From the cars we drive and the appliances we use to the sophisticated security systems protecting our homes and workplaces, networked embedded systems are everywhere. Are they secure? A better question, perhaps, is how would you even know?
For most of us, the best-case scenario is keeping our devices patched and applying basic access restrictions. Beyond that, we often take manufacturers at their word. As long as the smart TV is streaming and the smart lock is locking, we don’t ask the difficult questions. There is a collective discomfort with the reality that we are surrounded by embedded systems that are highly vulnerable to compromise, yet largely operate in a security blind spot.
As consumers, we have limited control over the security of devices in our own homes, let alone the systems implemented by the businesses and agencies we entrust with our data and security. Think about the times you’ve been notified of a breach—after the compromise occurred. Reactive measures are implemented only once it’s already too late. And you have to wonder, how many breaches go unreported or remain undiscovered and active right now?
How can we make these systems more secure? Zero-trust architecture offers a good starting point for enhancing system security. However, its comprehensive application across the sprawling ecosystem of embedded devices is a practical impossibility, leaving behind weak links that can be targeted. A layered approach, incorporating digital forensics, is likely the most effective answer.
Consider the steps Microsoft has taken with Windows Defender. They’ve adopted a proactive, digital forensics-based approach, giving them the ability to analyze anomalous files and processes running on personal computers. This capability helps to detect active threats before they become catastrophic breaches.
In stark contrast, no such tooling exists for the vast majority of embedded systems.
The reason for this gaping hole in security is simple: there’s no immediate incentive for manufacturers to perform rigorous vulnerability assessments and develop thorough forensic tooling. This process, and mitigating the inevitable vulnerabilities it would uncover, is burdensome. Instead, device security often becomes a compliance exercise—implementing a minimum set of best practices that satisfy a checklist.
Maintaining a reactive posture, or even willful ignorance toward vulnerabilities, is the least expensive path in the short term. Complicating things further, manufacturers can be reluctant to admit the existence and severity of vulnerabilities due to the impact to their corporate image – not to mention the potential liabilities.
However, forensic tooling can be developed for embedded systems to safely and securely acquire data from storage and memory in live operation. Automated analysis can be conducted on these “snapshots” to detect and assess Indicators of Compromise (IOCs)—the clues left by an attacker. Examples of such IOCs include:
Implementing these measures would significantly raise the bar for would-be attackers, but few manufacturers have taken the steps to either implement a proactive stance for themselves or to engage third party expertise.
The lack of security assurance in embedded systems is not just a manufacturer’s problem; it is a profound risk to everyday life. While we may often take them for granted, embedded systems are the silent foundation of our modern world, and their compromise can have far-reaching, personal consequences:
The blind spot in security for embedded systems is a risk we all bear, making the call for proactive assurance a universal concern.
Illustration by Inkinetic Studios.
Vulnerability research triage tricks, pattern-matching instincts, and ruthless time-saving habits for every reverse engineer.
Hacker origin stories from a few of Zetier's cybersecurity engineers.
TPM packet dissection and analysis in Wireshark using open source scripts and projects with a practical walkthrough using Proxmox.
Can prompt injections hidden in unreachable code still influence LLM's?
Everything you need to know about Offensive Cyberspace Operations and the OCO/CNO resources Zetier cyber engineers rely on.
2025 was a successful year for Zetier, with office growth, more "sheeping" unguarded colleague workstations, and fun diet(ary) choices
A case study in identifying real-world stack overflows in Netgear router firmware – without access to source code.
Are low-cost SBCs with 4k output viable for native development, RE, and tinkering?
See what your BDM debugger is actually doing under the hood with our new open-source tool.
You just fired up an old Linux-based appliance. Here's one hacking recipe to get beyond basic local access.
Understand the mechanics, risks, and future of IMSI catching (a.k.a. stealing your cellular ID) in 2025.
Thousands of video game enthusiasts are developing experience in the cybersecurity industry by accident.
One of our engineers obtained free printers on Craigslist, which revealed some intriguing obfuscation.
After competing for several years, a Zetier Cyber Engineer made the podium at the DEFCON 32 HHV CTF.
Check out the contributions our team made – and tools we open-sourced – in 2024.
Frida runs out-of-the-box on many common targets. How hard is it to port Frida to an unsupported platform?
When code is executed with Bungeegum, it operates within the application's context and memory space, mirroring how Android CNO tools are typically used in real-world scenarios.
A recently acquired piece of military technology holds secrets about worldwide manufacturing capabilities.
Thousands of military members juggle their reserve commitment and civilian life. Read this post to learn how Zetier makes sure you won’t drop the ball.
Building tshark from source with support for Lua has proven to be a challenge. This tutorial will save you some time and frustration.
Hardware memory busses are sometimes tied together with multiple ICs. Here is how to SMASH them!
Breadcrumbs are left throughout computer systems that hackers can use to track attribution or recover sensitive information. See possible gotchas in this post.
Various topics of interest covering IT, cybersecurity, tech innovations, from GitLab workflows to satellite tech advancements.
Zetier is introducing Snipey, a command-line interface (CLI) tool that extends the capabilities of Snipe-IT.
Highlights from around the internet that we discussed in the office during Dec 2023. Everything from the best deals on collectable turbo-jet engines to Bluetooth CVEs.
Explore the art of using JTAG for efficient NOR flash memory dumps – via our practical guide for hardware enthusiasts & engineers.
Lariat works with Device Farmer to address the challenges of platform fragmentation in Android device testing.
Sharing knowledge is in Zetier’s corporate DNA, and this expresses itself in multiple ways.
Smart load integration with inexpensive power supplies providing protections typically found only in pricier models.
At Zetier’s 2023 annual offsite we met in San Juan Puerto Rico for some corporate business, relationship building, good food, and fun in the sun.
DIY dental X-ray tech for PCB reverse engineering, enabling faster, budget-friendly 3D tomography.
CodeQL is a query language for code analysis, allowing powerful code introspection and data flow queries.
Subscribe now to keep reading and get access to the full archive.