Home Services About Blog Contact
Service 02

HARDWARE
PENETRATION TESTING

Physical attack testing at the silicon level. Side-channel analysis, fault injection, and chip-level exploitation - the attack surface that exists below the operating system, and that no software penetration tester can evaluate.

THE ATTACK SURFACE
BELOW THE OS

Software security testing finds vulnerabilities in code. Hardware security testing finds vulnerabilities in the device itself - the silicon, the cryptographic implementations, the physical interfaces, and the trust boundaries baked into the hardware design.

A device can have perfectly written firmware and still be vulnerable to a power analysis attack that extracts its cryptographic key in seconds. Hardware attacks bypass software-level protections entirely. This is the domain of specialist hardware hackers - not generalist penetration testers.

Power Analysis (SPA/DPA)
Simple and differential power analysis to extract cryptographic keys by analysing power consumption during crypto operations. Defeats AES, RSA, ECC implementations.
EM Side-Channel
Electromagnetic emission analysis as a non-invasive alternative to power analysis. Effective on devices where power measurement is impractical.
Voltage Glitching
Deliberately inducing faults by momentarily disrupting the power supply - bypassing secure boot, authentication checks, and read-out protection.
Clock Glitching
Injecting timing faults via clock manipulation to skip instructions at critical moments - used to bypass secure boot verification or authentication logic.
Debug Interface Exploitation
Full exploitation of UART, JTAG, SPI, and I2C interfaces including boundary-scan attacks, flash read-out via JTAG, and runtime memory manipulation.
Chip-Off & Memory Extraction
Physical removal and direct reading of flash memory chips where software-based extraction is blocked. Recovers firmware, keys, and stored data.
WHAT WE TEST
Secure Boot Bypass
Testing of secure boot chain integrity. Attempts to load unsigned firmware via voltage/clock glitching and JTAG manipulation to bypass verification.
Cryptographic Key Extraction
Power and EM side-channel attacks targeting hardware cryptographic operations to extract keys stored in secure enclaves or OTP fuses.
Physical Read-Out Protection
Testing of flash read-out protection (RDP) levels. Evaluation of chip-off feasibility and voltage glitch attacks to downgrade protection level.
Trusted Execution Environment (TEE)
Security evaluation of ARM TrustZone and similar TEE implementations - testing isolation, secure/normal world boundary enforcement, and SMC handler security.
Hardware Tamper Protection
Evaluation of physical tamper detection mechanisms - mesh sensors, anti-drill protection, tamper-evident seals - and bypass techniques.
THE TOOLKIT
ChipWhisperer Lite ChipWhisperer Pro J-Link EDU/Pro Bus Pirate Logic Analyser Oscilloscope XRAY / FLIR Soldering Station Hot Air Rework CH341A Flash Programmer NAND Flash Reader OpenOCD UrJTAG Flashrom
HOW WE WORK
01
Scope & Threat Modelling
Defining attack surface, target components, and test objectives based on device type and deployment context.
02
Passive Reconnaissance
Non-invasive analysis of PCB layout, component identification, interface mapping, and datasheet research before any probing begins.
03
Interface Exploitation
Active probing of debug interfaces (UART, JTAG, SPI, I2C), boundary-scan attacks, and runtime memory access attempts.
04
Side-Channel & Fault Injection
Power/EM analysis campaigns and voltage/clock glitching attacks targeting cryptographic operations and security-critical decision points.
05
Exploitation & Impact Validation
Confirmed vulnerabilities are actively exploited in a controlled environment to validate severity, demonstrate realistic attack chains, and assess true business impact. Every finding in the final report has been verified - no theoretical risks, no assumed severity.
06
Reporting & Debrief
CVSS-scored findings with full technical evidence, attack reproduction steps, business impact, and concrete remediation guidance delivered with a live debrief call.
DELIVERABLES & OUTCOMES
Executive Summary
Risk posture overview and prioritised findings suitable for C-suite presentation, with no requirement for technical background to understand.
Full Technical Report
Every attack path documented with oscilloscope captures, logic analyser traces, reproduction steps, CVSS scores, and remediation guidance.
Raw Capture Data
Power traces, EM recordings, and logic analyser captures delivered alongside the report for your engineering team's reference during remediation.
Attack Feasibility Assessment
Honest evaluation of which attacks are practical at scale versus requiring lab conditions, so your risk team can prioritise correctly.
Debrief Call & 30-Day Support
60-minute technical walkthrough with your engineering team plus 30 days of direct analyst access for remediation questions.
Proof-of-Concept Documentation
Working PoC scripts, glitch parameters, and capture setups from the engagement - so your engineering team can internally reproduce and validate every finding without repeating the assessment.

Secure your hardware before it ships.

Hardware vulnerabilities can't be patched over the air. Start with a free 30-minute call to understand your device's attack surface and how we can help you secure it at the silicon level.

Talk to Our Team