▲ Consulting · Services

What we can do for you.

Security assessments for OEMs and suppliers. Firmware and protocol reverse engineering for research labs and integrators working with third-party hardware.

Services

Automotive security assessments and reverse engineering.

Automotive Security

Work on whole vehicles, individual ECUs and the buses connecting them.

  • Black- & white-box penetration testsStructured assessments against a single ECU or a whole vehicle. Typically for OEMs and tier-1 suppliers.
  • Firmware reverse engineeringStatic and dynamic analysis of extracted firmware, for security review or to document behaviour on a part you need to integrate with.
  • Protocol & interface recoveryReflashing protocols, CAN signal layouts, DBC files, and other undocumented interfaces. For research labs, universities, and aftermarket integrators.
  • Secure Onboard Communication (SecOC)Audit SecOC implementation. Check for proper key storage and key distrbution.
Renesas RH850 microcontroller on a test board.

Embedded Hardware

Low-level attacks against the chips themselves, and the custom rigs to run them.

  • Custom hardware developmentPurpose-built test rigs and adapters. For example a FlexRay gateway, OBD-II dongle, or interface boards for a specific ECU under test.
  • Fault injectionTargeted glitching rigs used to recover firmware from locked MCUs.
  • Fuzzing at scaleCoverage-guided fuzzing harnesses for embedded firmware and standalone libraries, from ECU stacks to parser code.
Custom reverse-engineering and analysis tooling.

Software Development

Tooling that supports the work, either as one-offs for a single client or as reusable infrastructure you can own.

  • Custom reverse-engineering toolsIDA/Ghidra plugins, disassembly frontends and trace recorders.
  • Open-source extensionsAdapt the tools we already maintain to your workflow and protocols.
OPEN SOURCE

Tools we build and maintain

Start a project

Get in touch to discuss the scope of your assessment, reverse-engineering work, or custom tooling needs.

Get in touch →