
Wires to Weapons: Offensive Hardware Analysis with
UART, JTAG, SPI & I²C
Here’s a technical description you can use for your
training/session description:
Technical description
This session provides an in-depth, hands-on exploration of hardware communication interfaces commonly encountered during embedded and IoT security assessments:
UART, JTAG, SPI, and I²C.
Rather than focusing only on identifying pins or using standard tools, the training examines these interfaces at the electrical signal and protocol level. Participants will learn how signals behave, how data is transmitted and synchronized, and how customized tools can be built to capture, decode, analyze, manipulate, and test communication between embedded components.
The session covers:
- UART: TX/RX signaling, baud rate detection, start/stop bits, parity, voltage levels, console discovery, serial communication analysis, and interaction with embedded bootloaders and debug consoles.
- JTAG: TAP architecture, TCK, TMS, TDI, and TDO signals, state-machine operation, pin identification, chain discovery, boundary scan concepts, debug access, and firmware/security assessment techniques.
- SPI: Clock-driven communication, MOSI, MISO, SCLK, and CS signals, timing analysis, flash communication, protocol capture, transaction decoding, and assessment of external memory interfaces.
- I²C: SDA/SCL signaling, pull-up behavior, addressing, START/STOP conditions, ACK/NACK, clock stretching, device enumeration, bus analysis, and interaction with connected peripherals.
A major focus of the training is understanding raw signals before relying on automated tools. Participants will work with logic analyzers, serial adapters, debug interfaces, and custom-built hardware/software tools designed for protocol discovery, signal capture, decoding, replay, fuzzing, and security testing.
The goal is to help researchers move from simply finding UART, JTAG, SPI, or I²C pins to understanding:
Signal → Electrical Behavior → Protocol → Device Interaction → Security Assessment
By the end of the session, participants will have a practical methodology for analyzing undocumented hardware interfaces and developing customized tooling for embedded device penetration testing and security research.
![]()