CESH 310 Firmware: Tools, Tactics and Techniques
Bench-craft · 4 days · Assessed
This is the practical tooling course in the firmware reverse engineering pathway. Students learn how to drive the firmware analysis toolkit properly, and more importantly, how to decide which tool belongs at which point in the workflow. The focus is bench craft: repeatable handling of unfamiliar images, disciplined tool use, and turning raw binary material into something that can be inspected, executed and reasoned about.
Students work with tools and techniques for carving firmware apart, recognising embedded filesystems, identifying bootloaders, inspecting binaries, and moving between static and dynamic analysis. They use binwalk, unblob and supporting utilities to recover content, then work in Ghidra, IDA and rizin to inspect code and compare analysis output. They also get hands-on exposure to emulation so they can observe behaviour directly, rather than relying only on static interpretation.
Throughout the course, students use a select, run and validate method: choose the tool for the question being asked, run it with intent, check whether the output is trustworthy, and cross-confirm important conclusions before acting on them. By the end, they can build a repeatable firmware analysis workspace, unpack and inspect realistic images, use the major reverse engineering tools with confidence, and decide when static analysis, emulation or deeper manual work is the right next move.
Want to know what to expect in the classroom? Find out more about our training approach and how we turn technical concepts into practical, hands-on skills.
This list shows the various main topics we cover during the course:
A trainee learns how to use the tools without mistaking tool output for truth. Firmware analysis is full of partial extractions, wrong guesses and formats that almost, but not quite, parse cleanly. The course gives new entrants a practical method for working through those problems without making a mess of the evidence.
An experienced engineer sharpens their bench workflow across the main firmware tooling stack, and gains better judgement about when to switch tool, repeat an extraction, emulate behaviour or inspect code by hand. For your organisation that means more repeatable results, less time lost to tooling dead ends, and clearer analysis that other team members can pick up.
This course is for firmware analysts, reverse engineers and security professionals who want to build confidence with the practical firmware analysis toolkit. A basic understanding of firmware structure and reverse engineering concepts is recommended, but deep experience with individual tools such as Ghidra, IDA or rizin is not required.
Not sure where you fit? Find out more about our training audience and prerequisites.
You will need a laptop with at least 8GB RAM, preferably 16GB, an up-to-date and stable operating system, and an Ethernet port or reliable Ethernet dongle. Your laptop must be fully under your control so that you can install tools and dependencies and run arbitrary code.
It is useful to have the ability to run virtual machines. Any VMs provided during the course will be suitable for importing into VirtualBox; if you use a different hypervisor, you should be comfortable importing VMs from OVF file formats.
Any firmware images, sample targets and course-specific analysis tools required for the practical exercises will be provided. No specialist hardware is required.
We put together a goodie bag which directly relates to the activities in the course. The free goodie bag is yours to keep at the end of the course, just make sure you have enough luggage space to take it home. The exact details of what is in it will vary depending on availability but we always make it a useful and interesting collection. We provide any other tools needed to complete all the tasks set, aside from a laptop.
You don’t need to bring anything extra other than your enthusiasm!
The classroom is well appointed, has good WiFi and hot and cold drinks, it’s spacious, comfortable, has plenty of power sockets, lots of natural light, and is wheelchair friendly. The course is delivered in English and digital versions of slides and handouts will be provided where appropriate.
Lunch and morning and afternoon snacks are provided so please make sure you let us know about any dietary needs at least a week before we get started. With the exception of the social night, all other meals are for you to organise. We suggest getting a hotel that provides breakfast, and there are many good restaurants in Manchester for your evening meals. We will try and facilitate additional social arrangements, but, this is down to the individuals present.
There are a number of good and affordable hotels in the Manchester area. We are based in an area called Media City and we are in the same complex as the northern headquarters of the BBC. This means that there are lots of facilities locally and you could choose to not venture into the city centre.
If you do choose to look further around there are good tram links that can take you into the city as well as to key travel hubs such as Piccadilly, the national railway station, and Manchester International Airport.
Please check the weather before you travel and bring suitable clothes for the season. If in doubt, assume you will need a waterproof coat and an umbrella. The locals will tell you that Manchester is one of the rainiest places in the world, its not actually true but it does drizzle more than you might expect, even in summer.
Build a repeatable workflow for taking unfamiliar firmware from raw binary material to meaningful analysis. Over four days, you’ll work hands-on with extraction, static analysis and reverse engineering tools, learning not just how to use them, but when to use them and how to validate what they tell you.