CESH 130 PCB RE: Firmware Extraction & Hardware Attacks
Exploiting · 5 days · Assessed
Exploiting · 5 days · Assessed
This is the firmware extraction and hardware attack course in the PCB reverse engineering pathway. Students learn how to take a mapped target board and choose a practical route to recover firmware or gain useful access through exposed hardware paths. The focus is controlled execution: selecting the right interface, wiring it correctly, diagnosing failures, and preserving the target where possible.
Students assess the available routes through debug interfaces, service consoles, bootloaders, in-situ memory access, SPI flash, eMMC, removable storage and chip-off readout. They discover and interact with UART consoles, connect to JTAG and SWD where available, assess access control, interrupt and abuse bootloaders, dump memory devices, and verify extracted images.
Throughout the course, students use an execute, iterate and diagnose method: make a controlled attempt, observe the result, refine the setup, and avoid turning uncertainty into damage. By the end, they can recover firmware from realistic targets, document the method clearly, and hand a verified image into the firmware reverse engineering workflow.
Want to know what to expect in the classroom? Find out more about our training approach and how we turn technical concepts into practical, hands-on skills.
This list shows the various main topics we cover during the course:
A trainee learns to take a board from sealed product to firmware image using the interface that suits the target, which is the single most useful hardware skill in most security teams. It means your new entrants can feed the firmware analysts directly, rather than the team depending on a handful of people who know how to get an image out.
An experienced engineer widens their extraction repertoire across in-situ, SPI, eMMC and chip-off, and gains a first, honest footing in glitching and side-channel work. For your organisation that means fewer targets written off as too hard, and a clearer sense of when to escalate to the deeper fault-injection courses.
This course is for hardware security professionals and reverse engineering trainees who are ready to move from understanding a board to actively extracting firmware and accessing exposed hardware interfaces. Familiarity with PCB analysis and basic bench techniques is recommended, particularly identifying components, interfaces and test points.
Not sure where you fit? Find out more about our training audience and prerequisites.
You will need a laptop with at least 8GB RAM preferably 16GB, an up to date and stable Operating System, and an Ethernet port / reliable Ethernet dongle.
This laptop must be fully under your control such that you can install tools, dependencies and run arbitrary code. It is often useful to have the ability to run virtual machines and any that we provide will be suitable for importing into VirtualBox. If you use a different hypervisor, ensure that you are confident about importing VMs from OVF file formats. Unfortunately we are unable to pause the course for technical difficulties as a result of the amount of material that we need to cover.
We will use a number of other tools during the course. We put together a goodie bag which directly relates to the activities in the course. The free goodie bag is yours to keep at the end of the course, just make sure you have enough luggage space to take it home. The exact details of what is in it will vary depending on availability but we always make it a useful and interesting collection. We provide any other tools needed to complete all the tasks set, aside from a laptop.
You don’t need to bring anything extra other than your enthusiasm!
The classroom is well appointed, has good WiFi and hot and cold drinks, it’s spacious, comfortable, has plenty of power sockets, lots of natural light, and is wheelchair friendly. The course is delivered in English and digital versions of slides and handouts will be provided where appropriate.
Lunch and morning and afternoon snacks are provided so please make sure you let us know about any dietary needs at least a week before we get started. With the exception of the social night, all other meals are for you to organise. We suggest getting a hotel that provides breakfast, and there are many good restaurants in Manchester for your evening meals. We will try and facilitate additional social arrangements, but, this is down to the individuals present.
There are a number of good and affordable hotels in the Manchester area. We are based in an area called Media City and we are in the same complex as the northern headquarters of the BBC. This means that there are lots of facilities locally and you could choose to not venture into the city centre.
If you do choose to look further around there are good tram links that can take you into the city as well as to key travel hubs such as Piccadilly, the national railway station, and Manchester International Airport.
Please check the weather before you travel and bring suitable clothes for the season. If in doubt, assume you will need a waterproof coat and an umbrella. The locals will tell you that Manchester is one of the rainiest places in the world, its not actually true but it does drizzle more than you might expect, even in summer.
Learn how to take a mapped target board and choose, execute and troubleshoot the right extraction route. Over five days, you’ll work with debug interfaces, bootloaders and memory devices to recover and verify firmware while preserving the target wherever possible.