Back to Courses

CESH 140 PCB RE: Power, timing, thermal, acoustic and harmonics

Side-channels · 5 days · Assessed

BG

About the course

This is the side-channel analysis course in the PCB reverse engineering pathway. Students learn how to assess a device through the physical signals it leaks while operating, rather than through the interfaces its designers intended to expose. The focus is measurement-led analysis: capturing clean traces, separating useful signal from noise, and understanding when power, timing, heat, sound or electromagnetic harmonics reveal something security-relevant.

Students assess leakage through power consumption, execution timing, thermal behaviour, acoustic output and electromagnetic emissions. They learn how to instrument a target safely, choose measurement points, capture repeatable traces, compare normal and sensitive operations, and recognise patterns that indicate behaviour of interest.

Throughout the course, students use a capture, compare and explain method: measure the device in a known state, collect traces during meaningful operations, compare the results, and tie the observed leakage back to code, data, state or hardware design. By the end, they can identify plausible side-channel leakage on realistic embedded targets, capture evidence cleanly, and explain whether the behaviour creates a meaningful security risk or needs deeper specialist analysis.

Want to know what to expect in the classroom? Find out more about our training approach and how we turn technical concepts into practical, hands-on skills.

Skills and topics covered

This list shows the various main topics we cover during the course:

  • Side-channel planning from a board map
  • Identifying likely leakage sources on embedded targets
  • Power rail selection and measurement strategy
  • Safe probing and instrumentation for repeatable captures
  • Noise reduction, grounding and capture hygiene
  • Power trace capture and interpretation
  • Power analysis concepts and workflows
  • The practical limits of each technique
  • Measuring operation duration and timing variance
  • Thermal leakage assessment and heat-pattern observation
  • Acoustic leakage from components, clocks and switching behaviour
  • Electromagnetic harmonics and emissions capture
  • Relating observed leakage to clocks, buses and code paths
  • Comparing normal, sensitive and fault states
  • Diagnosing misleading traces, environmental noise and false positives

What will a new trainee gain?

A trainee learns to stop treating a running device as silent just because no debug port or service console is available. They gain a practical foundation in measuring what a target gives away through physics, which makes them more useful on hardware assessments where the interesting behaviour is not visible through normal interfaces.

What will an experienced team member gain?

An experienced engineer gains a broader side-channel toolkit across power, timing, thermal, acoustic and harmonic leakage, with enough structure to decide when a leak is noise, when it is useful, and when it deserves deeper attack development. For your organisation that means better early triage of embedded protections, clearer evidence, and fewer missed weaknesses hidden outside the obvious attack surface.

Who this course is for

This course is for hardware security professionals and reverse engineers who want to investigate what embedded devices reveal beyond their intended interfaces. Familiarity with PCB analysis, basic electronics and safe hardware instrumentation is recommended, as the course builds on those foundations to explore physical side-channel leakage.

Not sure where you fit? Find out more about our training audience and prerequisites.

Required equipment, tools, and software

You will need a laptop with at least 8GB RAM preferably 16GB, an up to date and stable Operating System, and an Ethernet port / reliable Ethernet dongle.

This laptop must be fully under your control such that you can install tools, dependencies and run arbitrary code.  It is often useful to have the ability to run virtual machines and any that we provide will be suitable for importing into VirtualBox.  If you use a different hypervisor, ensure that you are confident about importing VMs from OVF file formats.  Unfortunately we are unable to pause the course for technical difficulties as a result of the amount of material that we need to cover.

We will use a number of other tools during the course.  We put together a goodie bag which directly relates to the activities in the course.  The free goodie bag is yours to keep at the end of the course, just make sure you have enough luggage space to take it home. The exact details of what is in it will vary depending on availability but we always make it a useful and interesting collection.  We provide any other tools needed to complete all the tasks set, aside from a laptop.

You don’t need to bring anything extra other than your enthusiasm!

Venue and travel information

The classroom

The classroom is well appointed, has good WiFi and hot and cold drinks, it’s spacious, comfortable, has plenty of power sockets, lots of natural light, and is wheelchair friendly. The course is delivered in English and digital versions of slides and handouts will be provided where appropriate.

Food and refreshments

Lunch and morning and afternoon snacks are provided so please make sure you let us know about any dietary needs at least a week before we get started. With the exception of the social night, all other meals are for you to organise. We suggest getting a hotel that provides breakfast, and there are many good restaurants in Manchester for your evening meals. We will try and facilitate additional social arrangements, but, this is down to the individuals present.

Staying in Manchester

There are a number of good and affordable hotels in the Manchester area. We are based in an area called Media City and we are in the same complex as the northern headquarters of the BBC. This means that there are lots of facilities locally and you could choose to not venture into the city centre.

Getting here

If you do choose to look further around there are good tram links that can take you into the city as well as to key travel hubs such as Piccadilly, the national railway station, and Manchester International Airport.

Please check the weather before you travel and bring suitable clothes for the season. If in doubt, assume you will need a waterproof coat and an umbrella. The locals will tell you that Manchester is one of the rainiest places in the world, its not actually true but it does drizzle more than you might expect, even in summer.

Ready to uncover what hardware gives away?

Learn to capture and interpret the physical signals embedded devices leak while operating. Over five days, you’ll investigate power, timing, thermal, acoustic and electromagnetic behaviour, building the practical skills to distinguish meaningful security leakage from noise.

Collection of Arduino-compatible development boards, jumper wires, and IoT microcontrollers used for embedded systems development, hardware prototyping, and IoT security testing.

Get in touch

Register interest