Group Purchasing
Group Purchasing
AI SKILLSUPDATED

SEC556: IoT Penetration Testing

SEC556Offensive Operations, Artificial Intelligence
  • 3 Days (Instructor-Led)
  • 18 Hours (Self-Paced)
Course authored by:
Larry PesceJames Leyte-Vidal
Larry Pesce & James Leyte-Vidal
SEC556: IoT Penetration Testing
Course authored by:
Larry PesceJames Leyte-Vidal
Larry Pesce & James Leyte-Vidal
  • 18 CPEs

    Apply your credits to renew your certifications

  • Virtual Live Instruction or Self-Paced

    Train from anywhere. Attend a live instructor-led course remotely or train on your time over 4 months.

  • Intermediate Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 13 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

SEC556 equips security professionals with comprehensive skills to identify, assess, and exploit IoT device security mechanisms across diverse technological ecosystems.

Course Overview

SEC556 teaches students how to assess the security of modern Internet of Things (IoT) and embedded systems through hands-on analysis of firmware, hardware, wireless protocols, network communications, and application interfaces. Students learn practical techniques to identify, exploit, and defend vulnerabilities across connected ecosystems.

IoT Security Spans Every Technology Layer

A growing trend in recent years has seen small-form-factor computing devices increasingly accessing networks to provide connectivity to what typically used to be disconnected devices. While we can debate if your home appliances truly need Internet access, there is no debate that the Internet of Things (IoT) is here to stay. It allows for deeper connectivity of many devices that are indeed useful, with great benefits to homes and enterprises alike.

Unfortunately, with the proliferation of connected technology, many of these devices do not consider, or only minimally consider, security in the design process. While we have seen this behavior in other types of testing as well, IoT is different because it utilizes and mixes many different technology stacks such as custom Operating System builds, web and API interfaces, various networking protocols (e.g., Zigbee, LoRA, Bluetooth/BLE, WiFi), and proprietary wireless.

This wide range of diverse, poorly secured technology makes for a desirable pivot point into networks, opportunities for modification of user data, network traffic manipulation, and more. That’s why dedicated IoT security training is essential for professionals responsible for defending or assessing modern connected systems.

SEC556 is a hands-on IoT hacking course that will familiarize you with common interfaces in IoT devices and recommend a process along with the Internet of Things Attack (IoTA), testing framework to evaluate these devices within many layers of the Open Systems Interconnection (OSI) model. From firmware and network protocol analysis to hardware implementation issues and all the way to application flaws, we will give you the tools and hands-on techniques to evaluate the ever-expanding range of IoT devices.

The course approach facilitates examining the IoT ecosystem across many different verticals, from automotive technology to healthcare, manufacturing, and industrial control systems. In all cases, the methodology is the same, but the risk model is different. This IoT security training framework ensures students are equipped to assess devices across sectors, with the adaptability to handle emerging technologies and threats.

Once we have been empowered to understand each challenge, we can understand the need for more secure development and implementation practices with IoT devices.

Author Statement

"It has been amazing to watch the progression and widespread adoption of what we now know as the Internet of Things in both our homes and enterprises, whether you realize it or not! However, while IoT-enabled technologies have arguably made our lives better by improving conveniences and our ability to obtain more accurate data about our environment, we unknowingly increase our attack surface through their use.

In other words, the benefits often come at a cost, in many cases because of lackluster development practices by many IoT manufacturers that fail to consider the entirety of the attack surface of their device ecosystem. This failure is largely seen as financial; baking security in from the start is an expense that reduces the already low profit margins on IoT devices. Delays from adopting enhanced security measures can prevent a timely push to market, further compounding profit-per-device issues.

With the increased adoption of IoT, attackers have also focused their efforts on IoT platforms. Techniques and tool abilities have become exponentially more sophisticated, and they are often used for good to unlock additional features and capabilities. However, less ethical attackers have gained the same sophistication with their toolsets, giving them the upper hand in exploiting the technology we rely on for critical tasks. The IoT adoption rate, in combination with the sophistication of attackers, paints a grave picture for the future of IoT and the networks IoT devices are connected to, unless we begin now to improve the security of all facets of the IoT ecosystem.

We are very excited to deliver interactive, hands-on labs and a suite of hardware and software tools to equip IoT analysts and developers with practical skills, methodologies, and thought processes that they can bring back to their organizations and apply on day one. The skills you will build in this class will be valuable for today's IoT technology and serve as a foundation for tomorrow's advancements, regardless of your vertical, application, or data.

We’ve also been actively engaging the use of AI tools to assist the penetration tester. We are happy to share that we’ve included AI-based analysis objectives in many of our labs to further enhance your ability to use these force multipliers, should you see fit. We are hopeful they will accelerate your work as much as it has ours!”

- Larry Pesce and James Leyte-Vidal

2026 Course Update Summary

The latest SEC556 update expands SANS Institute’s hands-on IoT penetration testing course with modern firmware analysis workflows, AI-assisted testing techniques, expanded wireless exploitation labs, and updated offensive methodologies for today’s connected ecosystems.

For a detailed breakdown of what's new and how these updates can strengthen your team, download the flyer.

What You’ll Learn

  • Assess IoT network controls comprehensively
  • Investigate hardware interaction points
  • Uncover firmware vulnerabilities
  • Analyze wireless technology weaknesses
  • Manipulate Bluetooth Low Energy devices
  • Reverse-engineer unknown radio protocols
  • Use AI as a force multiplier for penetration testing activities

Business Takeaways

  • Faster detection of real threats
  • Maximized ROI on existing tools
  • Develops in-house threat detection expertise
  • Defensive coverage against modern tactics
  • Operational confidence and retention
  • Alignment with security goals and audit requirements

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC556: IoT Penetration Testing.

Section 1Introduction to IoT Network Traffic and Web Services

This section introduces IoT security challenges, focusing on testing methodologies applicable across diverse implementations. Students explore threat modeling, network reconnaissance, web application vulnerabilities, and API interaction techniques. The section emphasizes practical strategies for identifying and exploiting IoT network and web-based vulnerabilities.

Topics covered

  • Course methodology introduction
  • IoT testing framework
  • Network discovery techniques
  • Web service reconnaissance
  • Vulnerability exploitation strategies

Labs

  • AI-assisted threat modeling for IoT devices
  • Analyze an IoT device packet capture
  • Scan and exploit an IoT router device
  • Access a publicly exposed IoT webcam
  • Steal a car through IoT web service APIs

Overview

This course section introduces the overall problem with IoT security and examines how testing can address the problem in largely generic terms, given the multitude of IoT implementations.

The first technical concepts include network recon and attacks, as well as key web application issues often found with IoT devices, such as authentication bypass, RFI, and command injection.

Additionally, we will examine API requests from mobile apps to back-end services and the devices themselves, then use the tools testers need to inspect and exploit network and web-based IoT.

Full Lab Details

  • Lab 1.1 – Use AI to assist with threat modeling various types of IoT devices
  • Lab 1.2 – Perform packet capture analysis of an IoT system, manually and with the assistance of AI
  • Lab 1.3 – Identify the attack surface of an IoT device and exploit vulnerable services
  • Lab 1.4 – Learn how to access and stream data from a webcam
  • Lab 1.5 – Use APIs to access protected functionality of an IoT device

Full Topic Details

  • Course introduction
  • Internet of Things – History and overview
  • IoT testing methodology
  • IoT network analysis and exploitation
  • The Web of Things (WoT)
  • IoT Web services recon
  • Hacking IoT devices on the web
  • Attacking IoT web services APIs

Section 2Exploiting IoT Hardware Interfaces and Analyzing Firmware

Students will learn advanced hardware testing techniques, including device deconstruction, communication interface analysis, and firmware recovery. The section covers destructive and non-destructive testing methodologies, focusing on identifying hardware vulnerabilities and extracting critical system information.

Topics covered

  • Hardware testing fundamentals
  • Device disassembly techniques
  • Communication port identification
  • Firmware analysis methodologies
  • Filesystem exploitation

Labs

  • Obtaining and analyzing specification sheets
  • Sniffing Serial and SPI
  • Recovering Firmware from PCAP
  • Recovering filesystems with Binwalk
  • Pillaging the filesystem

Overview

This section will introduce key concepts to perform recon against various hardware devices for destructive and semi-destructive testing for hardware, as well as hardware identification, communication, and exploitation using various hardware tools.

We will also examine ways to recover device operating systems (firmware) and analyze them to recover stored secrets and various implementation flaws.

Full Lab Details

  • Lab 2.1 – Perform analysis of specification sheets to determine the characteristics of specific IC’s, then dive into plenty of supplemental material from many different IoT verticals
  • Lab 2.2 – Use the provided logic analyzer to sniff serial traffic from a Raspberry Pi, and use the provided Bus Pirate to capture and interact with a SPI flash chip
  • Lab 2.3 – Use both Wireshark and TShark to carve firmware update files from a packet capture
  • Lab 2.4 – Use Binwalk, Binwalk version 3, and Azure Firmware Analysis to extract and analyze various types of firmware
  • Lab 2.5 – Perform analysis of recovered filesystems from firmware, both manually and with the assistance of AI

Full Topic Details

  • Background and importance
  • Opening a device
  • Examining and identifying components
  • Discovering and Identifying Ports
  • A soldering primer
  • Sniffing, interaction, and exploitation of hardware ports
  • Other ways of recovering firmware
  • Firmware analysis
  • Pillaging the firmware

Section 3Exploiting Wireless IoT: WiFi, BLE, Zigbee, LoRA, and SDR

This section explores wireless technologies prevalent in IoT ecosystems, providing comprehensive techniques for traffic capture, network access, and device compromise. Students will gain expertise in analyzing standard and proprietary wireless communication protocols.

Topics covered

  • WiFi security assessment
  • Bluetooth Low Energy vulnerabilities
  • Zigbee protocol analysis
  • LoRA communication techniques
  • Software-Defined Radio exploration

Labs

  • WiFi PSK cracking
  • Bluetooth Low Energy interaction
  • Zigbee traffic analysis
  • Conducting a replay attack on IoT

Overview

This course section focuses on the more popular and developing, documented, and standardized wireless technologies often found in IoT technology.

The concepts introduced include capturing traffic, gaining access to networks and encrypted data, and interacting with and compromising IoT devices and their functions.

The section will introduce the concepts to analyze and exploit non-standard and proprietary RF communications often found in IoT devices.

Full Lab Details

  • Lab 3.1 – Learn the particulars of basic Wi-Fi adapter manipulation and mode switching, then use Kismet to perform recon and traffic capture. Finally, crack recovered handshakes to retrieve pre-shared keys
  • Lab 3.2 – Use the provided Bluetooth adapter to connect to and manipulate a IoT device hosted on your Raspberry Pi
  • Lab 3.3 – Use your provided CC2531 adapters to play (and capture) signals from a Zigbee IoT device, as well as analyze previously captured traffic using the Killerbee suite
  • Lab 3.4 – Use your provided HackRF Software Defined Radio to capture RF signals from an IoT device, and replay them, then perform analysis of those signals using URH. Additionally, use AI to perform identification and analysis of unknown wireless signals

Full Topic Details

  • Wi-Fi
  • Bluetooth Low Energy
  • Zigbee
  • LoRa
  • SDR

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will likely leave the class unsatisfied because you will not be able to participate in hands-on exercises that are essential to this course. Therefore, we strongly urge you to arrive with a system meeting all the requirements specified for the course.

It is critical that you back up your system before class. It is also strongly advised that you do not bring a system storing any sensitive data.

Mandatory System Hardware Requirements

  • CPU: 64-bit x86/AMD64 processor with at least 4 cores, launched in 2020 or later: Intel Core i5/i7/i9 (10th generation or newer) or Intel Core Ultra 5/7/9, or AMD Ryzen 5/7/9 equivalent.
  • Apple Silicon Support: This course fully supports Apple Silicon (M1/M2/M3/M4/M5) MacBooks using VMware Fusion and specially built ARM64 virtual machines. Students with Apple Silicon devices receive ARM64 Linux virtual machines that provide native performance on these platforms.
  • BIOS settings must be set to enable virtualization technology, such as "Intel-VTx" or "AMD-V" extensions. Be absolutely certain you can access your BIOS if it is password protected, in case changes are necessary.
  • 16GB of RAM or more is required.
  • 60GB of free storage space or more is required.
  • At least one available USB 3.0 Type-A port. A Type-C to Type-A adapter may be necessary for newer laptops and is a suitable replacement if no Type-A ports are available. Some endpoint protection software prevents the use of USB devices, so test your system with a USB drive before class.
  • Wireless networking (802.11 standard) is required. There is no wired Internet access in the classroom.
  • A wired Ethernet network adapter is required for this course. This can be either an internal or an external USB-based network adapter but you cannot use wireless networking alone.

Mandatory Host Configuration and Software Requirements

  • Your host operating system must be the latest version of Windows 11, or macOS 15 (Sequoia) or newer.
  • Fully update your host operating system prior to the class to ensure you have the right drivers and patches installed.
  • Linux hosts are not supported in the classroom due to their numerous variations. If you choose to use Linux as your host, you are solely responsible for configuring it to work with the course materials and/or VMs.
  • Local Administrator Access is required. (Yes, this is absolutely required. Don't let your IT team tell you otherwise.) If your company will not permit this access for the duration of the course, then you should make arrangements to bring a different laptop.
  • You should ensure that antivirus or endpoint protection software is disabled, fully removed, or that you have the administrative privileges to do so. Many of our courses require full administrative access to the operating system and these products can prevent you from accomplishing the labs.
  • Any filtering of egress traffic may prevent accomplishing the labs in your course. Firewalls should be disabled or you must have the administrative privileges to disable it.
  • Download and install VMware Workstation Pro 25H2 or later (for Windows 11 hosts), or VMWare Fusion Pro 25H2 or later (for macOS hosts) prior to class beginning. VMware Workstation Pro and VMware Fusion Pro are now free for commercial, educational, and personal use with no license key required. Download the latest version from the Broadcom Support Portal. For those with Windows host systems, Workstation Pro is recommended for a more seamless student experience.
  • On Windows hosts, VMware products might not coexist with the Hyper-V hypervisor. For the best experience, ensure VMware can boot a virtual machine. This may require disabling Hyper-V. Instructions for disabling Hyper-V, Device Guard, and Credential Guard are contained in the setup documentation that accompanies your course materials.
  • Download and install 7-Zip (for Windows Hosts) or Keka (for macOS hosts). These tools are also included in your downloaded course materials.

Your course media is delivered via download. The media files for class can be large. Many are in the 40-50GB range, with some over 100GB. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. You will need your course media immediately on the first day of class. Do not wait until the night before class to start downloading these files.

Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.

Your class uses an electronic workbook for its lab instructions. In this new environment, a second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course's labs.

If you have additional questions about the laptop specifications, please contact customer service.

This course is will enable attack-focused and defense-focused security practitioners, as well as those designing and implementing embedded, IoT, and IIoT solutions across many verticals (automotive, healthcare, consumer electronics, industrial instrumentation, smart home, etc.). This course is suited for:

  • Penetration testers
  • Embedded system developers
  • Security analysts
  • Security architects
  • Product security engineers
  • IoT product developers
  • Anyone releasing an IoT device to market

  • BusPirate 3.6a and cable
  • SPI Flash integrated circuit
  • Solderless breadboard
  • HackRF One with antenna
  • HackRF ANT500 antenna
  • USB Logic analyzer
  • Dupont wires
  • RaspberryPi 2G Vilros Kit (32 Gig SD card) (Note: this comes with a U.S. plug, so international students will need to bring an adapter)
  • USB wireless adapter
  • TP-Link Bluetooth Low Energy USB adapter
  • 433Mhz IoT remote-controlled outlet (110/120V only, EU and APAC students will need to bring a voltage converter)
  • A pair of CC2531 custom-flashed USB Zigbee adapters
  • USB 3.0 4-port hub
  • Ethernet cable
  • Custom Slingshot Linux Virtual Machine (copies for amd64 and arm64 architectures are available)
  • Custom Raspberry Pi image (PIoT.L01)
  • Access to Azure firmware analysis for the duration of the class
  • Access to ChatGPT (GUI) for the duration of the class

Attendees are expected to have a working knowledge of TCP/IP and web technologies and a basic knowledge of the Linux command lines before they come to class. While SEC556 is technically in-depth, it is important to note that programming knowledge is not required for the course.

SEC556 is part of the Offensive Operations curriculum. It is considered a Specialized Penetration Testing course, alongside courses SEC575 iOS and Android Application Security Analysis and Penetration Testing, SEC580 Metasploit for Enterprise Penetration Testing, and SEC617 Wireless Penetration Testing and Ethical Hacking.

IoT (Internet of Things) security training focuses on teaching professionals how to secure connected devices—everything from smart thermostats and industrial sensors to medical equipment and automotive tech. These devices often have limited computing resources and weak default security, making them vulnerable to attack.

At SANS, this training is part of our broader commitment to empower practitioners with real-world, hands-on skills. It typically includes:

  • Secure IoT architecture and design
  • Embedded device forensics
  • Protocol analysis (e.g., MQTT, CoAP)
  • Firmware exploitation and patching
  • Threat modeling for IoT ecosystems
  • Defensive strategies tailored to resource-constrained devices

  • Specialize in a High-Demand Field: Stand out with expertise in IoT—an urgent, underserved cybersecurity domain.
  • Gain Hands-On, Real-World Skills: Learn by doing: reverse firmware, exploit vulnerabilities, and secure devices.
  • Boost Your Market Value: Employers are racing to secure IoT—become the in-house expert they rely on.
  • Qualify for Leadership Roles: Develop cross-functional skills in architecture, threat modeling, and policy.

Relevant Job Roles

Vulnerability Analysis (OPM 541)

NICE: Protection and Defense

Responsible for assessing systems and networks to identify deviations from acceptable configurations, enclave policy, or local policy. Measure effectiveness of defense-in-depth architecture against known vulnerabilities.

Explore learning path

Application Pen Tester

Offensive Operations

Application penetration testers probe the security integrity of a company’s applications and defenses by evaluating the attack surface of all in-scope vulnerable web-based services, clientside applications, servers-side processes, and more. Mimicking a malicious attacker, app pen testers work to bypass security barriers in order to gain access to sensitive information or enter a company’s internal systems through techniques such as pivoting or lateral movement.

Explore learning path

Red Teamer Training, Salary, and Career Path

Offensive Operations

Monitor and analyze activity across cloud environments, proactively detect and assess threats, and implement preventive controls and targeted defenses to protect critical business systems and data.

Explore learning path

Systems Testing and Evaluation (OPM 671)

NICE: Design and Development

Responsible for planning, preparing, and executing system tests; evaluating test results against specifications and requirements; and reporting test results and findings.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
  • Location & instructor

    Virtual (OnDemand)

    Instructed by
    Date & Time
    OnDemand (Anytime)Self-Paced, 4 months access
    Course price
    $5,250 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Live Online Europe October 2026

    Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    €4,935 EUR*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Japan November 2026

    Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    ¥798,750 JPY*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Stay Sharp: Jan 2027

    Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $5,250 USD*Prices exclude applicable local taxes
    Registration Options
Showing 4 of 4

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources