Founding season · Enrollment dates are being finalized

OIX Founding Investigation Season

Offensive IoT Exploitation

Turn firmware artifacts into defensible connected-product security decisions.

Built for working pentesters and product-security engineers who already know the basics and need a repeatable investigation method.

  • 6-week guided start
  • 3 live group sessions
  • 16 practical investigations
  • Hardware-free
  • Access term to be confirmed

The work

Move from interesting artifacts to defensible decisions

What you produce

Investigation artifacts you can reuse at work

Each investigation ends with an explicit claim boundary and the next evidence worth acquiring.

  1. 01Evidence records that separate established facts from open proof obligations.
  2. 02Authority maps that connect firmware artifacts to product decisions.
  3. 03Reusable next-acquisition plans for evidence that static analysis cannot establish.

The guided route

Five investigations build the working method

Start with authority, storage, startup, kernel reachability, and a device control plane. The remaining investigations extend the same method.

  1. 1

    From Firmware Binary to Product-Level State Authority: Moxa EDR-G903 with FAT

    Extract a Moxa firmware image and build a bounded static-evidence case for the component that coordinates product runtime state.

    120 min
  2. 2

    Wyze Cam v3 — MTD Storage Layout & Authority Map

    Reconstruct the Wyze storage map and distinguish persistent, generated, repair, and update authority.

    120 min
  3. 3

    Init Script Attack Surface

    Use boot and init artifacts to rank service startup, privilege, input, and trust-boundary leads.

    150 min
  4. 4

    Kernel Module Forensics

    Use module metadata, symbols, parameters, and call surfaces to build bounded kernel attack-surface hypotheses.

    105 min
  5. 5

    From HTTP Route to Firmware Effect

    Trace a registered Tapo HTTP route to a firmware-changing handoff and stop claims where static binding evidence ends.

    90 min

Six weeks

Self-paced investigations with three fixed group sessions

The sessions give the founding group a shared cadence for evidence review and unresolved proof obligations. The full library remains available for twelve months.

  1. Group session 1Date to be confirmed
  2. Group session 2Date to be confirmed
  3. Group session 3Date to be confirmed

Inside an investigation

Keep the claim tied to the evidence

OIX records the question, the action, the observation, the boundary, and the next proof. Suspicious syntax alone does not become a vulnerability claim.

Evidence recordInit Script Attack Surface
Question
Which shell artifacts enter the review set, and which are activated?
Action
Enumerate by extension and interpreter signature, then follow boot references and explicit callers.
Evidence boundary
File presence and naming do not prove invocation.
Next proof
Trace the caller or capture runtime execution.

Complete library

16 practical investigations

Open a module to inspect the full route. Course bodies remain protected.

Module 1First Contact2 investigations
  1. Guided core

    From Firmware Binary to Product-Level State Authority: Moxa EDR-G903 with FAT

    Extract a Moxa firmware image and build a bounded static-evidence case for the component that coordinates product runtime state.

    120 min · Practical investigation

  2. Extended library

    From Firmware Package to Setup Path: Unitree Network State Reconstruction

    Promote firmware artifacts into an evidence-bounded setup path from package structure to network-state mutation.

    105 min · Practical investigation

Module 2Runtime Storage1 investigation
  1. Guided core

    Wyze Cam v3 — MTD Storage Layout & Authority Map

    Reconstruct the Wyze storage map and distinguish persistent, generated, repair, and update authority.

    120 min · Practical investigation

Module 3Security Artifact Triage4 investigations
  1. Guided core

    Init Script Attack Surface

    Use boot and init artifacts to rank service startup, privilege, input, and trust-boundary leads.

    150 min · Practical investigation

  2. Extended library

    Secrets & Credentials Sweep

    Triage credential-shaped artifacts while preserving provenance, scope, and runtime proof obligations.

    105 min · Practical investigation

  3. Extended library

    Unitree Bluetooth to Shell

    Trace the Unitree Bluetooth service lane into the shell helpers that mutate Wi-Fi and access-point state.

    90 min · Practical investigation

  4. Extended library

    Unitree SMDA Invariant Case Study

    Reconstruct a Unitree state mutation path and express its security boundary as evidence-backed invariants.

    105 min · Practical investigation

Module 4Kernel & Modules2 investigations
  1. Guided core

    Kernel Module Forensics

    Use module metadata, symbols, parameters, and call surfaces to build bounded kernel attack-surface hypotheses.

    105 min · Practical investigation

  2. Extended library

    Wyze Kernel Image Analysis

    Identify and inspect the Wyze kernel image without confusing embedded capability with active runtime exposure.

    90 min · Practical investigation

Module 5Failure Modes2 investigations
  1. Extended library

    MCU Contrast Exercise

    Recognize when Linux-oriented firmware assumptions fail and reconstruct an MCU artifact from its own evidence.

    75 min · Practical investigation

  2. Extended library

    Tapo Encrypted Firmware Decryption

    Reconstruct a protected Tapo update format and prove the recovered plaintext at byte and filesystem boundaries.

    120 min · Practical investigation

Module 6Source-Only Attack Surface3 investigations
  1. Extended library

    SmartPlug GPL — What Target Does the Retained Source Support?

    Determine whether a GPL drop is runnable, then build a bounded target hypothesis from retained configuration evidence.

    60 min · Practical investigation

  2. Extended library

    SmartPlug GPL — From Retained Configuration to Acquisition Plan

    Rank candidate boot and service surfaces, then specify the real-image evidence needed to test them.

    75 min · Practical investigation

  3. Extended library

    KS8695 Transfer Lab — Governing Artifacts and Pre-OS Trust

    Trace a sibling U-Boot port from reset authority to recovery ingress without transferring its conclusions to another target.

    120 min · Practical investigation

Module 7Control Plane Deepening2 investigations
  1. Extended library

    Reconstructing a Moxa Octeon Appliance

    Bind ABI, boot synthesis, configuration tiers, and management clients into a bounded Moxa runtime model.

    90 min · Practical investigation

  2. Guided core

    From HTTP Route to Firmware Effect

    Trace a registered Tapo HTTP route to a firmware-changing handoff and stop claims where static binding evidence ends.

    90 min · Practical investigation

Fit check

Know whether OIX matches the job you need to do

Built for

  • Working pentesters moving into connected-product assessments.
  • Product-security engineers responsible for firmware-backed products.

Bring with you

  • Comfort with Linux command-line workflows.
  • Basic familiarity with firmware or embedded systems.

Choose another route if

  • Learners seeking an introductory cybersecurity course.
  • Buyers seeking a certification exam or individually graded submission.

Questions

Before you enroll

Do I need IoT hardware?

No. The founding season uses provided firmware and source artifacts.

Is this an introductory security course?

No. OIX assumes Linux command-line comfort and basic firmware or embedded-systems familiarity.

Does OIX include a certification or grading?

No. There is no examination, certification, individual grading, or submission review.

How long can I use the investigations?

The access term will be shown before checkout opens.

Founding season

Build the investigation discipline before your next firmware assessment

Founding season · Enrollment dates are being finalized

Enrollment dates are being finalized.