Back to Courses

CESH 170 PCB RE: Voltage Manipulation, Clock-Control and Glitching

Specialism · 5 days · Assessed

BG

About the course

This is the fault injection course in the PCB reverse engineering pathway. Students learn how to move beyond passive observation and controlled access into deliberate manipulation of a target’s operating conditions. The focus is practical fault creation: using voltage, clock and timing control to disturb execution, test security assumptions, and identify where a device’s protections depend on fragile behaviour.

Students assess where and how a target can be influenced, including power rails, reset lines, clock sources, boot timing, debug lockout windows, secure boot checks, authentication paths and peripheral initialisation. They learn how to instrument a board for repeatable experiments, introduce controlled voltage glitches, manipulate clock behaviour, observe device responses, and build timing models that turn unreliable faults into useful test cases.

Throughout the course, students use a measure, disturb and refine method: understand the normal state, introduce one controlled fault, observe the effect, and adjust the experiment without losing sight of target safety or evidence quality. By the end, they can plan and execute basic fault injection work against realistic embedded targets, recognise exploitable fault behaviour, and produce findings that can be handed into deeper exploit, firmware or hardware attack workflows.

Want to know what to expect in the classroom? Find out more about our training approach and how we turn technical concepts into practical, hands-on skills.

Skills and topics covered

This list shows the various main topics we cover during the course:

  • Fault injection planning from a board map
  • Identifying candidate rails, clocks, resets and trigger points
  • Power rail mapping for voltage manipulation
  • Safe instrumentation for repeatable fault experiments
  • Voltage glitching concepts and practical setup
  • Clock source identification and clock-control strategy
  • Timing-window discovery during boot and security checks
  • Trigger selection using observable device behaviour
  • Reset, brown-out and boot-state manipulation
  • Authentication and access-control fault testing
  • Peripheral initialisation and state-transition abuse
  • Capturing and comparing normal versus faulted behaviour
  • Diagnosing unstable glitches, false positives and target crashes
  • Reporting fault behaviour, exploitability and defensive impact

What will a new trainee gain?

A trainee learns how voltage, clock and timing faults can change what an embedded device does, instead of treating chips as black boxes that either allow access or do not. It gives new entrants a controlled way to explore fault injection without jumping straight into expensive equipment, fragile assumptions or destructive trial and error.

What will an experienced team member gain?

An experienced engineer gains a practical route into glitching work that connects directly to secure boot, debug protection, firmware extraction and hardware trust boundaries. For your organisation that means more targets can be assessed for real fault resistance, rather than only reviewing whether protections appear sound on paper.

Who this course is for

This course is for hardware security professionals and reverse engineers ready to move into practical fault injection. Familiarity with PCB analysis, electronics and hardware instrumentation is recommended, particularly understanding power rails, clocks, reset behaviour and embedded device operation.

Not sure where you fit? Find out more about our training audience and prerequisites.

Required equipment, tools, and software

You will need a laptop with at least 8GB RAM preferably 16GB, an up to date and stable Operating System, and an Ethernet port / reliable Ethernet dongle.

This laptop must be fully under your control such that you can install tools, dependencies and run arbitrary code.  It is often useful to have the ability to run virtual machines and any that we provide will be suitable for importing into VirtualBox.  If you use a different hypervisor, ensure that you are confident about importing VMs from OVF file formats.  Unfortunately we are unable to pause the course for technical difficulties as a result of the amount of material that we need to cover.

We will use a number of other tools during the course.  We put together a goodie bag which directly relates to the activities in the course.  The free goodie bag is yours to keep at the end of the course, just make sure you have enough luggage space to take it home. The exact details of what is in it will vary depending on availability but we always make it a useful and interesting collection.  We provide any other tools needed to complete all the tasks set, aside from a laptop.

You don’t need to bring anything extra other than your enthusiasm!

Venue and travel information

The classroom

The classroom is well appointed, has good WiFi and hot and cold drinks, it’s spacious, comfortable, has plenty of power sockets, lots of natural light, and is wheelchair friendly. The course is delivered in English and digital versions of slides and handouts will be provided where appropriate.

Food and refreshments

Lunch and morning and afternoon snacks are provided so please make sure you let us know about any dietary needs at least a week before we get started. With the exception of the social night, all other meals are for you to organise. We suggest getting a hotel that provides breakfast, and there are many good restaurants in Manchester for your evening meals. We will try and facilitate additional social arrangements, but, this is down to the individuals present.

Staying in Manchester

There are a number of good and affordable hotels in the Manchester area. We are based in an area called Media City and we are in the same complex as the northern headquarters of the BBC. This means that there are lots of facilities locally and you could choose to not venture into the city centre.

Getting here

If you do choose to look further around there are good tram links that can take you into the city as well as to key travel hubs such as Piccadilly, the national railway station, and Manchester International Airport.

Please check the weather before you travel and bring suitable clothes for the season. If in doubt, assume you will need a waterproof coat and an umbrella. The locals will tell you that Manchester is one of the rainiest places in the world, its not actually true but it does drizzle more than you might expect, even in summer.

Ready to start manipulating the target?

Move beyond observing embedded hardware and learn how to deliberately influence its behaviour. Over five days, you’ll use voltage, clock and timing manipulation to create controlled faults, investigate security assumptions and identify weaknesses in real-world device protections.

Collection of Arduino-compatible development boards, jumper wires, and IoT microcontrollers used for embedded systems development, hardware prototyping, and IoT security testing.

Get in touch

Register interest