oob-iot-sec-labs/oob-iot-sec-labs.github.io
GitHub: oob-iot-sec-labs/oob-iot-sec-labs.github.io
一个聚焦物联网与嵌入式设备安全的开放研究社区,提供漏洞分析、安全工具、学习资料与实战记录等系统化资源。
Stars: 1 | Forks: 0

# OOB IoT Sec Labs
**IoT 网络安全社区 | IoT Cybersecurity Community**
[](LICENSE)
[](https://github.com/oob-iot-sec-labs/oob-iot-sec-labs.github.io/stargazers)
[](CONTRIBUTING.md)
## 简介 | Introduction
OOB IoT Sec Labs 是一个面向 IoT 网络安全研究者的开放社区,聚焦嵌入式系统、智能基础设施与 IoT 设备安全,融合高级二进制分析、AI 赋能自动化和安全工具自研,从第一性原理出发解构真实设备与复杂防御系统。
我们拒绝流水线式复刻,致力于培养具备独立思考能力、能够打破规则、重构技术直觉的创造性安全研究员。
OOB IoT Sec Labs is an open community for IoT security researchers, focused on embedded systems, smart infrastructure, and connected device security. The lab combines advanced binary analysis, AI-assisted automation, and custom security tooling to investigate real-world devices and complex defense systems.
## 研究与培训方向 | Research Areas
- **物联网与硬件安全**:JTAG/UART、侧信道分析、故障注入、安全启动绕过与真实设备攻防。
- **高级二进制分析**:静态分析、动态调试、Fuzzer、漏洞成因分析与高价值未知漏洞挖掘。
- **AI 赋能安全研究**:结合 AI、符号执行与自动化框架探索深层代码路径和复杂逻辑缺陷。
- **安全开发与工程化**:构建定制化 Fuzzer、固件分析流水线、漏洞利用辅助与防御加固工具。
## 模块导航 | Modules
| 模块 | 内容 |
| --- | --- |
| [漏洞研究](./vulnerabilities/) | CVE 分析、原创漏洞研究、设备安全与高价值未知漏洞挖掘 |
| [安全工具](./tools/) | 固件分析、网络扫描、漏洞利用辅助与防御加固工具 |
| [学习资料](./resources/) | 书籍、论文、课程资源与面向 IoT 安全研究的学习路线 |
| [实战记录](./writeups/) | CTF Writeup、真实漏洞复现、调试记录与工程化实践 |
## 目录结构 | Structure
oob-iot-sec-labs.github.io/
├── vulnerabilities/ # 漏洞研究 | Vulnerability Research
│ ├── CVE/ # CVE 漏洞分析
│ └── research/ # 原创漏洞研究
├── tools/ # 安全工具 | Security Tools
│ ├── firmware-analysis/ # 固件分析工具
│ ├── network-scanning/ # 网络扫描工具
│ ├── exploitation/ # 漏洞利用工具
│ └── defense/ # 防御加固工具
├── resources/ # 学习资料 | Learning Resources
│ ├── books/ # 书籍推荐
│ ├── papers/ # 学术论文
│ └── courses/ # 课程资源
└── writeups/ # 实战记录 | CTF & Research Writeups
## 站点 | Website
GitHub Pages:
## 免责声明 | Disclaimer
本仓库内容仅用于安全研究与教育目的,请勿用于非法用途。
All content is for security research and educational purposes only. Do not use it for illegal activities.
## 许可证 | License
[MIT License](LICENSE)标签:二进制分析, 云安全运维, 固件分析, 安全社区, 情报收集, 漏洞研究, 物联网安全, 硬件安全, 系统运维工具, 红队平台, 防御加固