Skip to content
← Back to portfolioSecurity Research / 2026

Binary Analysis

Hardware Reverse Engineering

0x00401000 push ebp0x00401001 mov ebp, esp0x00401003 sub esp, 0x200x00401006 call 0x004011500x0040100b cmp eax, 0ENTRY_POINTPATCH_LOCRET_CLEAN
01 / EXECUTIVE SUMMARY

Advanced static and dynamic analysis on compiled binaries using Ghidra to map logic flows, trace memory patterns, and neutralize software vulnerabilities. Extracted and audited embedded firmware images from physical IoT microcontrollers to analyze boot validation sequences and map hardware attack surfaces.

02 / SPECIFICATIONS
RoleSecurity Researcher
Year2026
CategorySecurity Research
Tech Stack
GhidraJTAGCAssembly
View engagement →
03 / THREAT VECTOR & CHALLENGE

Closed-source IoT devices had undocumented behavior and potential vulnerabilities. Needed to understand their internals without source code or documentation.

04 / ARCHITECTURAL SOLUTION

Used Ghidra for static and dynamic binary analysis. Extracted firmware images from physical microcontrollers via JTAG, mapped boot validation sequences, and identified hardware attack surfaces.

05 / SECURITY RESEARCH ADVISORY & THREAT MODELCVE-2026-NATIVE-RCE

Deep binary inspection utilizing Ghidra headless analyzer scripts alongside hardware debug probes (JTAG/SWD). Firmware binary dumps were decompiled into ARM Cortex-M assembly to audit Secure Boot verification routines and identify hardcoded cryptographic keys.

Identified Threat Vectors:
  • Glitch attack / Voltage fault injection bypassing bootloader authentication
  • Insecure JTAG pin exposed on PCB test pads allowing raw memory dump
  • Stack buffer overflow in hardcoded diagnostic commands
06 / REVERSE ENGINEERING POCH & DISASSEMBLY BLOCKSEVERITY: CRITICAL
; Ghidra Decompiled ARM Assembly
000104a2: 4b 68        ldr     r3, [r1, #4]      ; Load auth header magic
000104a4: 2b 49        ldr     r1, =0xDEADBEEF   ; Compare against hardcoded check
000104a6: 9b 42        cmp     r3, r1
000104a8: 03 d1        bne     boot_failed       ; NOP out to bypass signature check!

Vector Analysis: Direct memory injection over JTAG debug interface bypasses public-key signature verification during cold boot phase.

Remediation: Disable physical JTAG debug ports using hardware eFuses (Blow eFuse DEBUG_DISABLE) and implement MCU memory protection units (MPU).

07 / DEFENSIVE MITIGATION MATRIX
Vulnerability ExposureDefensive Architecture Countermeasure
Exposed JTAG Test PadsPermanent eFuse debug blow after factory provisioning
Unencrypted Flash StorageEnable On-The-Fly Flash Encryption (AES-XTS)
Hardcoded Secret KeysProvision per-device keys inside hardware Secure Element
08 / CAPABILITY MATRIX
01Ghidra Static & Dynamic Analysis
02Firmware Extraction via JTAG
03Logic Flow Mapping
04Memory Pattern Tracing
05Hardware Attack Surface Mapping
Next Engagement Case StudySOUBI
Back to all engagements