finds.dev← search

// the find

attify/firmware-analysis-toolkit

★ 1,607 · Rust · NOASSERTION · updated Sep 2026

Firmware security research platform combining binary analysis, taint tracing, and emulation across IoT, edge AI, mobile devices, and robotics.

FAT is a Rust CLI for firmware security research — identify unknown blobs, extract filesystems, run static/taint analysis on binaries and shell scripts, and drive QEMU-based emulation for dynamic testing. It's built by Attify as the tooling behind their IoT exploitation training, and covers ground from bare-metal MCU images and bootloaders up through Android APKs and on-device ML model formats.

The scope is unusually wide but organized coherently: identify -> extract -> analyze -> emulate as one pipeline instead of a grab-bag of scripts, with real crate separation (fat_extract, fat_analyze, fat_backend, fat_emulate) and test suites per crate. It writes its own SquashFS/cramfs parsers in Rust rather than shelling out to external extractors. MCU/bare-metal support (vector tables, memory maps, peripheral hints, flash-write authority) and Edge AI model inspection (TFLite, ONNX, Qualcomm DLC) cover formats most firmware tools skip entirely. The r2-triage -> sink-discovery -> instrument-hooks chain actually connects static findings to runtime hooks for emulation, which is normally left as manual glue work in comparable tools.

License is FSL-1.1-ALv2, a source-available license with a delayed conversion to a permissive one — not OSI open source, and a real blocker if you want to fork, redistribute, or build on it commercially today. The command surface is enormous (70+ subcommands in fat_cli alone), so the actual learning curve is steep despite the README's claim that it's approachable for newcomers. Emulation runs untrusted vendor firmware via QEMU with no sandboxing built into the tool itself — the SECURITY.md warning is honest, but isolation is entirely on the user. It's effectively single-maintainer (adi0x90) and doubles as courseware for Attify's paid training, so roadmap priorities may track curriculum needs more than general community requests.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →