Back to Courses

CESH 130 PCB RE: Firmware Extraction & Hardware Attacks

Exploiting · 5 days · Assessed

BG

About the course

This is the firmware extraction and hardware attack course in the PCB reverse engineering pathway. Students learn how to take a mapped target board and choose a practical route to recover firmware or gain useful access through exposed hardware paths. The focus is controlled execution: selecting the right interface, wiring it correctly, diagnosing failures, and preserving the target where possible.

Students assess the available routes through debug interfaces, service consoles, bootloaders, in-situ memory access, SPI flash, eMMC, removable storage and chip-off readout. They discover and interact with UART consoles, connect to JTAG and SWD where available, assess access control, interrupt and abuse bootloaders, dump memory devices, and verify extracted images.

Throughout the course, students use an execute, iterate and diagnose method: make a controlled attempt, observe the result, refine the setup, and avoid turning uncertainty into damage. By the end, they can recover firmware from realistic targets, document the method clearly, and hand a verified image into the firmware reverse engineering workflow.

Want to know what to expect in the classroom? Find out more about our training approach and how we turn technical concepts into practical, hands-on skills.

Skills and topics covered

This list shows the various main topics we cover during the course:

  • Hardware attack planning from a board map
  • Firmware extraction route selection
  • Defence assessment for debug and memory access
  • UART console discovery and interaction
  • JTAG and SWD discovery, connection and access checks
  • Bootloader identification, interruption and abuse
  • In-situ flash extraction workflows
  • SPI flash identification, wiring and dumping
  • eMMC identification, connection and readout strategy
  • Removable storage and exposed memory recovery
  • Chip-off readout decision-making and execution
  • Firmware image verification and integrity checks
  • Diagnosing failed reads, bad wiring and target-state issues
  • Recovery planning before destructive or high-risk actions
  • Evidence capture for repeatable extraction work
  • Producing a verified firmware image for later analysis

What will a new trainee gain?

A trainee learns to take a board from sealed product to firmware image using the interface that suits the target, which is the single most useful hardware skill in most security teams. It means your new entrants can feed the firmware analysts directly, rather than the team depending on a handful of people who know how to get an image out.

What will an experienced team member gain?

An experienced engineer widens their extraction repertoire across in-situ, SPI, eMMC and chip-off, and gains a first, honest footing in glitching and side-channel work. For your organisation that means fewer targets written off as too hard, and a clearer sense of when to escalate to the deeper fault-injection courses.

Who this course is for

This course is for hardware security professionals and reverse engineering trainees who are ready to move from understanding a board to actively extracting firmware and accessing exposed hardware interfaces. Familiarity with PCB analysis and basic bench techniques is recommended, particularly identifying components, interfaces and test points.

Not sure where you fit? Find out more about our training audience and prerequisites.

Required equipment, tools, and software

You will need a laptop with at least 8GB RAM preferably 16GB, an up to date and stable Operating System, and an Ethernet port / reliable Ethernet dongle.

This laptop must be fully under your control such that you can install tools, dependencies and run arbitrary code.  It is often useful to have the ability to run virtual machines and any that we provide will be suitable for importing into VirtualBox.  If you use a different hypervisor, ensure that you are confident about importing VMs from OVF file formats.  Unfortunately we are unable to pause the course for technical difficulties as a result of the amount of material that we need to cover.

We will use a number of other tools during the course.  We put together a goodie bag which directly relates to the activities in the course.  The free goodie bag is yours to keep at the end of the course, just make sure you have enough luggage space to take it home. The exact details of what is in it will vary depending on availability but we always make it a useful and interesting collection.  We provide any other tools needed to complete all the tasks set, aside from a laptop.

You don’t need to bring anything extra other than your enthusiasm!

Venue and travel information

The classroom

The classroom is well appointed, has good WiFi and hot and cold drinks, it’s spacious, comfortable, has plenty of power sockets, lots of natural light, and is wheelchair friendly. The course is delivered in English and digital versions of slides and handouts will be provided where appropriate.

Food and refreshments

Lunch and morning and afternoon snacks are provided so please make sure you let us know about any dietary needs at least a week before we get started. With the exception of the social night, all other meals are for you to organise. We suggest getting a hotel that provides breakfast, and there are many good restaurants in Manchester for your evening meals. We will try and facilitate additional social arrangements, but, this is down to the individuals present.

Staying in Manchester

There are a number of good and affordable hotels in the Manchester area. We are based in an area called Media City and we are in the same complex as the northern headquarters of the BBC. This means that there are lots of facilities locally and you could choose to not venture into the city centre.

Getting here

If you do choose to look further around there are good tram links that can take you into the city as well as to key travel hubs such as Piccadilly, the national railway station, and Manchester International Airport.

Please check the weather before you travel and bring suitable clothes for the season. If in doubt, assume you will need a waterproof coat and an umbrella. The locals will tell you that Manchester is one of the rainiest places in the world, its not actually true but it does drizzle more than you might expect, even in summer.

Ready to turn hardware access into firmware?

Learn how to take a mapped target board and choose, execute and troubleshoot the right extraction route. Over five days, you’ll work with debug interfaces, bootloaders and memory devices to recover and verify firmware while preserving the target wherever possible.

Collection of Arduino-compatible development boards, jumper wires, and IoT microcontrollers used for embedded systems development, hardware prototyping, and IoT security testing.

Get in touch

Register interest