Security · Device Penetration Test
We take your device apart the way an attacker would.
Firmware extraction, debug-port discovery, bus interception, secrets in flash, update-path integrity. A hardware security assessment by people who design hardware — and a written report you can hand to a customer who asked whether your device is safe.
Device Penetration Test
- Typical length
- 2–3 weeks
- What you get
- 8 written deliverables, listed below
- What decides the number
- How many distinct boards are in the product, whether the firmware is readable or locked, and whether you can give us a unit we are allowed to destroy. A device we can sacrifice is cheaper to assess than one we must return working.
- Scoping
- One call, then a written scope. We say no when it is not ours.
Contact salesGet a quote
01 The terms
Quoted per project, after a call. We do not publish a band for this, because a number without a scope is a guess and you would have to unpick it later anyway.
Tell us what the work has to do and when it has to be done, and you get the scope and the number in writing — or a straight answer that this is not ours.
03 The problem
An embedded product ships with a serial console nobody disabled, a firmware image anyone can pull off the flash, an API key compiled into that image, and an update path that accepts anything it is handed. None of these show up in a web application scan, because none of them are on the web.
And the people who usually get asked to test it are network and application testers. They are good at their job. Their job is not a circuit board.
04 What you get
- Written report: findings ranked by exploitability and impact, with reproduction steps
- Firmware extraction attempt — SPI flash, JTAG/SWD, UART bootloader
- Debug interface discovery: exposed UART, JTAG/SWD, test pads, unlocked fuses
- Secrets audit — keys, credentials and tokens recoverable from the image
- Bus interception on the device's own wires, including undocumented protocols
- Update-path review: is an unsigned or downgraded image accepted?
- Physical attack surface — enclosure, tamper evidence, exposed connectors
- A remediation list written for the engineer who has to fix it, not for an auditor
05 How it runs
- Before we start
- Scope agreed and written authorisation signed. Nothing begins without it. You ship us hardware; the clock starts when it arrives.
- Week 1
- Teardown, interface discovery, firmware extraction.
- Week 2
- Firmware and protocol analysis, update path, secrets.
- Week 3
- Report, ranked findings, remediation call.
06 Whether this is for you
This is for you if
- You are shipping an embedded product and a customer has started asking security questions
- IoT, industrial, metering, access-control or point-of-sale hardware
- A device with a radio, a serial port, or a firmware update mechanism
- You suspect the answer is bad and would rather find out before a customer does
This is not for you if
- Any device you do not own or have written authorisation from the owner to test. We ask for that authorisation in writing before we start, every time, and we will decline without it.
- Web application or corporate network penetration testing — that is a different discipline and you want an accredited firm for it.
- Certified assessments for PCI, SOC 2, FedRAMP or CE/UKCA sign-off. We are not an accredited lab and our report will not satisfy an auditor who needs one.
- Formal cryptographic review or protocol proof work
07 Proof
The methodology is the one we use as engineers. On eFuelPro we tapped a live RS485 bus, recovered 25-byte frames nobody had documented, and found a stray 0x88 broadcast from another device quietly corrupting calibration. Reading hardware that does not want to be read is the day job.
08 Questions
Are you CREST or OSCP certified?
No, and if your buyer requires that certification you should hire a firm that holds it — we will say so on the first call. What we hold instead is hardware engineering: we design boards and decode undocumented buses, which is what a device assessment actually consists of. If your buyer needs a certificate, go elsewhere — we will tell you so on the first call rather than after you have paid. This is our first year selling security work as such, and we will not pretend otherwise.
What happens to our data and our firmware?
NDA signed before you send anything. Everything you give us — images, captures, schemas, credentials — is held encrypted, never shared outside the engagement, and deleted 30 days after the report unless you ask us to keep it for a retest. Credentials are staging-only and we ask you to rotate them when we finish.
Will you destroy the device?
Possibly. Firmware extraction sometimes means desoldering a flash chip. Send a unit you can spare and tell us if you need it back working — it changes the approach and the price.
What if you find nothing serious?
You get the report saying so, with everything we tried. That document is what you send the customer who asked the question.
Next 2–3 weeks
Device Penetration Test
Tell us what the work has to do and when it has to be done. You will get a person who has read it, not a sequence.