Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
TEE-reversing — ARM 기기에서 리버스 엔지니어링 및 신뢰 코드 실행을 달성하는 방법을 배우기 위한 공개 TEE 리소스의 엄선된 목록 | Kitploit
도구/GitHubGitHub/enovella/tee-reversing
Android SecurityEmbedded Systems SecurityExploitationReverse EngineeringFuzzingMobile SecurityHardware SecurityBinary AnalysisPapers & ResearchLearning & EducationCurated ResourcesFirmware Analysis
1.0k1197개월 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
GitHubenovella/tee-reversing

TEE-reversing

ARM 기기에서 리버스 엔지니어링 및 신뢰 코드 실행을 달성하는 방법을 배우기 위한 공개 TEE 리소스의 엄선된 목록

저장소 보기

TEE 기초 및 일반

  • TEE(Trusted Execution Environment) 소개: ARM의 TrustZone

    • https://blog.quarkslab.com/introduction-to-trusted-execution-environment-arms-trustzone.html
  • TEE 소개 (원제: TEEを中心とするCPUセキュリティ機能の動向 )

    • https://seminar-materials.iijlab.net/iijlab-seminar/iijlab-seminar-20181120.pdf
  • ARM TrustZone 공격

    • https://blog.quarkslab.com/attacking-the-arms-trustzone.html
  • ARM TrustZone 보안 백서

    • http://infocenter.arm.com/help/topic/com.arm.doc.prd29-genc-009492c/PRD29-GENC-009492C_trustzone_security_whitepaper.pdf
  • ARM TrustZone 웹사이트

    • https://developer.arm.com/ip-products/security-ip/trustzone
  • TrustZone 해설: 아키텍처 기능 및 사용 사례

    • http://sefcom.asu.edu/publications/trustzone-explained-cic2016.pdf
  • 모바일 기기에서의 신뢰할 수 있는 실행

    • https://netsec.ethz.ch/publications/papers/paper-hyperphone-TRUST-2012.pdf
  • ARM TrustZone의 비밀 해부: 종합 조사

    • https://www.researchgate.net/profile/Nuno_Santos9/publication/330696364_Demystifying_Arm_TrustZone_A_Comprehensive_Survey/links/5c6ff1a792851c6950379cdd/Demystifying-Arm-TrustZone-A-Comprehensive-Survey.pdf
  • TEE 및 Arm TrustZone 이해 (Azeria 작성)

    • https://azeria-labs.com/trusted-execution-environments-tee-and-trustzone/
  • SoK: TrustZone 기반 TEE 시스템의 주요 보안 취약점 이해

    • https://www.cs.purdue.edu/homes/pfonseca/papers/sp2020-tees.pdf
  • 모바일 보안에 부팅 제공 (Jonathan Levin 작성)

    • https://papers.put.as/papers/ios/2016/TrustZone.pdf
  • ARM의 TrustZone 군비 경쟁 (Jonathan Levin 작성)

    • http://technologeeks.com/files/TZ.pdf

TEE 익스플로잇/보안 분석

하이실리콘/화웨이 (TrustedCore)

  • Android에서 TrustZone 익스플로잇 (BH-US 2015) - Di Shen(@returnsme)

    • https://www.blackhat.com/docs/us-15/materials/us-15-Shen-Attacking-Your-Trusted-Core-Exploiting-Trustzone-On-Android-wp.pdf
  • EL3 투어: Android 휴대폰의 최고 권한 획득 (Infiltrate19)

    • https://speakerdeck.com/hhj4ck/el3-tour-get-the-ultimate-privilege-of-android-phone
    • 논문: infiltrate.pdf
    • 동영상: https://vimeo.com/335948808
  • Nailgun: ARM 기기에서 권한 격리 깨기 (PoC #2 전용)

    • https://github.com/ningzhenyu/nailgun
  • Nick Stephens: 코로 휴대폰 잠금을 해제하는 방법. (NWd <> SWd 통신 및 익스플로잇의 큰 그림 제공) GeekPwn 2016

    • https://fr.slideshare.net/GeekPwnKeen/nick-stephenshow-does-someone-unlock-your-phone-with-nose

퀄컴 (QSEE)

  • TrustZone 신뢰에 대한 고찰 (2014)

    • https://www.blackhat.com/docs/us-14/materials/us-14-Rosenberg-Reflections-on-Trusting-TrustZone.pdf
  • 모든 컨텍스트에서 TrustZone 커널의 임의 코드 실행 달성 (2015/03/28)

    • http://bits-please.blogspot.com/2015/03/getting-arbitrary-code-execution-in.html
  • 퀄컴 TrustZone 구현 탐구 (2015/08/04)

    • http://bits-please.blogspot.com/2015/08/exploring-qualcomms-trustzone.html
  • MSM8974용 전체 TrustZone 익스플로잇 (2015/08/10)

    • http://bits-please.blogspot.com/2015/08/full-trustzone-exploit-for-msm8974.html
  • TrustZone 커널 권한 상승 (CVE-2016-2431)

    • http://bits-please.blogspot.com/2016/06/trustzone-kernel-privilege-escalation.html
  • War of the Worlds - QSEE에서 Linux 커널 하이재킹

    • http://bits-please.blogspot.com/2016/05/war-of-worlds-hijacking-linux-kernel.html
  • QSEE 권한 상승 취약점 및 익스플로잇 (CVE-2015-6639)

    • http://bits-please.blogspot.com/2016/05/qsee-privilege-escalation-vulnerability.html
  • 퀄컴 보안 실행 환경 탐구 (2016/04/26)

    • http://bits-please.blogspot.com/2016/04/exploring-qualcomms-secure-execution.html
  • 제로 권한에서 mediaserver로의 Android 권한 상승 (CVE-2014-7920 + CVE-2014-7921)

    • http://bits-please.blogspot.com/2016/01/android-privilege-escalation-to.html
  • 신뢰 문제: TrustZone TEE 익스플로잇 (2017년 7월 24일)

모토로라 (퀄컴 SoC)

  • 모토로라 부트로더 잠금 해제 (2016/02/10)
    • http://bits-please.blogspot.com/2016/02/unlocking-motorola-bootloader.html

HTC (퀄컴 SoC)

  • 여기 용이 있다: TrustZone의 취약점 (2014/08/14)
    • https://atredispartners.blogspot.com/2014/08/here-be-dragons-vulnerabilities-in.html

Trustonic (Kinibi 및 MobiCore)

  • 휴대폰 언박싱: 파트 I, II 및 III

    • https://medium.com/taszksec/unbox-your-phone-part-i-331bbf44c30c
    • https://medium.com/taszksec/unbox-your-phone-part-ii-ae66e779b1d6
    • https://medium.com/taszksec/unbox-your-phone-part-iii-7436ffaff7c7
    • https://github.com/puppykitten/tbase
    • https://github.com/puppykitten/tbase/blob/master/unboxyourphone_ekoparty.pdf
  • KINIBI TEE: Trusted Application 익스플로잇 (2018-12-10)

    • https://www.synacktiv.com/posts/exploit/kinibi-tee-trusted-application-exploitation.html
  • 삼성 Exynos 기기에서의 TEE 익스플로잇 - Eloi Sanfelix: 파트 I, II, III, IV

    • https://labs.bluefrostsecurity.de/blog/2019/05/27/tee-exploitation-on-samsung-exynos-devices-introduction/
    • https://labs.bluefrostsecurity.de/files/TEE.pdf
    • 동영상: (Infiltrate 2019) https://vimeo.com/335947683
  • 삼성 ARM TrustZone 깨기 (BlackHat USA 2019)

    • 슬라이드: https://i.blackhat.com/USA-19/Thursday/us-19-Peterlin-Breaking-Samsungs-ARM-TrustZone.pdf
    • 동영상: https://www.youtube.com/watch?v=uXH5LJGRwXI&list=PLH15HpR5qRsWrfkjwFSI256x1u2Zy49VI&index=30
  • TrustZone TEE에서 피드백 기반 퍼징 시작 (HITBGSEC2019)

    • https://gsec.hitb.org/materials/sg2019/D2%20-%20Launching%20Feedback-Driven%20Fuzzing%20on%20TrustZone%20TEE%20-%20Andrey%20Akimov.pdf

삼성 (TEEGRIS)

  • TEE 보안 깨기:

    • (파트 1 - 소개) https://www.riscure.com/blog/tee-security-samsung-teegris-part-1
    • (파트 2 - TA 익스플로잇) https://www.riscure.com/blog/tee-security-samsung-teegris-part-2
    • (파트 3 - TA 권한 상승 > TOS) https://www.riscure.com/blog/tee-security-samsung-teegris-part-3
  • 삼성 Exynos 9820 부트로더 및 TZ 리버스 엔지니어링 - @astarasikov

    • http://allsoftwaresucks.blogspot.com/2019/05/reverse-engineering-samsung-exynos-9820.html
  • S21의 10ADAB1E 펌웨어 버그 헌팅 (OffensiveCon 2022)

    • https://www.dropbox.com/s/2f14ga52jguu5cy/OffensiveCon%202022%20-%20Bug%20Hunting%20S21s%2010ADAB1E%20FW.pdf?dl=0
  • 오래된 삼성 Exynos Trustlet 버그에서 배우기 - @TwizzyIndy

    • https://twizzyindy.github.io/android/exynos/2026/01/06/learning-exynos-trustlet-en.html

애플 (Secure Enclave)

  • Secure Enclave 프로세서의 비밀 해부 - Tarjei Mandt, Mathew Solnik, David Wang
    • http://mista.nu/research/sep-paper.pdf
    • 슬라이드 https://www.blackhat.com/docs/us-16/materials/us-16-Mandt-Demystifying-The-Secure-Enclave-Processor.pdf

인텔 (Intel SGX)

  • Intel SGX 해설 - Victor Costan, Srinivas Devadas
    • https://css.csail.mit.edu/6.858/2017/readings/costan-sgx.pdf

TEE 퍼징

  • PARTEMU: 에뮬레이션을 통한 실제 TrustZone 소프트웨어의 동적 분석 지원

    • https://people.eecs.berkeley.edu/~rohanpadhye/files/partemu-usenixsec20.pdf
  • 퀄컴 TrustZone 앱 퍼징으로 가는 길

    • https://research.checkpoint.com/the-road-to-qualcomm-trustzone-apps-fuzzing/
    • https://cfp.recon.cx/media/tz_apps_fuzz.pdf
  • TrustZone TEE에서 피드백 기반 퍼징 시작 (HITB GSEC 2019 싱가포르)

    • 슬라이드: https://gsec.hitb.org/materials/sg2019/D2%20-%20Launching%20Feedback-Driven%20Fuzzing%20on%20TrustZone%20TEE%20-%20Andrey%20Akimov.pdf
    • 동영상: https://www.youtube.com/watch?v=yb7KGznzczs
  • AFL을 사용한 임베디드(신뢰) 운영체제 퍼징 (Martijn Bogaard | nullcon Goa 2019) OP-TEE

    • 슬라이드: https://nullcon.net/website/archives/pdf/bangalore-2019/fuzzing-embedded-(trusted)-operating-systems%20using-AFL.pdf
    • 동영상: https://www.youtube.com/watch?v=AZhxZlwZ160
    • 웨비나: https://www.youtube.com/watch?time_continue=12&v=ROyD9RTMePA
  • SAN19-225 AFL을 사용한 임베디드(신뢰) 운영체제 퍼징 (Martijn Bogaard) OP-TEE

    • 동영상: https://www.youtube.com/watch?v=7bYAwaJ7WZw

TEE 시큐어 부트

  • 삼성 S6 SBOOT 리버스 엔지니어링 - 파트 I 및 II

    • https://blog.quarkslab.com/reverse-engineering-samsung-s6-sboot-part-i.html
    • https://blog.quarkslab.com/reverse-engineering-samsung-s6-sboot-part-ii.html
  • TEE의 안전한 초기화: 시큐어 부트가 부족할 때 (EuskalHack 2017)

    • https://www.riscure.com/uploads/2017/08/euskalhack_2017_-_secure_initialization_of_tees_when_secure_boot_falls_short.pdf
  • Amlogic S905 SoC: BootROM 덤프를 위한 (그다지 안전하지 않은) 시큐어 부트 우회

    • https://fredericb.info/2016/10/amlogic-s905-soc-bypassing-not-so.html#amlogic-s905-soc-bypassing-not-so
  • 퀄컴 시큐어 부트 및 이미지 인증 기술 개요

    • https://www.qualcomm.com/documents/secure-boot-and-image-authentication-technical-overview-v20
  • 삼성의 루트 오브 트러스트 깨기 - 삼성 시큐어 부트 익스플로잇 (BlackHat 2020)

    • https://teamt5.org/en/posts/blackhat-s-talk-breaking-samsung-s-root-of-trust-exploiting-samsung-secure-boot/
  • ARM 기반 SoC의 시큐어 부트 상태 개요 (하드웨어 지원 신뢰 컴퓨팅 devroom - Maciej Pijanowski - FOSDEM 2021)

    • https://archive.fosdem.org/2021/schedule/event/tee_arm_secboot/attachments/paper/4635/export/events/attachments/tee_arm_secboot/paper/4635/Overview_of_Secure_Boot_in_Arm_based_SoCs.pdf
  • Android TA 버그 헌팅 및 퍼징 심층 분석 (Kanxue SDC 2023) - https://github.com/guluisacat/MySlides/blob/main/KanxueSDC2023/%E3%80%90%E8%AE%AE%E9%A2%98%E3%80%91%E6%B7%B1%E5%85%A5Android%E5%8F%AF%E4%BF%A1%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E%E6%8C%96%E6%8E%98.pdf

TEE 동영상

  • Ekoparty-13 (2017) Daniel Komaromy - 휴대폰 언박싱 - 삼성 TrustZone 샌드박스 탐구 및 깨기

    • 동영상: https://www.youtube.com/watch?v=L2Mo8WcmmZo
    • 슬라이드: https://github.com/puppykitten/tbase/blob/master/unboxyourphone_ekoparty.pdf
  • Daniel Komaromy - 스냅드래곤 속으로 (2014-10-11)

    • https://www.youtube.com/watch?v=2wJRnewVE-g
  • BSides DC 2018 및 DerbiCon VIII - 정확히: TrustZone 익스플로잇을 통한 화웨이 지문 인증 우회 (Nick Stephens)

    • https://www.youtube.com/watch?v=QFFhdqP7Dxg
    • https://www.youtube.com/watch?v=MdoGCXGHGnY
  • 용의 침입: ARM TrustZone 아키텍처의 취약점 탐구 (Josh Thomas, Charles Holmes) - 오스트리아 빈 Android 보안 심포지엄, 2015년 9월 9~11일

    • https://www.youtube.com/watch?v=vxNGgOR-iVM
  • Android와 TEE (Jan-Erik Ekberg, Trustonic) - 오스트리아 빈 Android 보안 심포지엄, 2015년 9월 9~11일

    • https://www.youtube.com/watch?v=5542lEk3OAM
  • 34C3 2017 - 콘솔 보안 - Switch (Plutoo, Derrek, Naehrwert)

    • https://media.ccc.de/v/34c3-8941-console_security_-_switch
  • 34C3 2017 - TrustZone만으로는 부족하다 (Pascal Cotret)

    • https://media.ccc.de/v/34c3-8831-trustzone_is_not_enough
  • RootedCON 2017 - 엄마가 절대 알려주지 않았던 TEE 이야기... (José A. Rivas)

    • 스페인어 원본 오디오 https://www.youtube.com/watch?v=lzrIzS84mdk
    • 영어 번역 https://www.youtube.com/watch?v=Lzb5OfE1M7s
  • BH US 2015 - 모바일 기기의 지문: 악용 및 유출

    • https://www.youtube.com/watch?v=7NkojB9gLXM

TEE에 적용된 마이크로아키텍처 공격

  • ARMageddon: 모바일 기기에서의 캐시 공격

    • [논문] https://www.usenix.org/system/files/conference/usenixsecurity16/sec16_paper_lipp.pdf
    • [관련 도구] https://github.com/IAIK/armageddon
  • 캐시 저장 채널: 앨리어스 기반 공격 및 검증된 대응책.

    • https://www.kth.se/polopoly_fs/1.641701.1550155969!/R.Guanciale.pdf
  • 34C3 - TEE에 대한 마이크로아키텍처 공격

    • https://media.ccc.de/v/34c3-8950-microarchitectural_attacks_on_trusted_execution_environments
  • TruSpy: ARM 기기의 시큐어 월드에서 캐시 부채널 정보 유출

    • https://eprint.iacr.org/2016/980.pdf

도구

에뮬레이션

  • Exynos9820 S-Boot용 QEMU 지원

    • https://github.com/astarasikov/qemu
  • QEMU에서 Exynos 4210 BootROM 에뮬레이션

    • https://fredericb.info/2018/03/emulating-exynos-4210-bootrom-in-qemu.html#emulating-exynos-4210-bootrom-in-qemu

리버스

  • TZAR 언패커

    • https://gist.github.com/astarasikov/f47cb7f46b5193872f376fa0ea842e4b#file-unpack_startup_tzar-py
  • IDA MCLF 로더

    • https://github.com/ghassani/mclf-ida-loader
  • Ghidra MCLF 로더

    • https://github.com/NeatMonster/mclf-ghidra-loader

기타 유용한 리소스

  • ARM Trusted Firmware: Cortex A 및 Cortex M용 시큐어 월드의 참조 구현

    • https://www.trustedfirmware.org/
  • OP-TEE: 오픈소스 ARM TrusZone 기반 TEE

    • https://www.op-tee.org/
  • 신뢰 문제: Project Zero 팀의 TrustZone TEE 익스플로잇

    • https://googleprojectzero.blogspot.com/2017/07/trust-issues-exploiting-trustzone-tees.html
  • Boomerang: TEE의 시맨틱 갭 익스플로잇 (A.Machiry) 2017

    • https://pdfs.semanticscholar.org/f62b/db9f1950329f59dc467238737d2de1a1bac4.pdf (슬라이드)
    • http://sites.cs.ucsb.edu/~cspensky/pdfs/ndss17-final227.pdf (논문)
    • https://github.com/ucsb-seclab/boomerang (도구)
  • TEE 연구 (TEE 연구에 유용한 일부 IDA 및 Ghidra 플러그인)

    • https://github.com/bkerler/tee_research
도구 다운로드
  • https://googleprojectzero.blogspot.com/2017/07/trust-issues-exploiting-trustzone-tees.html
  • Breaking Bad. Android(4-9.x)의 퀄컴 ARM64 TZ 및 하드웨어 지원 시큐어 부트 검토

    • https://github.com/bkerler/slides_and_papers/blob/master/QualcommCrypto.pdf
  • 기술 자문: 퀄컴 하드웨어 기반 키스토어에서 개인 키 추출 CVE-2018-11976 (NCC)

    • https://www.nccgroup.trust/us/our-research/private-key-extraction-qualcomm-keystore/
  • 퀄컴 TrustZone 정수 부호 버그 (2014/12)

    • https://fredericb.info/2014/12/qpsiir-80-qualcomm-trustzone-integer.html
  • 퀄컴 TrustZone 앱 퍼징으로 가는 길 (RECON Montreal 2019)

    • https://cfp.recon.cx/media/tz_apps_fuzz.pdf
  • TrustZone 다운그레이드 공격

    • http://ww2.cs.fsu.edu/~ychen/paper/downgradeTZ.pdf
  • 삼성 TrustZone 심층 분석

    • (파트 1 - 소개) https://blog.quarkslab.com/a-deep-dive-into-samsungs-trustzone-part-1.html
    • (파트 2 - TA 퍼징) https://blog.quarkslab.com/a-deep-dive-into-samsungs-trustzone-part-2.html
    • (파트 3 - EL3 익스플로잇) https://blog.quarkslab.com/a-deep-dive-into-samsungs-trustzone-part-3.html
  • No ConName 2015 - (비)신뢰 실행 환경 (Pau Oliva)

    • 동영상: 스페인어 오디오만 제공 https://vimeo.com/150787883
    • 슬라이드: https://t.co/vFATxEa7sy
  • BH US 2014 - TrustZone 신뢰에 대한 고찰 (Dan Rosenberg)

    • https://www.youtube.com/watch?v=7w40mS5yLjc
  • 왕초보를 위한 ARM TrustZone (Tim Hummels)

    • https://www.youtube.com/watch?v=ecBByjwny3s