Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
TEE-reversing — 一份精选的公开 TEE 资源列表,用于学习如何对 ARM 设备进行逆向工程并实现可信代码执行。 | Kitploit
工具/GitHubGitHub/enovella/tee-reversing
Android安全嵌入式系统安全漏洞利用逆向工程模糊测试移动安全硬件安全二进制分析论文与研究学习与教育精选资源固件分析
1.0k1197个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
GitHub
enovella/tee-reversing

TEE-reversing

一份精选的公开 TEE 资源列表,用于学习如何对 ARM 设备进行逆向工程并实现可信代码执行。

查看仓库

TEE 基础与概述

  • 可信执行环境简介:ARM 的 TrustZone

    • https://blog.quarkslab.com/introduction-to-trusted-execution-environment-arms-trustzone.html
  • TEE 简介 (原标题:TEEを中心とするCPUセキュリティ機能の動向 )

    • https://seminar-materials.iijlab.net/iijlab-seminar/iijlab-seminar-20181120.pdf
  • 攻击 ARM 的 TrustZone

    • https://blog.quarkslab.com/attacking-the-arms-trustzone.html
  • ARM TrustZone 安全白皮书

    • http://infocenter.arm.com/help/topic/com.arm.doc.prd29-genc-009492c/PRD29-GENC-009492C_trustzone_security_whitepaper.pdf
  • ARM TrustZone 网站

    • https://developer.arm.com/ip-products/security-ip/trustzone
  • TrustZone 详解:架构特性与用例

    • http://sefcom.asu.edu/publications/trustzone-explained-cic2016.pdf
  • 移动设备上的可信执行

    • https://netsec.ethz.ch/publications/papers/paper-hyperphone-TRUST-2012.pdf
  • 揭秘 ARM TrustZone:全面综述

    • https://www.researchgate.net/profile/Nuno_Santos9/publication/330696364_Demystifying_Arm_TrustZone_A_Comprehensive_Survey/links/5c6ff1a792851c6950379cdd/Demystifying-Arm-TrustZone-A-Comprehensive-Survey.pdf
  • 理解可信执行环境与 Arm TrustZone (作者:Azeria)

    • https://azeria-labs.com/trusted-execution-environments-tee-and-trustzone/
  • SoK:理解 TrustZone 辅助 TEE 系统中普遍存在的安全漏洞

    • https://www.cs.purdue.edu/homes/pfonseca/papers/sp2020-tees.pdf
  • 让移动安全启动 (作者:Jonathan Levin)

    • https://papers.put.as/papers/ios/2016/TrustZone.pdf
  • ARM 的 TrustZone 军备竞赛 (作者:Jonathan Levin)

    • http://technologeeks.com/files/TZ.pdf

TEE 漏洞利用/安全分析

海思/华为 (TrustedCore)

  • 在 Android 上利用 TrustZone (BH-US 2015),作者:Di Shen(@returnsme)

    • https://www.blackhat.com/docs/us-15/materials/us-15-Shen-Attacking-Your-Trusted-Core-Exploiting-Trustzone-On-Android-wp.pdf
  • EL3 之旅:获取 Android 手机的终极权限 (Infiltrate19)

    • https://speakerdeck.com/hhj4ck/el3-tour-get-the-ultimate-privilege-of-android-phone
    • 论文:infiltrate.pdf
    • 视频:https://vimeo.com/335948808
  • Nailgun:打破 ARM 设备中的特权隔离 (仅 PoC #2)

    • https://github.com/ningzhenyu/nailgun
  • Nick Stephens:如何用鼻子解锁你的手机。(概述 NWd <> SWd 之间的通信与漏洞利用) GeekPwn 2016

    • https://fr.slideshare.net/GeekPwnKeen/nick-stephenshow-does-someone-unlock-your-phone-with-nose

高通 (QSEE)

  • 关于信任 TrustZone 的反思 (2014)

    • https://www.blackhat.com/docs/us-14/materials/us-14-Rosenberg-Reflections-on-Trusting-TrustZone.pdf
  • 从任意上下文在 TrustZone 内核中实现任意代码执行 (28/03/2015)

    • http://bits-please.blogspot.com/2015/03/getting-arbitrary-code-execution-in.html
  • 探索高通的 TrustZone 实现 (04/08/2015)

    • http://bits-please.blogspot.com/2015/08/exploring-qualcomms-trustzone.html
  • 针对 MSM8974 的完整 TrustZone 漏洞利用 (10/08/2015)

    • http://bits-please.blogspot.com/2015/08/full-trustzone-exploit-for-msm8974.html
  • TrustZone 内核权限提升 (CVE-2016-2431)

    • http://bits-please.blogspot.com/2016/06/trustzone-kernel-privilege-escalation.html
  • 世界之战 - 从 QSEE 劫持 Linux 内核

    • http://bits-please.blogspot.com/2016/05/war-of-worlds-hijacking-linux-kernel.html
  • QSEE 权限提升漏洞及其利用 (CVE-2015-6639)

    • http://bits-please.blogspot.com/2016/05/qsee-privilege-escalation-vulnerability.html
  • 探索高通的安全执行环境 (26/04/2016)

    • http://bits-please.blogspot.com/2016/04/exploring-qualcomms-secure-execution.html
  • 从零权限到 mediaserver 的 Android 权限提升 (CVE-2014-7920 + CVE-2014-7921)

    • http://bits-please.blogspot.com/2016/01/android-privilege-escalation-to.html
  • 信任问题:利用 TrustZone TEE (2017年7月24日)

    • https://googleprojectzero.blogspot.com/2017/07/trust-issues-exploiting-trustzone-tees.html

摩托罗拉 (高通 SoC)

  • 解锁摩托罗拉引导加载程序 (10/02/2016)
    • http://bits-please.blogspot.com/2016/02/unlocking-motorola-bootloader.html

HTC (高通 SoC)

  • 此处有龙:TrustZone 中的漏洞 (14/08/2014)
    • https://atredispartners.blogspot.com/2014/08/here-be-dragons-vulnerabilities-in.html

Trustonic (Kinibi 与 MobiCore)

  • 拆解你的手机:第 I、II 与 III 部分

    • https://medium.com/taszksec/unbox-your-phone-part-i-331bbf44c30c
    • https://medium.com/taszksec/unbox-your-phone-part-ii-ae66e779b1d6
    • https://medium.com/taszksec/unbox-your-phone-part-iii-7436ffaff7c7
    • https://github.com/puppykitten/tbase
    • https://github.com/puppykitten/tbase/blob/master/unboxyourphone_ekoparty.pdf
  • KINIBI TEE:可信应用漏洞利用 (2018-12-10)

    • https://www.synacktiv.com/posts/exploit/kinibi-tee-trusted-application-exploitation.html
  • 三星 Exynos 设备上的 TEE 漏洞利用 (作者:Eloi Sanfelix):第 I、II、III、IV 部分

    • https://labs.bluefrostsecurity.de/blog/2019/05/27/tee-exploitation-on-samsung-exynos-devices-introduction/
    • https://labs.bluefrostsecurity.de/files/TEE.pdf
    • 视频:(Infiltrate 2019) https://vimeo.com/335947683
  • 攻破三星的 ARM TrustZone (BlackHat USA 2019)

    • 幻灯片:https://i.blackhat.com/USA-19/Thursday/us-19-Peterlin-Breaking-Samsungs-ARM-TrustZone.pdf
    • 视频:https://www.youtube.com/watch?v=uXH5LJGRwXI&list=PLH15HpR5qRsWrfkjwFSI256x1u2Zy49VI&index=30
  • 在 TrustZone TEE 上开展反馈驱动的模糊测试 (HITBGSEC2019)

    • https://gsec.hitb.org/materials/sg2019/D2%20-%20Launching%20Feedback-Driven%20Fuzzing%20on%20TrustZone%20TEE%20-%20Andrey%20Akimov.pdf

三星 (TEEGRIS)

  • 攻破 TEE 安全:

    • (第 1 部分 - 简介) https://www.riscure.com/blog/tee-security-samsung-teegris-part-1
    • (第 2 部分 - 利用 TA) https://www.riscure.com/blog/tee-security-samsung-teegris-part-2
    • (第 3 部分 - 从 TA 权限提升至 TOS) https://www.riscure.com/blog/tee-security-samsung-teegris-part-3
  • 逆向三星 Exynos 9820 引导加载程序与 TZ,作者:@astarasikov

    • http://allsoftwaresucks.blogspot.com/2019/05/reverse-engineering-samsung-exynos-9820.html
  • 挖掘 S21 的 10ADAB1E 固件漏洞 (OffensiveCon 2022)

    • https://www.dropbox.com/s/2f14ga52jguu5cy/OffensiveCon%202022%20-%20Bug%20Hunting%20S21s%2010ADAB1E%20FW.pdf?dl=0
  • 从旧版三星 Exynos Trustlet 漏洞中学习,作者:@TwizzyIndy

    • https://twizzyindy.github.io/android/exynos/2026/01/06/learning-exynos-trustlet-en.html

苹果 (安全隔区)

  • 揭秘安全隔区处理器,作者:Tarjei Mandt、Mathew Solnik 和 David Wang
    • http://mista.nu/research/sep-paper.pdf
    • 幻灯片 https://www.blackhat.com/docs/us-16/materials/us-16-Mandt-Demystifying-The-Secure-Enclave-Processor.pdf

英特尔 (Intel SGX)

  • Intel SGX 详解,作者:Victor Costan 和 Srinivas Devadas
    • https://css.csail.mit.edu/6.858/2017/readings/costan-sgx.pdf

TEE 模糊测试

  • PARTEMU:利用仿真实现对真实世界 TrustZone 软件的动态分析

    • https://people.eecs.berkeley.edu/~rohanpadhye/files/partemu-usenixsec20.pdf
  • 高通 TrustZone 应用模糊测试之路

    • https://research.checkpoint.com/the-road-to-qualcomm-trustzone-apps-fuzzing/
    • https://cfp.recon.cx/media/tz_apps_fuzz.pdf
  • 在 TrustZone TEE 上开展反馈驱动的模糊测试 (HITB GSEC 2019 新加坡)

    • 幻灯片:https://gsec.hitb.org/materials/sg2019/D2%20-%20Launching%20Feedback-Driven%20Fuzzing%20on%20TrustZone%20TEE%20-%20Andrey%20Akimov.pdf
    • 视频:https://www.youtube.com/watch?v=yb7KGznzczs
  • 使用 AFL 对嵌入式 (可信) 操作系统进行模糊测试 (Martijn Bogaard | nullcon Goa 2019) OP-TEE

    • 幻灯片:https://nullcon.net/website/archives/pdf/bangalore-2019/fuzzing-embedded-(trusted)-operating-systems%20using-AFL.pdf
    • 视频:https://www.youtube.com/watch?v=AZhxZlwZ160
    • 网络研讨会:https://www.youtube.com/watch?time_continue=12&v=ROyD9RTMePA
  • SAN19-225 使用 AFL 对嵌入式 (可信) 操作系统进行模糊测试 (Martijn Bogaard) OP-TEE

    • 视频:https://www.youtube.com/watch?v=7bYAwaJ7WZw

TEE 安全启动

  • 逆向三星 S6 SBOOT - 第 I 与第 II 部分

    • https://blog.quarkslab.com/reverse-engineering-samsung-s6-sboot-part-i.html
    • https://blog.quarkslab.com/reverse-engineering-samsung-s6-sboot-part-ii.html
  • TEE 的安全初始化:当安全启动失效时 (EuskalHack 2017)

    • https://www.riscure.com/uploads/2017/08/euskalhack_2017_-_secure_initialization_of_tees_when_secure_boot_falls_short.pdf
  • Amlogic S905 SoC:绕过 (并非那么) 安全的启动来转储 BootROM

    • https://fredericb.info/2016/10/amlogic-s905-soc-bypassing-not-so.html#amlogic-s905-soc-bypassing-not-so
  • 高通安全启动与镜像认证技术概述

    • https://www.qualcomm.com/documents/secure-boot-and-image-authentication-technical-overview-v20
  • 攻破三星的信任根 - 利用三星安全启动 (BlackHat 2020)

    • https://teamt5.org/en/posts/blackhat-s-talk-breaking-samsung-s-root-of-trust-exploiting-samsung-secure-boot/
  • 基于 ARM 的 SoC 中安全启动现状概述 (Hardware-Aided Trusted Computing devroom - Maciej Pijanowski- FOSDEM 2021)

    • https://archive.fosdem.org/2021/schedule/event/tee_arm_secboot/attachments/paper/4635/export/events/attachments/tee_arm_secboot/paper/4635/Overview_of_Secure_Boot_in_Arm_based_SoCs.pdf
  • 深入 Android TA 漏洞挖掘与模糊测试 (Kanxue SDC 2023) - https://github.com/guluisacat/MySlides/blob/main/KanxueSDC2023/%E3%80%90%E8%AE%AE%E9%A2%98%E3%80%91%E6%B7%B1%E5%85%A5Android%E5%8F%AF%E4%BF%A1%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E%E6%8C%96%E6%8E%98.pdf

TEE 视频

  • Ekoparty-13 (2017) Daniel Komaromy - 拆解你的手机 - 探索与攻破三星的 TrustZone 沙箱

    • 视频:https://www.youtube.com/watch?v=L2Mo8WcmmZo
    • 幻灯片:https://github.com/puppykitten/tbase/blob/master/unboxyourphone_ekoparty.pdf
  • Daniel Komaromy - 进入骁龙 (2014-10-11)

    • https://www.youtube.com/watch?v=2wJRnewVE-g
  • BSides DC 2018 与 DerbiCon VIII - 正中要害:通过利用 TrustZone 绕过华为指纹认证,作者:Nick Stephens

    • https://www.youtube.com/watch?v=QFFhdqP7Dxg
    • https://www.youtube.com/watch?v=MdoGCXGHGnY
  • 恶龙肆虐:探索 ARM TrustZone 架构中的漏洞,作者:Josh Thomas 和 Charles Holmes,Android 安全研讨会,奥地利维也纳,2015 年 9 月 9-11 日

    • https://www.youtube.com/watch?v=vxNGgOR-iVM
  • Android 与可信执行环境,作者:Jan-Erik Ekberg (Trustonic),Android 安全研讨会,奥地利维也纳,2015 年 9 月 9-11 日

    • https://www.youtube.com/watch?v=5542lEk3OAM
  • 34C3 2017 - 主机安全 - Switch,作者:Plutoo、Derrek 和 Naehrwert

    • https://media.ccc.de/v/34c3-8941-console_security_-_switch
  • 34C3 2017 - 仅有 TrustZone 还不够,作者:Pascal Cotret

    • https://media.ccc.de/v/34c3-8831-trustzone_is_not_enough
  • RootedCON 2017 - 关于可信执行环境,你妈妈从未告诉过你的事...,作者:José A. Rivas

    • 音频为西班牙语原声 https://www.youtube.com/watch?v=lzrIzS84mdk
    • 英文翻译 https://www.youtube.com/watch?v=Lzb5OfE1M7s
  • BH US 2015 - 移动设备上的指纹:滥用与泄露

    • https://www.youtube.com/watch?v=7NkojB9gLXM

针对 TEE 的微架构攻击

  • ARMageddon:针对移动设备的缓存攻击

    • [论文] https://www.usenix.org/system/files/conference/usenixsecurity16/sec16_paper_lipp.pdf
    • [相关工具] https://github.com/IAIK/armageddon
  • 缓存存储信道:别名驱动攻击与经验证的防御措施。

    • https://www.kth.se/polopoly_fs/1.641701.1550155969!/R.Guanciale.pdf
  • 34C3 - 针对可信执行环境的微架构攻击

    • https://media.ccc.de/v/34c3-8950-microarchitectural_attacks_on_trusted_execution_environments
  • TruSpy:ARM 设备上来自安全世界的缓存侧信道信息泄露

    • https://eprint.iacr.org/2016/980.pdf

工具

仿真

  • QEMU 对 Exynos9820 S-Boot 的支持

    • https://github.com/astarasikov/qemu
  • 在 QEMU 中仿真 Exynos 4210 BootROM

    • https://fredericb.info/2018/03/emulating-exynos-4210-bootrom-in-qemu.html#emulating-exynos-4210-bootrom-in-qemu

逆向

  • TZAR 解包器

    • https://gist.github.com/astarasikov/f47cb7f46b5193872f376fa0ea842e4b#file-unpack_startup_tzar-py
  • IDA MCLF 加载器

    • https://github.com/ghassani/mclf-ida-loader
  • Ghidra MCLF 加载器

    • https://github.com/NeatMonster/mclf-ghidra-loader

其他有用资源

  • ARM Trusted Firmware:面向 Cortex A 和 Cortex M 的安全世界参考实现

    • https://www.trustedfirmware.org/
  • OP-TEE:基于 ARM TrustZone 的开源 TEE

    • https://www.op-tee.org/
  • 信任问题:利用 TrustZone TEE,作者:Project Zero 团队

    • https://googleprojectzero.blogspot.com/2017/07/trust-issues-exploiting-trustzone-tees.html
  • Boomerang:利用可信执行环境中的语义鸿沟 (A.Machiry) 2017

    • https://pdfs.semanticscholar.org/f62b/db9f1950329f59dc467238737d2de1a1bac4.pdf (幻灯片)
    • http://sites.cs.ucsb.edu/~cspensky/pdfs/ndss17-final227.pdf (论文)
    • https://github.com/ucsb-seclab/boomerang (工具)
  • TEE 研究 (一些用于 TEE 研究的实用 IDA 和 Ghidra 插件)

    • https://github.com/bkerler/tee_research
下载工具
  • Breaking Bad:回顾 Android (4-9.x) 上的高通 ARM64 TZ 与硬件支持的安全启动

    • https://github.com/bkerler/slides_and_papers/blob/master/QualcommCrypto.pdf
  • 技术公告:从高通硬件支持的密钥库中提取私钥 CVE-2018-11976 (NCC)

    • https://www.nccgroup.trust/us/our-research/private-key-extraction-qualcomm-keystore/
  • 高通 TrustZone 整数符号性缺陷 (12/2014)

    • https://fredericb.info/2014/12/qpsiir-80-qualcomm-trustzone-integer.html
  • 高通 TrustZone 应用模糊测试之路 (RECON Montreal 2019)

    • https://cfp.recon.cx/media/tz_apps_fuzz.pdf
  • 针对 TrustZone 的降级攻击

    • http://ww2.cs.fsu.edu/~ychen/paper/downgradeTZ.pdf
  • 深入剖析三星的 TrustZone

    • (第 1 部分 - 简介) https://blog.quarkslab.com/a-deep-dive-into-samsungs-trustzone-part-1.html
    • (第 2 部分 - TA 模糊测试) https://blog.quarkslab.com/a-deep-dive-into-samsungs-trustzone-part-2.html
    • (第 3 部分 - 利用 EL3) https://blog.quarkslab.com/a-deep-dive-into-samsungs-trustzone-part-3.html
  • No ConName 2015 - (不) 可信执行环境,作者:Pau Oliva

    • 视频:仅西班牙语音频 https://vimeo.com/150787883
    • 幻灯片:https://t.co/vFATxEa7sy
  • BH US 2014 - 关于信任 TrustZone 的反思,作者:Dan Rosenberg

    • https://www.youtube.com/watch?v=7w40mS5yLjc
  • ARM TrustZone 傻瓜教程,作者:Tim Hummels

    • https://www.youtube.com/watch?v=ecBByjwny3s