IoT and embedded penetration testing
Full device analysis: hardware, firmware, communication and update processes. I look for the paths a real attacker would take to own the device or its data.
- Hardware analysis: debug interfaces, memory, secure boot protections
- Firmware extraction and analysis, hunting for secrets and weak mechanisms
- Wired and wireless communication, including pairing mechanisms
- Over-the-air update process and image signing
- Report with CVSS 3.1 ratings and concrete remediation steps