Pentesting for robots, IoT and physical fleets.
Nine RoboSec capabilities in one autonomous swarm — from the MQTT broker at the top to the JTAG pin on the robot. Evidence-graded findings with hardware-safe proofs.
Nine RoboSec capabilities
- MQTT broker attacks — auth bypass, topic enumeration, retained-message exfil.
- ROS2 / DDS discovery — node inventory, unauthenticated actuator commands.
- Firmware supply-chain analysis and unsigned OTA detection.
- Fleet-management API IDOR and unsigned OTA promotion paths.
- BLE / RF / Zigbee radio scanning and sniff-and-replay.
- Robot local-admin consoles — default creds, undocumented debug endpoints.
- UART / JTAG / USB physical debug and boot-chain integrity audit.
- Enrollment / attestation auditing and command-replay / OTA-downgrade tests.
Every physical-debug probe is bounded and reversible. Destructive classes are default-deny and surface as gated-capability notices in the report.
Related RoboSec and IoT reading
- Agentic pentesting explained — how autonomous agents extend from IT into robotic systems.
- The SwarmHack engine — the kill chain driving the 9 RoboSec capabilities.
- SSE and ZTNA validation — where RoboSec crosses the network edge and identity plane.
- Agent capability reference — MQTT, ROS2/DDS, firmware and radio plugins in detail.
- Authorization envelope — signed scope for radio and physical operations.
- The SwarmHack story — why swarm behaviour suits heterogeneous device fleets.