V33RU/awesome-connected-things-sec

A Curated list of Security Resources for all connected things

3,530

stars

722

commits

Aug 29, 2026

updated

v33ru.github.io/awesome-connected-things-sec/
automotive-security
awesome
awesome-list
ble-security
bluetooth-security
embedded-security
firmware-analysis
firmware-security
hardware-hacking
ics-security
iot-pentesting
iot-security
reverse-engineering
rf-security
wireless-security

README

🔐 Awesome Connected Things Security Resources

A curated repository of IoT, Embedded, Industrial & Automotive, Core Tech security knowledge.

Awesome

Typing SVG


       


         


     


Table of Contents

Hardware Attacks

Fundamentals

Interface Attacks

UART

JTAG

SWD (Serial Wire Debug)

SPI

I2C

TPM

Memory Extraction

eMMC

Side-Channel and Fault Injection

Fundamentals

Glitching Attacks

Power Analysis

Other Microcontrollers

PCIe and DMA Attacks


Wireless Protocols

RF Fundamentals

Bluetooth / BLE

Fundamentals

Exploitation Techniques

Vulnerability Research

Conference Talks

Tools - Software

Tools - Hardware

Tools

Hacking Bluetooth Coffee Machines

Zigbee / Z-Wave

Fundamentals

Exploitation

Tools - Software

Tools - Hardware

LoRa / LoRaWAN

Fundamentals

Exploitation

Tools

Matter / Thread

Fundamentals

Security Research

Cellular (GSM/LTE/5G)

Fundamentals

Exploitation

Tools

NFC/RFID

DECT (Digital Enhanced Cordless Telecommunications)


Wi-Fi

Protocol Vulnerabilities

Exploitation

Reverse Engineering WiFi

USB

UWB (Ultra-Wideband)

TETRA


Firmware Security

Fundamentals

Extraction

Static Analysis Tools

Dynamic Analysis and Emulation

Emulation Tutorials

OTA Update Security

Fundamentals

Attack Vectors

RTOS Security

Zephyr RTOS

FreeRTOS

Reverse Engineering Tools

Reverse Engineering Tutorials

Ghidra Tutorials

Online Assemblers

ARM Exploitation

Binary Analysis

Secure Boot

Development

Bypasses

UEFI Security


Router Firmware Analysis

Router Exploitation

Netgear Series

Cisco Series

Secure Boot Bypasses

Network and Web Protocols

MQTT

Fundamentals

Security and Exploitation

Known CVEs

Tools

Applications

Malware Research

CoAP

Specifications and Security

Tools - Software

Tools - Hardware

Research and Tutorials

mTLS

Tools

ToolUseLink
mtls-interceptReverse proxy that dynamically signs client certs to MITM full mTLS sessionsgithub.com/fungaren/mtls-intercept
mitmproxyConfigure client_certs with extracted IoT device cert to impersonate device in mTLS handshakemitmproxy.org
SSLsplitTransparent mTLS proxy - forward extracted device cert to complete mutual handshake with cloudgithub.com/droe/sslsplit
eCapture (eBPF)Hook OpenSSL/BoringSSL on Linux IoT gateways pre-encrypt - decrypts mTLS + TLS 1.3 + PFSecapture.cc
Wireshark + SSLKEYLOGFILEDecrypt captured mTLS sessions from IoT gateways using NSS pre-master secret logswiki.wireshark.org/TLS
FridaRuntime hook SSLContext, TrustManager, KeyManager in Android IoT companion appsfrida.re
Objectionandroid sslpinning disable - strips mTLS pinning in companion appsgithub.com/sensepost/objection
apk-mitmStatically patches IoT companion APK to disable mTLS cert pinninggithub.com/shroudedcode/apk-mitm
MagiskTrustUserCertsMoves custom CA to system store on rooted Android POS/kiosk to complete mTLS MITMgithub.com/NVISOsecurity/MagiskTrustUserCerts
frida-multiple-unpinningUniversal Frida script targeting 20+ mTLS/pinning patterns in hardened IoT appsgithub.com/httptoolkit/frida-android-unpinning
NEU-SNS/IoTLSIMC'21 research repo - SSLKEYLOGFILE files to decrypt MITM'd mTLS connections across 32 devicesgithub.com/NEU-SNS/IoTLS
mitmrouterLinux-based IoT traffic interception router - intercepts device TLS at network levelgithub.com/nmatt0/mitmrouter

Blogs & Articles

Research Papers

YouTube

IoT Protocols Overview

Cloud and Backend Security

AWS IoT Security

Fundamentals

Tools

Vulnerabilities

Firebase / Cloud Misconfigurations


Mobile Application Security

Android

Android Kernel Exploitation

Android Scudo Allocator

iOS

Industrial and Automotive

ICS/SCADA

Automotive Security

EV Chargers


Payment Systems

ATM Hacking

Payment Village


Tools

Hardware Tools

Multi-Purpose

Debug Adapters

USB

Flipper Zero

  • NullSec Flipper Suite - Flipper Zero payload collection for RF, RFID/NFC, BadUSB, infrared and wireless pentesting.
  • PineFlip - Flipper Zero companion app for Linux with screen mirroring, file manager and firmware management.

Hak5

Software Tools

Exploitation Frameworks

Firmware Analysis


Fuzzing Tools

Fundamentals

IoT-Specific Fuzzing

Tools

Pentesting Operating Systems

Search Engines


Defensive Security

Threat Modeling

STRIDE Framework

IoT-Specific Threat Modeling

Secure Development

Guidelines and Standards

Hardening Guides

Incident Response


Learning Resources

Training Platforms

Cheatsheets

Vulnerability Guides

Pentesting Guides

YouTube Channels

Books

Hardware Hacking

Firmware and Reverse Engineering

IoT Security

Wireless and RF

Embedded and Mobile

NFC/RFID

Automotive Security

Industrial and General Security

White Papers and Reports


IoT Series

Labs and CTFs

Vulnerable Applications

Hardware

Industrial

VoIP

CTF Competitions


Hardware CTFs

IoT CTFs

Embedded/Firmware CTFs

ARM CTFs

Continuous Learning Platforms

Lab Setup


Research and Community

Technical Research

Blogs

Community Platforms

Villages

Researchers to Follow


Device-Specific Research

Cameras

Smart Home Devices

Smart Speakers

Printers

Drones

Kitchen Appliances

NAS Devices

Game Consoles

Phones/Tablets

TrustZone and TEE Research

Pwn2Own Research


MCP / AI Agent

Bluetooth Reverse Engineering

  • bt-re-mad-skillz - LLM skills for Bluetooth Controller firmware RE at the HCI layer, for Claude Code and ChatGPT/Codex.

Contributing

Contributions welcome. Submit a PR with new resources following the existing structure.

License

This collection is provided for educational and research purposes.

Contributors

V33RU

689 commits

falcnix

11 commits

9lyph

4 commits

dsopas

2 commits

V33RU/awesome-connected-things-sec

A Curated list of Security Resources for all connected things

3,530

stars

722

commits

Aug 29, 2026

updated

v33ru.github.io/awesome-connected-things-sec/
automotive-security
awesome
awesome-list
ble-security
bluetooth-security
embedded-security
firmware-analysis
firmware-security
hardware-hacking
ics-security
iot-pentesting
iot-security
reverse-engineering
rf-security
wireless-security

README

🔐 Awesome Connected Things Security Resources

A curated repository of IoT, Embedded, Industrial & Automotive, Core Tech security knowledge.

Awesome

Typing SVG


       


         


     


Table of Contents

Hardware Attacks

Fundamentals

Interface Attacks

UART

JTAG

SWD (Serial Wire Debug)

SPI

I2C

TPM

Memory Extraction

eMMC

Side-Channel and Fault Injection

Fundamentals

Glitching Attacks

Power Analysis

Other Microcontrollers

PCIe and DMA Attacks


Wireless Protocols

RF Fundamentals

Bluetooth / BLE

Fundamentals

Exploitation Techniques

Vulnerability Research

Conference Talks

Tools - Software

Tools - Hardware

Tools

Hacking Bluetooth Coffee Machines

Zigbee / Z-Wave

Fundamentals

Exploitation

Tools - Software

Tools - Hardware

LoRa / LoRaWAN

Fundamentals

Exploitation

Tools

Matter / Thread

Fundamentals

Security Research

Cellular (GSM/LTE/5G)

Fundamentals

Exploitation

Tools

NFC/RFID

DECT (Digital Enhanced Cordless Telecommunications)


Wi-Fi

Protocol Vulnerabilities

Exploitation

Reverse Engineering WiFi

USB

UWB (Ultra-Wideband)

TETRA


Firmware Security

Fundamentals

Extraction

Static Analysis Tools

Dynamic Analysis and Emulation

Emulation Tutorials

OTA Update Security

Fundamentals

Attack Vectors

RTOS Security

Zephyr RTOS

FreeRTOS

Reverse Engineering Tools

Reverse Engineering Tutorials

Ghidra Tutorials

Online Assemblers

ARM Exploitation

Binary Analysis

Secure Boot

Development

Bypasses

UEFI Security


Router Firmware Analysis

Router Exploitation

Netgear Series

Cisco Series

Secure Boot Bypasses

Network and Web Protocols

MQTT

Fundamentals

Security and Exploitation

Known CVEs

Tools

Applications

Malware Research

CoAP

Specifications and Security

Tools - Software

Tools - Hardware

Research and Tutorials

mTLS

Tools

ToolUseLink
mtls-interceptReverse proxy that dynamically signs client certs to MITM full mTLS sessionsgithub.com/fungaren/mtls-intercept
mitmproxyConfigure client_certs with extracted IoT device cert to impersonate device in mTLS handshakemitmproxy.org
SSLsplitTransparent mTLS proxy - forward extracted device cert to complete mutual handshake with cloudgithub.com/droe/sslsplit
eCapture (eBPF)Hook OpenSSL/BoringSSL on Linux IoT gateways pre-encrypt - decrypts mTLS + TLS 1.3 + PFSecapture.cc
Wireshark + SSLKEYLOGFILEDecrypt captured mTLS sessions from IoT gateways using NSS pre-master secret logswiki.wireshark.org/TLS
FridaRuntime hook SSLContext, TrustManager, KeyManager in Android IoT companion appsfrida.re
Objectionandroid sslpinning disable - strips mTLS pinning in companion appsgithub.com/sensepost/objection
apk-mitmStatically patches IoT companion APK to disable mTLS cert pinninggithub.com/shroudedcode/apk-mitm
MagiskTrustUserCertsMoves custom CA to system store on rooted Android POS/kiosk to complete mTLS MITMgithub.com/NVISOsecurity/MagiskTrustUserCerts
frida-multiple-unpinningUniversal Frida script targeting 20+ mTLS/pinning patterns in hardened IoT appsgithub.com/httptoolkit/frida-android-unpinning
NEU-SNS/IoTLSIMC'21 research repo - SSLKEYLOGFILE files to decrypt MITM'd mTLS connections across 32 devicesgithub.com/NEU-SNS/IoTLS
mitmrouterLinux-based IoT traffic interception router - intercepts device TLS at network levelgithub.com/nmatt0/mitmrouter

Blogs & Articles

Research Papers

YouTube

IoT Protocols Overview

Cloud and Backend Security

AWS IoT Security

Fundamentals

Tools

Vulnerabilities

Firebase / Cloud Misconfigurations


Mobile Application Security

Android

Android Kernel Exploitation

Android Scudo Allocator

iOS

Industrial and Automotive

ICS/SCADA

Automotive Security

EV Chargers


Payment Systems

ATM Hacking

Payment Village


Tools

Hardware Tools

Multi-Purpose

Debug Adapters

USB

Flipper Zero

  • NullSec Flipper Suite - Flipper Zero payload collection for RF, RFID/NFC, BadUSB, infrared and wireless pentesting.
  • PineFlip - Flipper Zero companion app for Linux with screen mirroring, file manager and firmware management.

Hak5

Software Tools

Exploitation Frameworks

Firmware Analysis


Fuzzing Tools

Fundamentals

IoT-Specific Fuzzing

Tools

Pentesting Operating Systems

Search Engines


Defensive Security

Threat Modeling

STRIDE Framework

IoT-Specific Threat Modeling

Secure Development

Guidelines and Standards

Hardening Guides

Incident Response


Learning Resources

Training Platforms

Cheatsheets

Vulnerability Guides

Pentesting Guides

YouTube Channels

Books

Hardware Hacking

Firmware and Reverse Engineering

IoT Security

Wireless and RF

Embedded and Mobile

NFC/RFID

Automotive Security

Industrial and General Security

White Papers and Reports


IoT Series

Labs and CTFs

Vulnerable Applications

Hardware

Industrial

VoIP

CTF Competitions


Hardware CTFs

IoT CTFs

Embedded/Firmware CTFs

ARM CTFs

Continuous Learning Platforms

Lab Setup


Research and Community

Technical Research

Blogs

Community Platforms

Villages

Researchers to Follow


Device-Specific Research

Cameras

Smart Home Devices

Smart Speakers

Printers

Drones

Kitchen Appliances

NAS Devices

Game Consoles

Phones/Tablets

TrustZone and TEE Research

Pwn2Own Research


MCP / AI Agent

Bluetooth Reverse Engineering

  • bt-re-mad-skillz - LLM skills for Bluetooth Controller firmware RE at the HCI layer, for Claude Code and ChatGPT/Codex.

Contributing

Contributions welcome. Submit a PR with new resources following the existing structure.

License

This collection is provided for educational and research purposes.

Contributors

V33RU

689 commits

falcnix

11 commits

9lyph

4 commits

dsopas

2 commits