Built for
- Working pentesters moving into connected-product assessments.
- Product-security engineers responsible for firmware-backed products.
LearningFounding season · Enrollment dates are being finalized
OIX Founding Investigation Season
Turn firmware artifacts into defensible connected-product security decisions.
Built for working pentesters and product-security engineers who already know the basics and need a repeatable investigation method.
The work
What you produce
Each investigation ends with an explicit claim boundary and the next evidence worth acquiring.
The guided route
Start with authority, storage, startup, kernel reachability, and a device control plane. The remaining investigations extend the same method.
Extract a Moxa firmware image and build a bounded static-evidence case for the component that coordinates product runtime state.
120 minReconstruct the Wyze storage map and distinguish persistent, generated, repair, and update authority.
120 minUse boot and init artifacts to rank service startup, privilege, input, and trust-boundary leads.
150 minUse module metadata, symbols, parameters, and call surfaces to build bounded kernel attack-surface hypotheses.
105 minTrace a registered Tapo HTTP route to a firmware-changing handoff and stop claims where static binding evidence ends.
90 minSix weeks
The sessions give the founding group a shared cadence for evidence review and unresolved proof obligations. The full library remains available for twelve months.
Inside an investigation
OIX records the question, the action, the observation, the boundary, and the next proof. Suspicious syntax alone does not become a vulnerability claim.
Complete library
Open a module to inspect the full route. Course bodies remain protected.
Extract a Moxa firmware image and build a bounded static-evidence case for the component that coordinates product runtime state.
Promote firmware artifacts into an evidence-bounded setup path from package structure to network-state mutation.
Reconstruct the Wyze storage map and distinguish persistent, generated, repair, and update authority.
Use boot and init artifacts to rank service startup, privilege, input, and trust-boundary leads.
Triage credential-shaped artifacts while preserving provenance, scope, and runtime proof obligations.
Trace the Unitree Bluetooth service lane into the shell helpers that mutate Wi-Fi and access-point state.
Reconstruct a Unitree state mutation path and express its security boundary as evidence-backed invariants.
Use module metadata, symbols, parameters, and call surfaces to build bounded kernel attack-surface hypotheses.
Identify and inspect the Wyze kernel image without confusing embedded capability with active runtime exposure.
Recognize when Linux-oriented firmware assumptions fail and reconstruct an MCU artifact from its own evidence.
Reconstruct a protected Tapo update format and prove the recovered plaintext at byte and filesystem boundaries.
Determine whether a GPL drop is runnable, then build a bounded target hypothesis from retained configuration evidence.
Rank candidate boot and service surfaces, then specify the real-image evidence needed to test them.
Trace a sibling U-Boot port from reset authority to recovery ingress without transferring its conclusions to another target.
Bind ABI, boot synthesis, configuration tiers, and management clients into a bounded Moxa runtime model.
Trace a registered Tapo HTTP route to a firmware-changing handoff and stop claims where static binding evidence ends.
Fit check
Questions
No. The founding season uses provided firmware and source artifacts.
No. OIX assumes Linux command-line comfort and basic firmware or embedded-systems familiarity.
No. There is no examination, certification, individual grading, or submission review.
The access term will be shown before checkout opens.
Founding season
Founding season · Enrollment dates are being finalized
Enrollment dates are being finalized.