awesome-connected-things-sec — Updated!
UpdatedAug 31, 2026A Curated list of Security Resources for all connected thingsSecurity research a 2026-8-31 04:29:49 Author: kitploit.com(查看原文) 阅读量:18 收藏

UpdatedAug 31, 2026

A Curated list of Security Resources for all connected things

Security research and exploitation techniques for IoT, embedded, industrial, and automotive systems.

Awesome

Typing SVG

       

         

     


Contents

Hardware Attacks

Fundamentals

Interface Attacks

UART

JTAG

SWD (Serial Wire Debug)

SPI

I2C

TPM

eMMC

Side-Channel and Fault Injection

Fundamentals

Glitching Attacks

Power Analysis

Other Microcontrollers

PCIe and DMA Attacks


Wireless Protocols

RF Fundamentals

Bluetooth / BLE

Fundamentals

Exploitation Techniques

Vulnerability Research

Conference Talks

Tools - Software

Tools - Hardware

Tools

Hacking Bluetooth Coffee Machines

Zigbee / Z-Wave

Fundamentals

Exploitation

Tools - Software

Tools - Hardware

LoRa / LoRaWAN

Fundamentals

Exploitation

Tools

Matter / Thread

Fundamentals

Security Research

Cellular (GSM/LTE/5G)

Fundamentals

Exploitation

Tools

NFC/RFID

DECT (Digital Enhanced Cordless Telecommunications)


Wi-Fi

Protocol Vulnerabilities

Exploitation

Reverse Engineering WiFi

USB

UWB (Ultra-Wideband)

TETRA


Firmware Security

Fundamentals

Static Analysis Tools

Dynamic Analysis and Emulation

Emulation Tutorials

OTA Update Security

Fundamentals

Attack Vectors

RTOS Security

Zephyr RTOS

FreeRTOS

Reverse Engineering Tools

Reverse Engineering Tutorials

Ghidra Tutorials

Online Assemblers

ARM Exploitation

Binary Analysis

Secure Boot

Development

Bypasses

UEFI Security


Router Firmware Analysis

Router Exploitation

Netgear Series

Cisco Series

Secure Boot Bypasses

Network and Web Protocols

MQTT

Fundamentals

Security and Exploitation

Known CVEs

Tools

Applications

Malware Research

CoAP

Specifications and Security

Tools - Software

Tools - Hardware

Research and Tutorials

mTLS

Tools

| Tool | Use | Link | | ───────────────────────── | ─────────────────────────────────────────────────────────────────────────────────────────────── | ──────────────────────────────────────────────────────────────────────────────────────────────────────── | | mtls-intercept | Reverse proxy that dynamically signs client certs to MITM full mTLS sessions | github.com/fungaren/mtls-intercept | | mitmproxy | Configure client_certs with extracted IoT device cert to impersonate device in mTLS handshake | mitmproxy.org | | SSLsplit | Transparent mTLS proxy - forward extracted device cert to complete mutual handshake with cloud | github.com/droe/sslsplit | | eCapture (eBPF) | Hook OpenSSL/BoringSSL on Linux IoT gateways pre-encrypt - decrypts mTLS + TLS 1.3 + PFS | ecapture.cc | | Wireshark + SSLKEYLOGFILE | Decrypt captured mTLS sessions from IoT gateways using NSS pre-master secret logs | wiki.wireshark.org/TLS | | Frida | Runtime hook SSLContext, TrustManager, KeyManager in Android IoT companion apps | frida.re | | Objection | Android sslpinning disable - strips mTLS pinning in companion apps | github.com/sensepost/objection | | apk-mitm | Statically patches IoT companion APK to disable mTLS cert pinning | github.com/shroudedcode/apk-mitm | | MagiskTrustUserCerts | Moves custom CA to system store on rooted Android POS/kiosk to complete mTLS MITM | github.com/NVISOsecurity/MagiskTrustUserCerts | | frida-multiple-unpinning | Universal Frida script targeting 20+ mTLS/pinning patterns in hardened IoT apps | github.com/httptoolkit/frida-android-unpinning | | NEU-SNS/IoTLS | IMC'21 research repo - SSLKEYLOGFILE files to decrypt MITM'd mTLS connections across 32 devices | github.com/NEU-SNS/IoTLS | | mitmrouter | Linux-based IoT traffic interception router - intercepts device TLS at network level | github.com/nmatt0/mitmrouter |

Blogs & Articles

Research Papers

YouTube

IoT Protocols Overview

Cloud and Backend Security

AWS IoT Security

Fundamentals

Tools

Vulnerabilities

Firebase / Cloud Misconfigurations


Mobile Application Security

Android

Android Kernel Exploitation

Android Scudo Allocator

iOS

Industrial and Automotive

ICS/SCADA

Automotive Security

EV Chargers


Payment Systems

ATM Hacking

Payment Village


Hardware Tools

Multi-Purpose

Debug Adapters

USB

Flipper Zero

  • NullSec Flipper Suite - Flipper Zero payload collection for RF, RFID/NFC, BadUSB, infrared and wireless pentesting.
  • PineFlip - Flipper Zero companion app for Linux with screen mirroring, file manager and firmware management.

Hak5

Software Tools

Exploitation Frameworks

Firmware Analysis


Fuzzing Tools

Fundamentals

IoT-Specific Fuzzing

Tools

Pentesting Operating Systems

Search Engines


Defensive Security

Threat Modeling

STRIDE Framework

IoT-Specific Threat Modeling

Secure Development

Guidelines and Standards

Hardening Guides

Incident Response


Learning Resources

Training Platforms

Cheatsheets

Vulnerability Guides

Pentesting Guides

YouTube Channels

Books

Hardware Hacking

Firmware and Reverse Engineering

IoT Security

Wireless and RF

Embedded and Mobile

NFC/RFID

Automotive Security

Industrial and General Security

White Papers and Reports


IoT Series

Labs and CTFs

Vulnerable Applications

Hardware

Industrial

VoIP

CTF Competitions


Hardware CTFs

IoT CTFs

Embedded/Firmware CTFs

ARM CTFs

Continuous Learning Platforms

Lab Setup


Research and Community

Technical Research

Blogs

Villages

Researchers to Follow


Device-Specific Research

Cameras

Smart Home Devices

Smart Speakers

Printers

Drones

Kitchen Appliances

NAS Devices

Game Consoles

Phones/Tablets

TrustZone and TEE Research

Pwn2Own Research


MCP / AI Agent

Bluetooth Reverse Engineering

  • bt-re-mad-skillz - LLM skills for Bluetooth Controller firmware RE at the HCI layer, for Claude Code and ChatGPT/Codex.

Contributing

Contributions welcome. Submit a PR with new resources following the existing structure.

Read more

Categories


文章来源: https://kitploit.com/en/posts/github-v33ru-awesome-connected-things-sec-ff4329506e2824e3a8d548a915502c7d841d9963f187e8366985aaafd54fa212
如有侵权请联系:admin#unsafe.sh