Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
owasp-istg — The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt innovations, and developments in the IoT market while still ensuring comparability of test results. | Kitploit
工具/GitHubGitHub/owasp/owasp-istg
Embedded Systems SecurityIoT SecurityVulnerability AnalysisWeb SecurityWireless SecurityHardware HackingPenetration TestingMobile SecurityHardware SecurityLearning & EducationCurated ResourcesFirmware Analysis
12726118天前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
GitHubowasp/owasp-istg

owasp-istg

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt innovations, and developments in the IoT market while still ensuring comparability of test results.

查看仓库网站
内容在请求的语言中不可用。显示英文版本。

OWASP IoT Security Testing Guide

CC BY-SA 4.0 OpenSSF Best Practices

The OWASP IoT Security Testing Guide provides a comprehensive methodology for penetration tests in the IoT field offering flexibility to adapt innovations and developments on the IoT market while still ensuring comparability of test results. The guide provides an understanding of communication between manufacturers and operators of IoT devices as well as penetration testing teams that’s facilitated by establishing a common terminology.

Security assurance and test coverage can be demonstrated with the overview of IoT components and test case categories applicable to each below. The methodology, underlying models, and catalog of test cases present tools that can be used separately and in conjunction with each other.

Component Overview

  • 🔔Click here to read the OWASP ISTG 📖📚🔔
  • ✅ Get the latest ISTG Checklists✅
  • 📝 🔍 Contribute to ISTG — see also the contribution guidelines for the conventions used in this repository

Table of Contents

  1. Introduction

  2. IoT Security Testing Framework

    2.1. IoT Device Model

    2.2. Attacker Model

    2.3. Testing Methodology

  3. Test Case Catalog

    3.1. Processing Units (ISTG-PROC)

    3.2. Memory (ISTG-MEM)

    3.3. Firmware (ISTG-FW)

    3.3.1. Installed Firmware (ISTG-FW[INST])

    3.3.1. Firmware Update Mechnanism (ISTG-FW[UPDT])

    3.4. Data Exchange Services (ISTG-DES)

    3.5. Internal Interfaces (ISTG-INT)

    3.5.1. Inter-Integrated Circuit (ISTG-INT[I2C])

    3.5.2. Universal Asynchronous Receiver-Transmitter (ISTG-INT[UART])

    3.6. Physical Interfaces (ISTG-PHY)

    3.7. Wireless Interfaces (ISTG-WRLS)

Related Work

The concepts, models and test steps presented in the OWASP IoT Security Testing Guide are based on the master's thesis "Development of a Methodology for Penetration Tests of Devices in the Field of the Internet of Things" by Luca Pascal Rotsch.

Test cases were derived from the following public sources:

  • OWASP "Web Security Testing Guide"
  • OWASP "Firmware Security Testing Methodology"
  • OWASP "Mobile Security Testing Guide"
  • "IoT Pentesting Guide" by Aditya Gupta
  • "IoT Penetration Testing Cookbook" by Aaron Guzman and Aditya Gupta
  • "The IoT Hacker's Handbook" by Aditya Gupta
  • "Practical IoT Hacking" by Fotios Chantzis, Ioannis Stais, Paulino Calderon, Evangelos Deirmentzoglou, and Beau Woods
  • further sources are referenced in the respective test cases

We also like to thank our collaborators and supporters (see Project Collaborators and Acknowledgements)!

下载工具

3.8. User Interfaces (ISTG-UI)