Skip to content
KitploitKITPLOIT
ツールブログ
Log in
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
TEE-reversing — ARMデバイス上でリバースエンジニアリングを行い、信頼できるコード実行を実現する方法を学ぶための、厳選された公開TEEリソース集 | Kitploit
ツール/GitHubGitHub/enovella/tee-reversing
Androidセキュリティ組み込みシステムセキュリティエクスプロイトリバースエンジニアリングファジングモバイルセキュリティハードウェアセキュリティバイナリ解析論文と研究学習と教育厳選リソースファームウェア解析
1.0k119298ヶ月前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
GitHubenovella/tee-reversing

TEE-reversing

ARMデバイス上でリバースエンジニアリングを行い、信頼できるコード実行を実現する方法を学ぶための、厳選された公開TEEリソース集

リポジトリを見る

TEEの基礎と一般

  • Trusted Execution Environment入門: ARMのTrustZone

    • https://blog.quarkslab.com/introduction-to-trusted-execution-environment-arms-trustzone.html
  • TEE入門 (原著タイトル: TEEを中心とするCPUセキュリティ機能の動向 )

    • https://seminar-materials.iijlab.net/iijlab-seminar/iijlab-seminar-20181120.pdf
  • ARMのTrustZoneへの攻撃

    • https://blog.quarkslab.com/attacking-the-arms-trustzone.html
  • ARM TrustZoneセキュリティホワイトペーパー

    • http://infocenter.arm.com/help/topic/com.arm.doc.prd29-genc-009492c/PRD29-GENC-009492C_trustzone_security_whitepaper.pdf
  • ARM TrustZoneのWebサイト

    • https://developer.arm.com/ip-products/security-ip/trustzone
  • TrustZone解説: アーキテクチャの特徴とユースケース

    • http://sefcom.asu.edu/publications/trustzone-explained-cic2016.pdf
  • モバイルデバイスにおける信頼できる実行

    • https://netsec.ethz.ch/publications/papers/paper-hyperphone-TRUST-2012.pdf
  • ARM Trustzoneの謎を解き明かす : 包括的サーベイ

    • https://www.researchgate.net/profile/Nuno_Santos9/publication/330696364_Demystifying_Arm_TrustZone_A_Comprehensive_Survey/links/5c6ff1a792851c6950379cdd/Demystifying-Arm-TrustZone-A-Comprehensive-Survey.pdf
  • Trusted Execution EnvironmentとArm TrustZoneを理解する (著: Azeria)

    • https://azeria-labs.com/trusted-execution-environments-tee-and-trustzone/
  • SoK: TrustZone支援TEEシステムにおける蔓延するセキュリティ脆弱性の理解

    • https://www.cs.purdue.edu/homes/pfonseca/papers/sp2020-tees.pdf
  • モバイルセキュリティを追い出す (著: Jonathan Levin)

    • https://papers.put.as/papers/ios/2016/TrustZone.pdf
  • TrustZoneをめぐるARM競争 (著: Jonathan Levin)

    • http://technologeeks.com/files/TZ.pdf

TEEエクスプロイト/セキュリティ分析

HiSilicon/Huawei (TrustedCore)

  • Android上のTrustzoneの悪用 (BH-US 2015) (著: Di Shen(@returnsme))

    • https://www.blackhat.com/docs/us-15/materials/us-15-Shen-Attacking-Your-Trusted-Core-Exploiting-Trustzone-On-Android-wp.pdf
  • EL3ツアー : Androidスマートフォンの究極の特権を手に入れる (Infiltrate19)

    • https://speakerdeck.com/hhj4ck/el3-tour-get-the-ultimate-privilege-of-android-phone
    • 論文: infiltrate.pdf
    • ビデオ: https://vimeo.com/335948808
  • Nailgun: ARMデバイスの特権分離を破る (PoC #2のみ)

    • https://github.com/ningzhenyu/nailgun
  • Nick Stephens : 鼻でスマートフォンのロックを解除する方法 (NWd <> SWd間の通信とエクスプロイトの全体像) GeekPwn 2016

    • https://fr.slideshare.net/GeekPwnKeen/nick-stephenshow-does-someone-unlock-your-phone-with-nose

Qualcomm (QSEE)

  • TrustZoneを信頼することへの考察 (2014)

    • https://www.blackhat.com/docs/us-14/materials/us-14-Rosenberg-Reflections-on-Trusting-TrustZone.pdf
  • 任意のコンテキストからTrustZoneカーネルで任意コード実行を達成する (28/03/2015)

    • http://bits-please.blogspot.com/2015/03/getting-arbitrary-code-execution-in.html
  • QualcommのTrustZone実装を探る (04/08/2015)

    • http://bits-please.blogspot.com/2015/08/exploring-qualcomms-trustzone.html
  • MSM8974向け完全なTrustZoneエクスプロイト (10/08/2015)

    • http://bits-please.blogspot.com/2015/08/full-trustzone-exploit-for-msm8974.html
  • TrustZoneカーネルの権限昇格 (CVE-2016-2431)

    • http://bits-please.blogspot.com/2016/06/trustzone-kernel-privilege-escalation.html
  • War of the Worlds - QSEEからLinuxカーネルをハイジャックする

    • http://bits-please.blogspot.com/2016/05/war-of-worlds-hijacking-linux-kernel.html
  • QSEEの権限昇格の脆弱性とエクスプロイト (CVE-2015-6639)

    • http://bits-please.blogspot.com/2016/05/qsee-privilege-escalation-vulnerability.html
  • QualcommのSecure Execution Environmentを探る (26/04/2016)

    • http://bits-please.blogspot.com/2016/04/exploring-qualcomms-secure-execution.html
  • ゼロ権限からmediaserverへのAndroid権限昇格 (CVE-2014-7920 + CVE-2014-7921)

    • http://bits-please.blogspot.com/2016/01/android-privilege-escalation-to.html
  • 信頼の問題: TrustZone TEEの悪用 (2017年7月24日)

    • https://googleprojectzero.blogspot.com/2017/07/trust-issues-exploiting-trustzone-tees.html
  • Breaking Bad. Android (4-9.x)におけるQualcomm ARM64 TZとハードウェア対応セキュアブートのレビュー

    • https://github.com/bkerler/slides_and_papers/blob/master/QualcommCrypto.pdf
  • 技術アドバイザリ: Qualcommのハードウェア支援キーストアからの秘密鍵抽出 CVE-2018-11976 (NCC)

    • https://www.nccgroup.trust/us/our-research/private-key-extraction-qualcomm-keystore/
  • Qualcomm TrustZoneの整数符号性バグ (12/2014)

    • https://fredericb.info/2014/12/qpsiir-80-qualcomm-trustzone-integer.html
  • Qualcomm TrustZoneアプリのファジングへの道 (RECON Montreal 2019)

    • https://cfp.recon.cx/media/tz_apps_fuzz.pdf
  • TrustZoneへのダウングレード攻撃

    • http://ww2.cs.fsu.edu/~ychen/paper/downgradeTZ.pdf

Motorola (Qualcomm SoC)

  • Motorolaブートローダーのロック解除 (10/02/2016)
    • http://bits-please.blogspot.com/2016/02/unlocking-motorola-bootloader.html

HTC (Qualcomm SoC)

  • ここにドラゴンあり: TrustZoneの脆弱性 (14/08/2014)
    • https://atredispartners.blogspot.com/2014/08/here-be-dragons-vulnerabilities-in.html

Trustonic (Kinibi & MobiCore)

  • Unbox Your Phone: パートI、II & III

    • https://medium.com/taszksec/unbox-your-phone-part-i-331bbf44c30c
    • https://medium.com/taszksec/unbox-your-phone-part-ii-ae66e779b1d6
    • https://medium.com/taszksec/unbox-your-phone-part-iii-7436ffaff7c7
    • https://github.com/puppykitten/tbase
    • https://github.com/puppykitten/tbase/blob/master/unboxyourphone_ekoparty.pdf
  • KINIBI TEE: Trusted Applicationのエクスプロイト (2018-12-10)

    • https://www.synacktiv.com/posts/exploit/kinibi-tee-trusted-application-exploitation.html
  • Eloi Sanfelix著: Samsung ExynosデバイスにおけるTEEエクスプロイト - パートI、II、III、IV

    • https://labs.bluefrostsecurity.de/blog/2019/05/27/tee-exploitation-on-samsung-exynos-devices-introduction/
    • https://labs.bluefrostsecurity.de/files/TEE.pdf
    • ビデオ: (Infiltrate 2019) https://vimeo.com/335947683
  • SamsungのARM TrustZoneを破る (BlackHat USA 2019)

    • スライド: https://i.blackhat.com/USA-19/Thursday/us-19-Peterlin-Breaking-Samsungs-ARM-TrustZone.pdf
    • ビデオ: https://www.youtube.com/watch?v=uXH5LJGRwXI&list=PLH15HpR5qRsWrfkjwFSI256x1u2Zy49VI&index=30
  • TrustZone TEEに対するフィードバック駆動ファジングの開始 (HITBGSEC2019)

    • https://gsec.hitb.org/materials/sg2019/D2%20-%20Launching%20Feedback-Driven%20Fuzzing%20on%20TrustZone%20TEE%20-%20Andrey%20Akimov.pdf
  • Samsungのtrustzoneを深く掘り下げる

    • (パート1 - イントロ) https://blog.quarkslab.com/a-deep-dive-into-samsungs-trustzone-part-1.html
    • (パート2 - TAのファジング) https://blog.quarkslab.com/a-deep-dive-into-samsungs-trustzone-part-2.html
    • (パート3 - EL3の悪用) https://blog.quarkslab.com/a-deep-dive-into-samsungs-trustzone-part-3.html

Samsung (TEEGRIS)

  • TEEセキュリティを破る :

    • (パート1 - イントロ) https://www.riscure.com/blog/tee-security-samsung-teegris-part-1
    • (パート2 - TAの悪用) https://www.riscure.com/blog/tee-security-samsung-teegris-part-2
    • (パート3 - EoP: TAからTOSへの権限昇格) https://www.riscure.com/blog/tee-security-samsung-teegris-part-3
  • @astarasikov著: Samsung Exynos 9820ブートローダーとTZのリバースエンジニアリング

    • http://allsoftwaresucks.blogspot.com/2019/05/reverse-engineering-samsung-exynos-9820.html
  • S21の10ADAB1Eファームウェアのバグハンティング (OffensiveCon 2022)

    • https://www.dropbox.com/s/2f14ga52jguu5cy/OffensiveCon%202022%20-%20Bug%20Hunting%20S21s%2010ADAB1E%20FW.pdf?dl=0
  • @TwizzyIndy著: 過去のSamsung Exynos Trustletバグから学ぶ

    • https://twizzyindy.github.io/android/exynos/2026/01/06/learning-exynos-trustlet-en.html

Apple (Secure Enclave)

  • Tarjei Mandt、Mathew Solnik、David Wang著: Secure Enclave Processorの謎を解き明かす
    • http://mista.nu/research/sep-paper.pdf
    • スライド https://www.blackhat.com/docs/us-16/materials/us-16-Mandt-Demystifying-The-Secure-Enclave-Processor.pdf

Intel (Intel SGX)

  • Victor CostanとSrinivas Devadas著: Intel SGX解説
    • https://css.csail.mit.edu/6.858/2017/readings/costan-sgx.pdf

TEEファジング

  • PARTEMU: エミュレーションによる実世界TrustZoneソフトウェアの動的解析を可能にする

    • https://people.eecs.berkeley.edu/~rohanpadhye/files/partemu-usenixsec20.pdf
  • Qualcomm TrustZoneアプリのファジングへの道

    • https://research.checkpoint.com/the-road-to-qualcomm-trustzone-apps-fuzzing/
    • https://cfp.recon.cx/media/tz_apps_fuzz.pdf
  • TrustZone TEEに対するフィードバック駆動ファジングの開始 (HITB GSEC 2019 シンガポール)

    • スライド: https://gsec.hitb.org/materials/sg2019/D2%20-%20Launching%20Feedback-Driven%20Fuzzing%20on%20TrustZone%20TEE%20-%20Andrey%20Akimov.pdf
    • ビデオ: https://www.youtube.com/watch?v=yb7KGznzczs
ツールをダウンロード