Skip to main content
The Cyber Security: ethical hacking and cyber security training, Canada
Core

IoT Penetration Testing

Connected devices fail in ways a pure web or network tester never sees. This IoT penetration testing course covers the whole product: the hardware, the firmware, the radio links and the cloud and mobile backends behind them. You test only devices provided in the academy lab under written authorization.

You extract and analyse firmware, uncover hardcoded secrets and weak update mechanisms, interrogate radio protocols, and follow the trail into the mobile app and cloud application programming interfaces, or APIs, that control the device.

Duration
8 weeks
Format
Live online, instructor-led
Prerequisites
None required
Class size
Capped at 12 learners
IoT Penetration Testing

What you will be able to do

  • Identify debug interfaces on a board and extract its firmware safely
  • Unpack firmware and locate hardcoded secrets and weak update logic
  • Capture and analyse Bluetooth Low Energy and sub-GHz radio traffic
  • Test the cloud APIs and mobile app that support a connected device
  • Explain the physical access an attack assumes and why it matters
  • Prioritise fixes across hardware, firmware and backend for a manufacturer
  • Produce an IoT engagement report that a product team can act on

Course outline

5 modules

  • Identifying components and datasheets
  • Finding UART, JTAG and SWD interfaces
  • Safe probing and bus sniffing
  • Extracting firmware from flash

What you need before you start

  • Comfort with Linux and the command line
  • Basic networking and familiarity with how APIs work
  • Willingness to work with hardware tools and wiring in the lab

Who this course is for

  • Penetration testers moving into embedded and hardware testing
  • Product security engineers at device manufacturers
  • Firmware and embedded developers who want to test their own work
  • Testers preparing for the CompTIA PenTest+ exam

Where this leads

Prepares you for

PenTest+

Awarded by CompTIA

CompTIA awards the PenTest+ certification after you pass its exam; the academy does not issue it. The device testing, analysis and reporting skills in this course line up with the penetration testing workflow PenTest+ assesses across the engagement lifecycle.

Questions about this course

Ready to launch your cyber security career?

Join the next live online cohort. No experience required, just bring the curiosity.