A Curated list of Security Resources for all connected things
-
Updated
Aug 29, 2026
A Curated list of Security Resources for all connected things
Platform Security Assessment Framework
Firmware security research platform combining binary analysis, taint tracing, and emulation across IoT, edge AI, mobile devices, and robotics.
IoTGoat is a deliberately insecure firmware created to educate software developers and security professionals with testing commonly found vulnerabilities in IoT devices.
Autonomous AI pentesting engine across web, cloud, identity, CI/CD, IaC, databases, Active Directory, Kubernetes, IoT firmware and AI/LLM endpoints (OWASP LLM Top 10). Real exploits with proof for every finding. Privacy gateway: the LLM never sees your real IPs, hosts or creds; nothing leaves your perimeter.
D-Link firmware decryption PoC
Firmware Guide
Openwrt 18.06.5 featured with the Exein's security framework
Self-hosted, agentic vulnerability research for binaries & firmware: an AI agent decompiles, fuzzes, and verifies exploits inside a sandbox, recording every finding to a typed graph. BYOK, fully local.
Offline security checklist & report generator
Deterministic firmware-to-exploit evidence engine. Drop a firmware blob, get hash-anchored findings with SARIF + CycloneDX SBOM + verified exploit chains.
Cross-distribution Linux system-maintenance and supply-chain tool — pure-stdlib Python, zero runtime dependencies. Arch/Manjaro, Debian/Ubuntu and the RHEL family: update, audit where software came from, check hardening, scan the firmware and boot chain.
A simple 16-bit RISC CPU written from scratch in C. topics: cpu risc virtual-machine c computer-architecture systems-programming emulator
Bootloader for tinyAVR 0-, 1- and 2-series, and megaAVR 0-series, supporting signed and encrypted firmware loaded from external I2C memory.
Designing and implementing UEFI bootkits capable of hijacking the boot process and subverting kernel integrity on Windows and Linux.
Lab about hacking, vulnerabilities exploitation, ...
FirmHound 固件猎犬:IoT 固件漏洞挖掘自动化流水线(挑战杯揭榜挂帅·网络安全赛题第一队作品)。解包→攻击面→二进制分析→静态审计→十维评分→反证验证→动态验证→证据报告。
Bare-metal secure bootloader for STM32F407 with AES-GCM encrypted transfer, ECDSA signature verification and anti-rollback protection
CVE-2021-21735 write-up: ZTE ZXHN H168N V3.5 wizard-page information leak, firmware routing flaw, and the path from exposed PPPoE/WLAN data to full admin compromise.
Original research and non-destructive PoC for an unauthenticated firmware update vulnerability with missing cryptographic firmware authentication in Netis NC63
To associate your repository with the firmware-security topic, visit your repo's landing page and select "manage topics."