscoシリーズ
- Cisco RV110Wファームウェアアップデートのパッチ差分解析 - Part 1
- CVE-2024-20356: Ciscoアプライアンスを脱獄してDOOMを実行する
- Flashback Connects - Cisco RV340 SSL VPN RCE
セキュアブートバイパス
- フォルトインジェクションを使用したセキュアブートのバイパス
- Google Nest Hub (第2世代) におけるセキュアブートの突破
- 侵害への起動: Windows SecureBootのリモート攻撃対象面のハンティング
ネットワークとWebプロトコル
MQTT
基礎
セキュリティと悪用
- スマートホームはハッキングに対して脆弱か?
- Sesameスマートドアロックのペネトレーションテスト
- Servisnet Tessa - MQTT認証情報ダンプ (Metasploit)
- Eclipse Mosquitto 引用符なしサービスパス
既知のCVE
- CVE-2020-13849 - DoS脆弱性 (CVSS 7.5)
- CVE-2023-3028 - 不十分な認証 (CVSS 9.8)
- CVE-2021-0229 - リソース消費 (CVSS 5.3)
- CVE-2019-5432 - 不正なパケットによるクラッシュ (CVSS 7.5)
ツール
- Mosquitto - オープンソースMQTTブローカー
- HiveMQ
- MQTT Explorer
- MQTT Topic ACL Linter - 無効、広範、重複、および重複するMQTTトピックフィルターACLルールに対するローカル専用の静的解析。ブローカーに接続したり、セキュリティ監査を代替するものではありません。
- Nmap MQTTライブラリ
- ベストMQTTクライアントツール7選
アプリケーション- IoT MQTTをV2Vおよびコネクテッドカーに使用する
- MQTTハードウェア開発プロジェクト
- Kubernetes、Kafka、MQTT、TensorFlowによる10万台のコネクテッドカー
- Auth0を使用したMQTTによるデバイス認証
- MQTT IoT異常検知のためのディープラーニングUDF
- MQTTガイド: ドアベルをハッキングする
マルウェアリサーチ
CoAP
仕様とセキュリティ
ツール - ソフトウェア
- CoAP NSE (Nmap)
- Copper4Cr - Chrome用CoAPユーザーエージェント
- libcoap CLIツール
- Scapy CoAPプラグイン
- Eclipse Californium (Java)
- Peach Fuzzer
ツール - ハードウェア
リサーチとチュートリアル
mTLS
ツール
| ツール | 用途 | リンク | | ───────────────────────── | ─────────────────────────────────────────────────────────────────────────────────────────────── | ──────────────────────────────────────────────────────────────────────────────────────────────────────── | | mtls-intercept | クライアント証明書に動的に署名し、完全なmTLSセッションをMITMするリバースプロキシ | github.com/fungaren/mtls-intercept | | mitmproxy | 抽出したIoTデバイス証明書でclient_certsを設定し、mTLSハンドシェイクでデバイスを偽装する | mitmproxy.org | | SSLsplit | 透過的mTLSプロキシ - 抽出したデバイス証明書を転送し、クラウドとの相互ハンドシェイクを完了する | github.com/droe/sslsplit | | eCapture (eBPF) | Linux IoTゲートウェイ上のOpenSSL/BoringSSLを暗号化前にフック - mTLS + TLS 1.3 + PFSを復号する | ecapture.cc | | Wireshark + SSLKEYLOGFILE | NSS pre-master secretログを使用して、IoTゲートウェイからキャプチャしたmTLSセッションを復号する | wiki.wireshark.org/TLS | | Frida | Android IoTコンパニオンアプリのSSLContext、TrustManager、KeyManagerを実行時にフックする | frida.re | | Objection | Android sslpinning disable - コンパニオンアプリのmTLSピンニングを解除する | github.com/sensepost/objection | | apk-mitm | IoTコンパニオンAPKを静的にパッチし、mTLS証明書ピンニングを無効化する | github.com/shroudedcode/apk-mitm | | MagiskTrustUserCerts | ルート化されたAndroid POS/キオスクでカスタムCAをシステムストアに移動し、mTLS MITMを完了する | github.com/NVISOsecurity/MagiskTrustUserCerts | | frida-multiple-unpinning | 堅牢化されたIoTアプリの20以上のmTLS/ピンニングパターンを対象とする汎用Fridaスクリプト | github.com/httptoolkit/frida-android-unpinning | | NEU-SNS/IoTLS | IMC'21研究リポジトリ - 32デバイスにわたるMITMされたmTLS接続を復号するSSLKEYLOGFILEファイル | github.com/NEU-SNS/IoTLS | | mitmrouter | LinuxベースのIoTトラフィック傍受ルーター - ネットワークレベルでデバイスTLSを傍受する | github.com/nmatt0/mitmrouter |
ブログと記事
- mTLS: 証明書認証が誤って実装される場合
- IoTにおけるmTLS認証: コネクテッドデバイスのセキュリティ強化
- ハンズオンIoT MitM パート1 - AWS IoT MQTT + mTLS傍受
- OWASP MASTG-TECH-0012: Android IoTコンパニオンアプリにおける証明書ピンニングのバイパス
- 理論から実践へ: mTLSの実践 パート1
- Mosquitto MQTTブローカーでのmTLS設定
- AWS IoTドキュメント: X.509クライアント証明書とフリートプロビジョニング
- Azure IoT Hub: mTLS X.509 CA認証の概念
研究論文
- モノのインターネットシステムにおけるTLSとmTLSの評価 - MIUN DiVA, 2024
- Atlas: IoT向けクロスベンダーmTLS認証の実現 - arXiv 2025
- 産業用IoT向け軽量mTLS認証 - PMC/NIH 2023
- IoT戦場ネットワーク向け量子強化mTLS - IJPSAT
- AI対IoTセキュリティ: TLS攻撃に対するフィンガープリンティングと防御 - IEEE Xplore 2025
YouTube
- ARPポイズニング + mitmproxy TLS傍受によるIoTデバイストラフィックの傍受
- Linuxを使用したmitmrouterによるIoTデバイストラフィックの傍受
- 相互TLS - バックエンドエンジニアリングショー ディープダイブ
- SSL/TLSの傍受 - FiddlerとMITMProxyによる復号ウォークスルー
- Kubernetes mTLSトラフィックの復号 - eCapture、カスタムCA、eBPF手法
- mTLSのマスタリング: MITM攻撃を阻止しAPI/IoTセキュリティを強化する
- IoTペネトレーションテスト入門ウェビナー - CyberWarFare Labs
IoTプロトコル概要
クラウドとバックエンドのセキュリティ
AWS IoTセキュリティ
基礎
- 包括的なAWSペンテストガイド - BreachLock
- AWSペンテスト方法論 - MorattiSec
- AWSペネトレーションテスト方法論 - Rootshell
- AWSペネトレーションテスト技術 2025
ツール
- CloudFox - クラウド攻撃パス
- S3Scanner - 漏洩バケットの発見
- Cloudfoxable Labs
- AWSセキュリティペンテストリソース
- Pacu - AWSエクスプロイトフレームワーク
- ScoutSuite - マルチクラウドセキュリティ監査
- Prowler - クラウドセキュリティ評価
脆弱性
Firebase / クラウドの設定ミス
モバイルアプリケーションセキュリティ
Android
- Androidアプリリバースエンジニアリング101
- Androidアプリケーションペネトレーションテストブック
- Androidペンテストビデオコース - TutorialsPoint
- Android Tamer
- Android Hacker's Handbook
- Android 14フォレンジックの第一印象
- GhidraによるAndroid ARM64文字列の難読化解除
- Androidネイティブコンポーネントのファジング入門
- Androidゲームのハッキング
- FlutterにおけるHTTPS通信の傍受
Androidカーネルエクスプロイト
- Androidカーネルエクスプロイト
- Android Binderへの攻撃: CVE-2023-20938の分析とエクスプロイト
- Qualcomm TrustZoneを使用したAndroidカーネルへの攻撃
- Androidドライバーを前進させる
- 現代の実環境Androidエクスプロイトの分析
- Androidの堅牢化されたメモリアロケータのエクスプロイト
- GPUAF - すべてのQualcommベースAndroidスマートフォンをルート化する2つの方法
- Qualcomm DSPドライバー - 予期せぬエクスプロイトの発掘
- Qualcomm DSPカーネル内部
- Binderファジング
Android Scudoアロケータ
iOS
- iOSペンテストガイド
- OWASPモバイルセキュリティテストガイド
- iOSハッカーがAndroidを試す
- iOSカーネルパニックログの分析
- iOS 18を打ち破る
- QEMUでiPhoneをエミュレートする
- AppleのUSB Restricted Modeバイパス (CVE-2025-24200) の最初の分析
- iOSカーネルエクスプロイトプリミティブのためのUNIXパイプの探求
産業と自動車
ICS/SCADA
- ICS Village
- ICS Discordグループ
- Controlthings.ioプラットフォーム
- 応用サイバーセキュリティとスマートグリッド
- OTネットワークにおける深いラテラルムーブメント
- ICSヒストリアンのハッキング: ITからOTへのピボットポイント
- OPC UAディープダイブシリーズ - パート1〜5
- 新しいOT/IoTサイバーウェポンの内部: IOCONTROL
- 注意、高電圧: Rockwell Automation PowerMonitor 1000の攻撃対象領域の探求
自動車セキュリティ
- Awesome車両セキュリティ
- Car Hacking Village
- Jeepハック
- Subaruヘッドユニットのジェイルブレイク
- カーハッキング実践ガイド101
- CANインジェクション: キーレス車両盗難
- 私が車をハッキングした方法シリーズ - パート1〜6
- 私も車をハッキングした方法
- 2021年型Toyota RAV4 PrimeからSecure Onboard Communication (SecOC) キーを抽出する
- 逆アセンブラと分岐を使用したECUファームウェアの復元
- 自動車メモリ保護ユニット: 隠れた脆弱性を暴く
- Webハッカー対自動車業界: 自動車における重大な脆弱性 (Sam Curry, 2023)
- Kiaのハッキング: ナンバープレートだけで車を遠隔操作する (Sam Curry, 2024)
- Subaruのハッキング: STARLINK管理パネルを介した車両の追跡と制御 (Sam Curry, 2025)
- Pwn2Own Automotive (ZDIブログカテゴリ - 2024 & 2025 東京)
- Synacktiv出版物 - Pwn2Own Automotive Writeup
- Awesome CAN Bus - キュレーションされたリソース
EV充電器
- Pwn2own Automotive EV充電器ハードウェアの詳細
- Pwn2Own Automotive 2024: ChargePoint Home Flexのハッキング
- EV充電器のリバースエンジニアリング
- Pwn2Own Automotive 2024: Autel MaxiCharger分析 (Computest Sector7)
- SaiFlowブログ - OCPP/EV充電プロトコルの脆弱性
決済システム
ATMハッキング
Payment Village
ツール
ハードウェアツール
- Bus Pirate
- Bus Pirate 5: ハードウェアハッキングのスイスアーミーナイフ
- The Shikra
- Attify Badge
- Flipper Zero
- HackRF
- RTL-SDR
- ICE-V Wireless FPGA開発ボードの詳細
多目的
デバッグアダプタ- ST-Link
USB
- FaceDancer21
- RfCat
- NullSec Ducky Payloads - Windows、macOS、Linux向けのRubber Ducky BadUSBペイロードコレクション。
Flipper Zero
- NullSec Flipper Suite - RF、RFID/NFC、BadUSB、赤外線、ワイヤレスペネトレーションテスト向けのFlipper Zeroペイロードコレクション。
- PineFlip - 画面ミラーリング、ファイルマネージャー、ファームウェア管理を備えたLinux用Flipper Zeroコンパニオンアプリ。
Hak5
- Hak5 Field Kits
- NullSec Pineapple Suite - deauth、evil twin、ハンドシェイクキャプチャ、ネットワーク偵察向けのWiFi Pineappleペイロードコレクション。
ソフトウェアツール
エクスプロイトフレームワーク
- BlueSploit
- IoTSecFuzz
- PENIOT
- ISF - Industrial Security Framework
- HAL - Hardware Analyzer
- PRET - Printer Exploitation Toolkit
- Expliot Framework
- RouterSploit
- HomePwn
- Firmware Analysis Toolkit (FAT)
- Shambles: The Next-Generation IoT Reverse Engineering Tool
ファームウェア解析
ファジングツール
- The art of Fuzzing: Introduction
- A LibAFL Introductory Workshop
- The Blitz Tutorial Lab on Fuzzing with AFL++
- State of Linux Snapshot Fuzzing
- Fuzzing between the lines in popular barcode software
- Boofuzz
- Syzkaller - Kernel Fuzzer
- parking-game-fuzzer
基礎
IoT固有のファジング
- Fuzzing ICS Protocols
- Fuzzowski - Network Protocol Fuzzer
- FIRM-AFL: High-Throughput IoT Firmware Fuzzing
- Snipuzz: Black-box Fuzzing of IoT Firmware
- Fuzzing IoT Binaries Part 1
- Fuzzing IoT Binaries Part 2
- Awesome Embedded Fuzzing
ツール
ペネトレーションテスト用OS
- AttifyOS
- IoT Penetration Testing OS v1
- EmbedOS
- Sigint OS - LTE IMSI Catcher
- Instant GNU Radio OS
- Dragon OS - SDR Software
- Skywave Linux - SDR
- Zephyr RTOS
- Ubuntu LTS
検索エンジン
- Shodan
- Censys
- ZoomEye
- BinaryEdge
- Thingful
- Wigle
- Hunter.io
- BuiltWith
- Recon-ng
- PublicWWW
- FCC ID Database
- CVE PoC Search - CVE IDで公開GitHub PoCリポジトリを検索。
防御的セキュリティ
脅威モデリング
- STRIDE Threat Model Guide - Practical DevSecOps
- OWASP Threat Modeling Process
- STRIDE-based Threat Modeling for IoT Precision Agriculture
STRIDEフレームワーク
- What is STRIDE in Threat Modeling - Security Compass
- Threat Modeling with ATT&CK - MITRE
- What is Threat Modeling - Fortinet
IoT固有の脅威モデリング
- STRIDE Threat Modeling for IoT Smart Home
- STRIDE Threat Modeling for Smart Solar Energy Systems
- STRIDE Threat Modeling for IoT Healthcare Systems
- STRIDE for IoT Agriculture - IEEE
セキュア開発
- Compiler Options Hardening Guide for C and C++
- Linux Hardening Guide
- Docker Security - Step-by-Step Hardening
- How To Secure A Linux Server
ガイドラインと標準
- NIST IoT Cybersecurity Framework
- NIST SP 800-213 - IoT Device Cybersecurity Guidance
- NISTIR 8259 - Foundational Cybersecurity Activities for IoT Manufacturers
- ETSI EN 303 645 - Cyber Security for Consumer IoT
- OWASP IoT Top 10 (2018)
- OWASP IoT Project
ハードニングガイド
インシデントレスポンス
学習リソース
トレーニングプラットフォーム
チートシート
- Hardware Hacking Cheatsheet
- Nmap Tutorial
- Pentest Hardware Handbook
- THC's favourite Tips, Tricks & Hacks
- Cross Cache Attack CheetSheet
脆弱性ガイド
- OWASP IoT Top 10 2018 Mapping
- Reflecting on OWASP IoT Top 10
- CVE North Stars
- IoT Vulnerabilities with CVE and PoC
- Linux Privilege Escalation
ペネトレーションテストガイド
- Shodan Pentesting Guide
- Modern Vulnerability Research on Embedded Systems
- Awesome Embedded Systems Vulnerability Research
YouTubeチャンネル
- Joe Grand
- LiveOverflow
- Binary Adventure
- EEVBlog
- Craig Smith
- IoTSecurity101
- Besim ALTINOK
- Ghidra Ninja
- Cyber Gibbons
- Scanline
- Aaron Christophel
- Valerio Di Giampietro
- Gamozo Labs - Printer Hacking
書籍
ハードウェアハッキング
- The Hardware Hacking Handbook - Jasper van Woudenberg & Colin O'Flynn (2021)
- Practical Hardware Pentesting - Jean-Georges Valle (2021)
- Practical Hardware Pentesting 2nd Edition (2023)
- Hardware Hacking: Have Fun While Voiding Your Warranty - Joe Grand (2004)
- Hacking the Xbox - Andrew "bunnie" Huang (2013)
- The Hardware Hacker - Andrew "bunnie" Huang (2019)
- The Art of PCB Reverse Engineering - Keng Tiong (2015)
- Manual PCB-RE: The Essentials - Keng Tiong (2021)
- Hardware Security Training, Hands-on! (2023)
- Hardware Security: Challenges and Solutions (2025)
- Mastering Hardware Hacking (2025)
- Ultimate Hardware Hacking Gear Guide
- Microcontroller Exploits (2024)
- Engineering Secure Devices - Dominik Merli (2024)
- Cryptography and Embedded Systems Security - Hou & Breier (2024)
ファームウェアとリバースエンジニアリング
- The Firmware Handbook - Jack Ganssle (2004)
- Learning Linux Binary Analysis - Ryan O'Neill (2016)
- Fuzzing Against the Machine (2023)
- Rootkits and Bootkits - Matrosov, Rodionov, Bratus (2019)
- Ghidra Software Reverse Engineering 2nd Edition (2025)
- The Ghidra Book 2nd Edition - Nance & Eagle (2026)
- The Definitive Handbook on Reverse Engineering Tools (2025)
- x86 Software Reverse-Engineering, Cracking, and Counter-Measures - Domas & Domas (2024)
- Fuzzing Android - Zawawy, Rodionov et al. (2026)
- From Day Zero to Zero Day - Eugene Lim (2025)
- The Spacecraft Hacker's Handbook - Olchawa & Starcik (2026)
IoTセキュリティ
- Abusing the Internet of Things - Nitesh Dhanjani (2015)
- IoT Penetration Testing Cookbook - Aaron Guzman & Aditya Gupta (2017)
- Practical IoT Hacking: The Definitive Guide (2021)
- PatrIoT: Practical and Agile Threat Research for IoT (2022)
- The Embedded Linux Security Handbook - St. Onge & Krishnan (2025)
- Securing Smart Things - Massimo Nardone (2026)
ワイヤレスとRF
- Inside Radio: An Attack and Defense Guide - Qing Yang, Lin Huang (2018)
- Hack the Airwaves: Advanced BLE Exploitation (2023)
- Practical SDR - David Clark & Paul Clark (2025)
- The Art of ARM Assembly, Volume 1 - Randall Hyde (2025)
- The Wireless Cookbook - Bill Zimmerman (2026)
組み込みとモバイル
NFC/RFID
- Near Field Communication (NFC): From Theory to Practice (2012)
- Security Issues in Mobile NFC Devices - Michael Roland (2024)
自動車セキュリティ
- The Car Hacker's Handbook - Craig Smith (2016)
- Building Secure Automotive IoT Applications - Oka et al. (2024)
- Offensive Automotive Cybersecurity - Nasser & Oka (2025)
産業および一般セキュリティ
- Gray Hat Hacking 5th Edition (2018)
- Black Hat Python 2nd Edition (2021)
- Attacking Network Protocols - James Forshaw (2017)
- Securing Industrial Control Systems - Rahman et al. (2026)
ホワイトペーパーとレポート
IoTシリーズ
ラボとCTF
脆弱なアプリケーション
- DVID - Damn Vulnerable IoT Device
- IoTGoat - Vulnerable OpenWrt Firmware
- BLE CTF
- Microcorruption
- ARM-X CTF
ハードウェア
産業
VoIP
CTFコンペティション
ハードウェアCTF
IoT CTF
組み込み/ファームウェアCTF
ARM CTF
継続的学習プラットフォーム
ラボ構築
研究とコミュニティ
技術研究
- Dropcam Hacking
- LED Light Hacking
- PS4 Jailbreak Status
- Lenovo Watch X Privacy Issues
- Smart Scale Privacy Issues
- Besder IP Camera Security Analysis
ブログ- Team82 Research
- Voidstarsec
- wrongbaud
- Firmware Analysis
- Exploitee.rs
- Payatu Blog
- Raelize Blog
- JCJC Dev
- W00tsec
- Devttys0
- Embedded Bits
- Keenlab
- Courk.cc
- IoT Security Wiki
- Cybergibbons
- Firmware.RE
- K3170makan
- Tclaverie
- Besimaltinok
- Ctrlu
- IoT Pentest
- Duo Decipher
- Sp3ctr3
- 0x42424242
- Dantheiotman
- Danman
- Quentinkaiser
- Quarkslab
- Ice9
- F-Secure Labs
- MG.lol
- CJHackerz
- Bunnie's Blog
- Synacktiv Publications
- Cr4.sh
- Ktln2
- Naehrdine
- Limited Results
- Fail0verflow
- Exploit Security
- Attify Blog
- Jilles.com
- Syss Tech Blog
- HardBreak Wiki
- 8ksec
- Starlabs
- boschko.ca
- 0xtriboulet
- Nozomi Networks
コミュニティプラットフォーム
ビレッジ
フォローすべき研究者
- Jilles
- Joe Fitz
- Aseem Jakhar
- Cybergibbons
- Jasper
- Dave Jones
- bunnie
- Ilya Shaposhnikov
- Mark C.
- Aaron Guzman
- Yashin Mehaboobe
- Arun Magesh
- Mr-IoT
- QKaiser
- 9lyph
デバイス固有のリサーチ
カメラ
- ARLO: I'M WATCHING YOU
- Hacking a Tapo TC60 Camera
- Rooting a Hive Camera
- Pwn2Own: Synology BC500 IP Camera
- Turning Camera Surveillance on its Axis
- Pwn2Own Ireland 2024 - Ubiquiti AI Bullet
スマートホームデバイス
- Hacking a Smart Home Device
- The Silent Spy Among Us: Smart Intercom Attacks
- Pwnassistant - Home Assistant RCE
- Hacking Sonoff Smart Home IoT Device
スマートスピーカー
- Turning Google smart speakers into wiretaps for $100k
- Smart Speaker Shenanigans: Making the Sonos ONE Sing its Secrets
- Listen Up: Sonos Over-The-Air Remote Kernel Exploitation and Covert Wiretap
- Streaming Zero-Fi Shells to Your Smart Speaker
プリンター
- Pwning a Brother labelmaker, for fun and interop!
- lexmark printer haxx
- Pwn2Own Ireland 2024: Canon imageCLASS MF656Cdw
- Print Scan Hacks: Brother devices
ドローン
- DJI Mavic 3 Drone Research: Firmware Analysis
- DJI Mavic 3 Drone Research: Vulnerability Analysis
- DJI - The ART of obfuscation
- Local Privilege Escalation on the DJI RM500 Smart Controller
キッチン家電
NAS デバイス
- A Pain in the NAS: Synology DS920+ Edition
- Weekend Destroyer - RCE in Western Digital PR4100 NAS
- Exploiting the Synology TC500 at Pwn2Own Ireland 2024
ゲームコンソール
- Hacking the Nintendo DSi Browser
- mast1c0re: Exploiting the PS4 and PS5 through a game save
- Being Overlord on the Steam Deck with 1 Byte
- Hacking the XBox 360 Hypervisor
スマートフォン/タブレット
- Pixel 6 Bootloader Series
- Solo: A Pixel 6 Pro Story
- Gaining kernel code execution on an MTE-enabled Pixel 8
- Bypassing MTE with CVE-2025-0072
- Debugging the Pixel 8 kernel via KGDB
- A First Glimpse of the Starlink User Terminal
- Diving into Starlink's User Terminal Firmware
TrustZone と TEE のリサーチ
- ARM TrustZone: pivoting to the secure world
- TEE Reversing
- A Deep Dive into Samsung's TrustZone - Parts 1-3
- Researching Xiaomi's TEE
- Kinibi TEE: Trusted Application Exploitation
- Reversing Samsung's H-Arx Hypervisor Framework
- EL3vated Privileges: Glitching Google WiFi Pro from Root to EL3
Pwn2Own リサーチ
- Your not so "Home Office" - SOHO Hacking at Pwn2Own
- Pwn2Own Toronto 2023 Series - Parts 1-5
- Pwn2Own: WAN-to-LAN Exploit Showcase
MCP / AI エージェント
Bluetooth リバースエンジニアリング
- bt-re-mad-skillz - HCI レイヤーにおける Bluetooth コントローラファームウェアのリバースエンジニアリング向け LLM スキル。Claude Code および ChatGPT/Codex 用。
コントリビューション
コントリビューションを歓迎します。既存の構成に従って、新しいリソースを含む PR を送信してください。