Binary-level vulnerability research for IoT devices, industrial controllers, and embedded systems — router firmware, smart home devices, and IIoT sensors — via a 5-phase AI pipeline (QEMU execution, binary analysis, responsible disclosure).
Request IoT AuditMost IoT firmware ships with outdated Linux kernels, hardcoded credentials, and unauthenticated network services. Traditional penetration testing misses binary-level vulnerabilities in custom daemons that have no source code available. Our approach starts with the firmware image itself — no source required.
Phase 1 extracts and fingerprints the firmware (binwalk, unsquashfs, custom unpackers). Phase 2 enumerates attack surface — open ports, daemons, web interfaces. Phase 3 uses QEMU-based virtual execution for dynamic tracing. Phase 4 applies AI-guided binary analysis and protocol fuzzing. Phase 5 handles coordinated disclosure and CVE assignment.
Singapore's Cybersecurity Agency (CSA) Cybersecurity Labelling Scheme (CLS) for IoT devices requires documented security testing. Our reports align with CLS requirements and can support labelling applications for Level 2 and Level 3 assessments.
No. We work from firmware images. If you can provide the firmware binary (or a device for extraction), we can proceed without physical access to your production hardware.
MQTT, Modbus, Zigbee, Z-Wave, CoAP, BACnet, and custom binary protocols. We also test OTA update mechanisms and bootloader security.
Yes. We can provide the security testing documentation required for CSA Cybersecurity Labelling Scheme applications.
IoT Firmware Audit: QEMU Binary Analysis and the 5-Phase AI Pipeline
Singapore-based. Fixed fee, 5–10 business day delivery. AI-assisted pipeline with human expert review.