hardware-ctf
Installation
SKILL.md
Hardware CTF
Solve hardware and embedded lab tasks by identifying the capture or device interface first, then decoding with timing, voltage, framing, and architecture assumptions made explicit.
When this skill applies
- Logic analyzer captures, Saleae
.salfiles, sigrok sessions, CSV edge traces, oscilloscope traces, audio captures of serial data, or display-signal samples. - UART, I2C, SPI, CAN, CANopen, JTAG, SWD, USB HID, USB MIDI, Bluetooth RFCOMM/BLE, RF/SDR, RFID/NFC, or peripheral PCAPs.
- Firmware images, SPI flash dumps, UEFI/BIOS blobs, bootloaders, microcontroller binaries, extracted filesystems, board photos, pinouts, schematics, CAD, G-code, or 3D-printing artifacts.
- Side-channel data such as power traces, timing traces, acoustic keyboard samples, LED Morse, or EM/RF measurements.
Operating model
- Preserve evidence and identify artifact class: capture, firmware, board/interface, RF sample, side-channel dataset, or CAD/G-code.
- Lock physical assumptions: sample rate, voltage domain, channel order, idle level, clock, endian, bit order, modulation, architecture, and toolchain.
- Decode the transport before interpreting payloads: bus framing, packet boundaries, checksums, compression, filesystem, or symbol timing.
- Choose the narrowest tool path: protocol decoder, firmware extractor, disassembler, emulator, SDR flowgraph, side-channel statistic, or visualization.
- Validate by reconstructing an observable: secret bytes, image, waveform, register trace, firmware string, UART console output, HID path, RF message, or 3D geometry.
- Record every assumption that affects decoding so the proof can be replayed or corrected.