IoT Penetration Testing
Connected devices fail in ways a pure web or network tester never sees. This IoT penetration testing course covers the whole product: the hardware, the firmware, the radio links and the cloud and mobile backends behind them. You test only devices provided in the academy lab under written authorization.
You extract and analyse firmware, uncover hardcoded secrets and weak update mechanisms, interrogate radio protocols, and follow the trail into the mobile app and cloud application programming interfaces, or APIs, that control the device.
- Duration
- 8 weeks
- Format
- Live online, instructor-led
- Prerequisites
- None required
- Class size
- Capped at 12 learners

What you will be able to do
- Identify debug interfaces on a board and extract its firmware safely
- Unpack firmware and locate hardcoded secrets and weak update logic
- Capture and analyse Bluetooth Low Energy and sub-GHz radio traffic
- Test the cloud APIs and mobile app that support a connected device
- Explain the physical access an attack assumes and why it matters
- Prioritise fixes across hardware, firmware and backend for a manufacturer
- Produce an IoT engagement report that a product team can act on
Course outline
5 modules
- Identifying components and datasheets
- Finding UART, JTAG and SWD interfaces
- Safe probing and bus sniffing
- Extracting firmware from flash
What you need before you start
- Comfort with Linux and the command line
- Basic networking and familiarity with how APIs work
- Willingness to work with hardware tools and wiring in the lab
Who this course is for
- Penetration testers moving into embedded and hardware testing
- Product security engineers at device manufacturers
- Firmware and embedded developers who want to test their own work
- Testers preparing for the CompTIA PenTest+ exam
Where this leads
Prepares you for
PenTest+
Awarded by CompTIA
CompTIA awards the PenTest+ certification after you pass its exam; the academy does not issue it. The device testing, analysis and reporting skills in this course line up with the penetration testing workflow PenTest+ assesses across the engagement lifecycle.
Questions about this course
More in offensive security
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



