awesome-connected-things-sec — Updated!
UpdatedAug 31, 2026A Curated list of Security Resources for all connected thingsSecurity research a
2026-8-31 04:29:49
Author: kitploit.com(查看原文)
阅读量:10
收藏

UpdatedAug 31, 2026
A Curated list of Security Resources for all connected things
Security research and exploitation techniques for IoT, embedded, industrial, and automotive systems.
Contents
Hardware Attacks
Fundamentals
Interface Attacks
UART
JTAG
SWD (Serial Wire Debug)
SPI
I2C
TPM
eMMC
Side-Channel and Fault Injection
Fundamentals
Glitching Attacks
Power Analysis
Other Microcontrollers
PCIe and DMA Attacks
Wireless Protocols
RF Fundamentals
Bluetooth / BLE
Fundamentals
Exploitation Techniques
Vulnerability Research
Conference Talks
Hacking Bluetooth Coffee Machines
Zigbee / Z-Wave
Fundamentals
Exploitation
LoRa / LoRaWAN
Fundamentals
Exploitation
Matter / Thread
Fundamentals
Security Research
Cellular (GSM/LTE/5G)
Fundamentals
Exploitation
NFC/RFID
DECT (Digital Enhanced Cordless Telecommunications)
Wi-Fi
Protocol Vulnerabilities
Exploitation
Reverse Engineering WiFi
USB
UWB (Ultra-Wideband)
TETRA
Firmware Security
Fundamentals
Dynamic Analysis and Emulation
Emulation Tutorials
OTA Update Security
Fundamentals
Attack Vectors
RTOS Security
Zephyr RTOS
FreeRTOS
Reverse Engineering Tutorials
Ghidra Tutorials
Online Assemblers
ARM Exploitation
Binary Analysis
Secure Boot
Development
Bypasses
UEFI Security
Symlink Attacks
Router Firmware Analysis
Router Exploitation
Netgear Series
TP-Link Series
Cisco Series
Secure Boot Bypasses
Network and Web Protocols
MQTT
Fundamentals
Security and Exploitation
Known CVEs
Applications
Malware Research
CoAP
Specifications and Security
Research and Tutorials
mTLS
| Tool | Use | Link |
| ───────────────────────── | ─────────────────────────────────────────────────────────────────────────────────────────────── | ──────────────────────────────────────────────────────────────────────────────────────────────────────── |
| mtls-intercept | Reverse proxy that dynamically signs client certs to MITM full mTLS sessions | github.com/fungaren/mtls-intercept |
| mitmproxy | Configure client_certs with extracted IoT device cert to impersonate device in mTLS handshake | mitmproxy.org |
| SSLsplit | Transparent mTLS proxy - forward extracted device cert to complete mutual handshake with cloud | github.com/droe/sslsplit |
| eCapture (eBPF) | Hook OpenSSL/BoringSSL on Linux IoT gateways pre-encrypt - decrypts mTLS + TLS 1.3 + PFS | ecapture.cc |
| Wireshark + SSLKEYLOGFILE | Decrypt captured mTLS sessions from IoT gateways using NSS pre-master secret logs | wiki.wireshark.org/TLS |
| Frida | Runtime hook SSLContext, TrustManager, KeyManager in Android IoT companion apps | frida.re |
| Objection | Android sslpinning disable - strips mTLS pinning in companion apps | github.com/sensepost/objection |
| apk-mitm | Statically patches IoT companion APK to disable mTLS cert pinning | github.com/shroudedcode/apk-mitm |
| MagiskTrustUserCerts | Moves custom CA to system store on rooted Android POS/kiosk to complete mTLS MITM | github.com/NVISOsecurity/MagiskTrustUserCerts |
| frida-multiple-unpinning | Universal Frida script targeting 20+ mTLS/pinning patterns in hardened IoT apps | github.com/httptoolkit/frida-android-unpinning |
| NEU-SNS/IoTLS | IMC'21 research repo - SSLKEYLOGFILE files to decrypt MITM'd mTLS connections across 32 devices | github.com/NEU-SNS/IoTLS |
| mitmrouter | Linux-based IoT traffic interception router - intercepts device TLS at network level | github.com/nmatt0/mitmrouter |
Blogs & Articles
Research Papers
YouTube
IoT Protocols Overview
Cloud and Backend Security
AWS IoT Security
Fundamentals
Vulnerabilities
Firebase / Cloud Misconfigurations
Mobile Application Security
Android
Android Kernel Exploitation
Android Scudo Allocator
iOS
Industrial and Automotive
ICS/SCADA
Automotive Security
EV Chargers
Payment Systems
ATM Hacking
Payment Village
Multi-Purpose
Debug Adapters
USB
Flipper Zero
- NullSec Flipper Suite - Flipper Zero payload collection for RF, RFID/NFC, BadUSB, infrared and wireless pentesting.
- PineFlip - Flipper Zero companion app for Linux with screen mirroring, file manager and firmware management.
Hak5
Exploitation Frameworks
Firmware Analysis
Fundamentals
IoT-Specific Fuzzing
Pentesting Operating Systems
Search Engines
Defensive Security
Threat Modeling
STRIDE Framework
IoT-Specific Threat Modeling
Secure Development
Guidelines and Standards
Hardening Guides
Incident Response
Learning Resources
Cheatsheets
Vulnerability Guides
Pentesting Guides
YouTube Channels
Books
Hardware Hacking
Firmware and Reverse Engineering
IoT Security
Wireless and RF
Embedded and Mobile
NFC/RFID
Automotive Security
Industrial and General Security
White Papers and Reports
IoT Series
Labs and CTFs
Vulnerable Applications
Hardware
Industrial
VoIP
CTF Competitions
Hardware CTFs
IoT CTFs
Embedded/Firmware CTFs
ARM CTFs
Lab Setup
Research and Community
Technical Research
Blogs
Villages
Researchers to Follow
Device-Specific Research
Cameras
Smart Home Devices
Smart Speakers
Printers
Drones
Kitchen Appliances
NAS Devices
Game Consoles
Phones/Tablets
TrustZone and TEE Research
Pwn2Own Research
MCP / AI Agent
Bluetooth Reverse Engineering
- bt-re-mad-skillz - LLM skills for Bluetooth Controller firmware RE at the HCI layer, for Claude Code and ChatGPT/Codex.
Contributing
Contributions welcome. Submit a PR with new resources following the existing structure.
Read more
文章来源: https://kitploit.com/en/posts/github-v33ru-awesome-connected-things-sec-ff4329506e2824e3a8d548a915502c7d841d9963f187e8366985aaafd54fa212
如有侵权请联系:admin#unsafe.sh