Brown Fine Security
Official@brownfinesecurity
IoT Pentesting Services
Agent Skills by Brown Fine Security
Showing 16 vetted skills indexed across 1 GitHub repositories.
jtagprobe
Probe IoT targets for exposed SWD and JTAG debug interfaces using a SEGGER J-Link.
logicmso
Analyze Saleae Logic MSO binary captures and decode UART, SPI, I2C, and 1-Wire protocols.
netflows
Extract TCP and UDP flows from pcap files with DNS hostname resolution.
jadx
Decompile Android APK DEX bytecode into readable Java source code.
nmap
Identify open ports and enumerate network services with Nmap.
picocom
Interact with UART serial consoles using picocom with session logging.
chipsec
Analyze offline UEFI firmware dumps to detect malware and vulnerabilities.
apktool
Decode Android APK resources and disassemble smali code for analysis.
onvifscan
Test ONVIF devices for authentication vulnerabilities and weak credentials.
telnetshell
Execute Telnet commands and enumerate IoT devices with session logging.
IoT UART Console (picocom)
Automate serial console interaction with IoT devices via picocom.
Nmap Scan
Automates two-phase Nmap scanning for ports, services, versions, and NSE vulnerabilities.
Ffind
Detect artifact file types and extract ext2/3/4 or F2FS filesystems from firmware images.
Wsdiscovery
Locate WS-Discovery enabled devices and output device metadata in JSON or text.
IoTNet
Analyze IoT network traffic from PCAP files or live captures to detect protocols and security vulnerabilities.
IoT Telnet Shell (telnetshell)
Automate telnet interactions with IoT device shells using Python 3 and pexpect.
Frequently Asked Questions About Brown Fine Security
FAQPage SchemaWhat specific security tasks can be performed using these capabilities?▼
These capabilities enable comprehensive IoT security assessments, including UART serial console interaction, UEFI firmware dump analysis, Android APK resource decoding, and network protocol vulnerability scanning. You can identify open ports, enumerate services, and test authentication mechanisms on ONVIF-compliant devices and WS-Discovery enabled hardware.
Which technical personas benefit most from these security assessments?▼
Hardware security researchers, embedded systems engineers, and mobile application penetration testers benefit from these capabilities. The suite is designed for professionals tasked with auditing the security posture of connected devices, analyzing proprietary firmware, and identifying vulnerabilities within Android-based mobile applications.
What are the primary prerequisites for running these security assessments?▼
Execution requires a Linux-based environment with access to target device hardware interfaces or captured network traffic files. Dependencies include standard network scanning utilities, firmware extraction binaries, and decompilation engines for Java-based bytecode analysis. Ensure appropriate physical access to UART headers or network segments for live testing.