Following the Instructions: Live ARM Tracing with the ETM, ITM, and TPIU

ARM Cortex-M CPUs ship with a set of on-chip trace peripherals that most developers never touch and most reverse engineers forget exist. In this post, we'll wire up an Xbox One controller, configure the ETM and TPIU from OpenOCD, and capture a live instruction trace with nothing more than a logic analyzer and Pulseview - then use Ghidra to figure out why the trace keeps dying.

more ...


SCPI and Hardware Instrumentation for Reverse Engineers - Part 1

Oscilloscopes, power supplies, and multimeters are all quintessential tools in the hardware hacker's toolbox. While many of us know how to configure these tools manually, I have found that security researchers often overlook the need for remote instrumentation. In this post, we'll outline some basic, practical examples of using SCPI and VISA to instrument the hardware in your lab.

more ...




JTAG Hacking with a Raspberry Pi

With this blog post, we'll introduce the PiFex, a basic companion board for the Raspberry Pi designed to teach users the basics of hardware hacking and embedded protocols. We will then demonstrate how to use the PiFex to access a JTAG tap on an undocumented SSD, allowing memory reads and GDB access to the SSD CPU.

more ...


Intro to Embedded RE: UART Discovery and Firmware Extraction via UBoot

This blog entry aims to familiarize readers with locating an active UART on a target system, how to approach a UBoot console, and ultimately how to leverage both of these components to extract the flash memory from our target. After reading this, readers will be familiar with the screen utility the depthcharge python3 libraries.

more ...

Intro to Embedded Reverse Engineering: Tools and Series Overview

This post reviews some of the tools needed when setting up a lab for reverse engineering embedded systems. There will be two sections, one for hardware tools and one for software tools. After reading this blog post, the reader should know what is needed to set up an introductory lab for reverse engineering embedded systems and firmware images.

more ...