IoT & Drone Security
IoT devices often lack basic security. We test hardware and firmware to prevent device compromise.
Who this is for
Product, firmware and operations teams shipping physical or connected systems, where a security problem has consequences you cannot patch remotely.
Methodology
What We Test
- Wireless protocols (Zigbee, BLE, LoRa, Wi-Fi)
- Hardware interfaces (UART, JTAG, SPI, I2C)
- Firmware extraction, encryption, and hardcoded secrets
- Mobile companion apps and cloud API backends
- GPS/GNSS signal integrity and spoofing resilience
- Drone flight controller command injection
How We Test
We perform physical teardowns to access debug ports. We sniff and replay radio signals to hijack control. We reverse engineer firmware binaries to find logic flaws and private keys. We assess resistance to physical tampering and signal jamming.
What You Receive
- Hardware revision recommendations
- Firmware patch strategies and secure boot guidance
- Signal protection and encryption protocols
- Demonstration of device takeover or data extraction
How an engagement runs
-
Scope, authorisation & safety constraints
We agree the target hardware or environment, the tests permitted on it, and the safety and operational limits before anything is powered on. Nothing starts without written authorisation from someone able to give it.
-
Samples, access & environment
We confirm what you supply — devices or samples, firmware and hardware revisions, bench or lab access, interfaces and credentials — and agree in writing whether work may be invasive or destructive, and how samples are returned or disposed of.
-
Passive analysis first
We start with observation, documentation review and passive analysis so we understand the system before touching anything that could affect it. On operational technology this stage carries the most weight.
-
Controlled active testing
Active testing happens on a bench, a replica or an agreed non-operational window — never against live production or safety-critical operations without explicit written approval and your engineers present.
-
Report & walkthrough
You get an executive summary and technical detail covering what we proved, what held, what could not be tested safely, and why. We walk your team through it.
-
Retest
Fixes are retested against the same samples or environment where that is practical. Retest scope is agreed in your scope document before the engagement begins.
Toolkit
- Binwalk
- HackRF
- Ubertooth
- JTAGulator
