In stock Sniff it. Glitch it. Pwn it.
PWNLAB builds open-source hardware for breaking into IoT, RF and embedded systems, and runs the security research behind it. Portable, field-tested, and priced for every lab. Shipped worldwide through Electronic Cats and partners.
Hardware that does the hard part
Four purpose-built tools for IoT, RF and embedded work. Open source, field-proven, and ready to ship from the Electronic Cats store.
In stock
In stock
Out of stock
In stock Flipper Add-On: Ethernet
Drop your Flipper Zero onto any wired LAN
We use what we build
PWNLAB is a working security lab. We research, test and break real systems, then turn what we learn into the tools you see here.
Security Research
Deep offensive research into IoT, RF and embedded systems. The same work that powers our tools, shared openly with the community.
- Vulnerability discovery
- RF & protocol analysis
- Responsible disclosure
Hardware & IoT Security Testing
End-to-end security testing for connected products, IoT and embedded hardware: from firmware extraction, SWD/JTAG access and fault injection to radio attacks across the full attack surface, before they ship.
- Firmware & SWD/JTAG analysis
- EMFI, glitching & radio attacks
- Pre-launch device assessments
Tooling & Open Hardware
We design, build and ship the open-source hardware and software used by security teams worldwide, and can build custom tooling on request.
- Custom hardware
- Firmware & CLIs
- Open-source by default
Advanced Security Training
RF hacking is the heart of this program. We teach the methodology and the custom tooling we built to do the work, hands-on with the same CatSniffer, Minino and FaultyCat hardware we ship. Delivered on-site or remotely, as private training for corporate and government teams.
- IoT RF hacking
- Medical device RF security
- Industrial systems RF security
- Incident Response & Threat Hunting for SOCs
Our repositories
Public repositories from @pwnlabmx: open hardware and open source, all yours to build on.
Radio Frequency Security Assessment Methodology
DICOM Fuzz Corpus
A public feed of Nmap Scripting Engine Modules
Sniffle for CatSniffer
CatSniffer is an original multiprotocol and multiband board for sniffing, communicating, and attacking IoT (Internet of Things) devices using the latest radio IoT protocols. It is a highly portable USB stick that integrates TI CC1352, Semtech SX1262, and an RP2040 for V3 or a Microchip SAMD21E17 for V2
Minino is an original multiprotocol and multiband board made for sniffing, communicating, and attacking IoT devices. It was designed as a mini Cat that integrates the powerful ESP32C6, GPS, microSD and OLED. This board is a mini swiss army knife for IoT security researchers, developers, and enthusiasts.
Catsniffer firmware
CatSniffer Tools
Faulty Cat is a low-cost Electromagnetic Fault Injection (EMFI) tool, designed specifically for self-study and hobbiest research.
CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security
Nmap - the Network Mapper. Github mirror of official SVN repository.
Workspace to use with the CodeQL extension for Visual Studio Code.
Video of the month
This is what really happens at DEF CON. Our latest reel, straight from the floor at DEF CON 34.
Catch our latest demos, teardowns and field tests over on Instagram. New drops every month.
Follow @pwnlabmxFrom the lab
Releases, research notes and field reports.
PWNLAB at DEF CON 34, on the vendor floor with Electronic Cats
We spent August 6 to 9 at the Las Vegas Convention Center West Hall, sharing the Electronic Cats vendor space and putting the whole PWNLAB lineup into people's hands.
Introducing RFSAM, an open methodology for RF security assessments
RFSAM answers the question every RF audit starts with: you have an unknown signal or an unknown device, so where do you begin, and how do you know what you missed?
FaultyCat firmware v3 lands: a full rewrite with two attack engines
Firmware v3.0.0.0 is a from-scratch rewrite for the v2.x hardware, shipping EMFI and Crowbar engines with Direct and Campaign modes.
A security lab that ships silicon
PWNLAB is a security-research outfit and hardware maker. We build the tools we wish existed for red-teaming IoT and embedded systems, then open-source the lot: schematics, firmware and software, so the community can build, audit and extend.
Our hardware is developed and manufactured in collaboration with Electronic Cats, open-hardware makers based in Mexico, and is certified by the Open Source Hardware Association.
Work with us- RF & IoT sniffingLoRa, Sub-1 GHz, 2.4 GHz, Zigbee, Thread, BLE, Wi-Fi.
- Hardware fault injectionEMFI and voltage glitching for embedded security testing.
- Wired network toolingARP scan/spoof, PCAP capture and analysis on Flipper Zero.
- Open hardware & firmwarePublic schematics, AGPL/CERN-OHL licensing, OTA updates.
Led by experienced researchers
PWNLAB is founded by Paulino Calderón (@cldrn), co-founder of the renowned network and application security consultancy Websec (MX/CA). Author of several research publications and author of Nmap: Network Exploration and Security Auditing Cookbook (3 editions), Mastering the Nmap Scripting Engine and co-author of Practical IoT Hacking. A long-time open source contributor, and an international speaker/instructor at conferences like Black Hat, DEF CON, DragonJARCON, and 8.8.
That same research drives every PWNLAB tool, and it's the expertise you tap when you hire our team.
- Books and publicationsBlog posts, research publications and printed publications.
- Open Source ContributorNmap, Metasploit, OWASP projects, and personal projects.
- International Speaker/InstructorBlackhat US, Blackhat Asia, Blackhat Europe, DEF CON, DragonJARCON, 8.8, and many others.
- Experience+18 years of professional experience
Ready to gear up?
Every PWNLAB tool is open source and ships worldwide through the Electronic Cats store.