Skip to main content

Curated list of embedded security tools and resources: firmware analysis, reverse engineering, hardware hacking, IoT security, fuzzing, secure boot, side-channel analysis, and SDR.

56
GitHub Stars
238
Curated Resources
4
Categories
23 hours ago
Last Refreshed
Software ToolsHardware ToolsFurther Learning and TrainingOther Awesome Lists

Use this list with your AI agent

Add the Context Awesome MCP server to Claude, Cursor, or any MCP client, then ask:

"Show me software defined radios resources from awesome-embedded-security"

Installation instructions →

What's inside

Hardware Tools

  • ADALM-PLUTO (PlutoSDR)Software Defined Radios

    Active learning module (PlutoSDR) used to explore software-defined radio, RF experimentation, and wireless communications.

  • AirspySoftware Defined Radios

    Receive-only SDRs with high dynamic range and front-end filtering, covering HF through 1.8 GHz depending on model.

  • Awesome Flipper ZeroRF Tools (Non-SDR)

    A collection of Awesome resources for the Flipper Zero device.

  • bladeRFSoftware Defined Radios

    Full-duplex 2x2 MIMO SDR tuning 47 MHz to 6 GHz, with an on-board FPGA for signal processing at the edge.

  • BruceRF Tools (Non-SDR)

    Powerful open-source ESP32 firmware designed for offensive security and Red Team operations.

  • Bus PirateHardware Reverse Engineering Multitools

    Open source hacker multi-tool that talks to electronic stuff. It's got a bunch of features an intrepid hacker might need to prototype their next project.

Software Tools

  • AFL++Fuzzing Tools

    A coverage-guided fuzzer with enhanced mutations, QEMU and Unicorn emulation modes, and custom power schedules.

  • AMD fTPM Security GuidanceRoot of Trust and TPM

    AMD guidance and security bulletin coverage related to firmware TPM behavior on supported platforms.

  • AMD SEVTEE/Trusted Execution Environments

    Secure Encrypted Virtualization for encrypting VM memory with AMD-V hardware assistance.

  • AngrDisassemblers/Decompilers

    Platform-agnostic binary analysis framework. Brought to you by the Computer Security Lab at UC Santa Barbara, SEFCOM at Arizona State University, their associated CTF team, Shellphish, the open source community, and @rhelmot.

  • Angr ManagementDisassemblers/Decompilers

    Multi-architecture binary analysis toolkit, with the capability to perform dynamic symbolic execution (like Mayhem, KLEE, etc.) and various static analyses on binaries. If you'd like to learn how to use it, you're in the right place!

  • argXtractBinary Parsing and Analysis Tools

    Statically extracts arguments to SVC calls and HAL functions from stripped ARM Cortex-M BLE firmware without symbol tables, enabling security audits of Nordic and similar binaries. ACSAC 2021.

Other Awesome Lists

  • Android Security

    Android reverse engineering, exploitation, and mobile application security tooling.

  • Application Security

    Secure development practices, code analysis, and application security testing.

  • awesome

    The root Awesome list, indexing curated lists across every topic.

  • Awesome Automotive Security

    Vehicle security research covering CAN, ECUs, telematics, and automotive standards.

  • CANbus

    CAN bus tooling, adapters, protocol documentation, and reverse engineering resources.

  • CAN IDs

    Catalogue of decoded CAN bus identifiers and message formats across vehicle makes and models.

Further Learning and Training

  • Common CriteriaStandards and Regulation

    ISO/IEC 15408 security evaluation framework, with the public database of certified products and the protection profiles they were evaluated against.

  • DVID

    Damn Vulnerable IoT Device: open hardware ATmega328p board (Gerbers published) purpose-built for practicing UART extraction, firmware dumping, and Bluetooth sniffing attacks on physical hardware.

  • DVRF

    Damn Vulnerable Router Firmware: modified Linksys firmware containing intentional MIPS/ARM binary exploitation challenges (buffer overflows, format strings, heap bugs) runnable under QEMU without physical hardware.

  • Embeddedsecurity.io

    Beginners resource on embedded systems security.

  • ETSI EN 303 645Standards and Regulation

    Consumer IoT security baseline of 33 provisions, used as the basis for national schemes in the UK, Singapore, Finland, and Australia.

  • EU Cyber Resilience ActStandards and Regulation

    Regulation 2024/2847, setting security requirements and vulnerability reporting obligations for products with digital elements sold in the EU.

Showing a sample of 238 resources. View the full list on GitHub →