The bench, one shelf at a time
Everything to start hardware hacking, grouped by what you are attacking. You do not need all of it: grab the core kit, then add a shelf when a course calls for it.
The core kit
A shell, a chip dump, and a look at any bus. Everything else is situational.
Serial & console
get a shell, read boot logs
CORE
Turns a debug serial header into a USB console. The single most useful tool on the bench.
CORE
Captures and decodes UART, SPI and I2C off the wire. Find the baud rate, read the bus.
Continuity to find GND, voltage to spot TX. The cheap tool that saves fried boards.
Flash & chips
dump firmware off the board
CORE
Reads and writes SPI flash chips over USB. With a clip, dumps a whole firmware image.
CORE
Clamps onto a 25-series flash chip in-circuit, no desoldering. The other half of the dump.
One tool that speaks UART, SPI, I2C and more. Great for poking an unknown bus interactively.
Radio & RF
sniff and replay the air
Receive-only software radio. Watch 433 MHz remotes, pagers and telemetry in the spectrum.
A bare 433/868 MHz transceiver that transmits as well as receives. Wire it to a host and drive it with rfcat.
An all-in-one pocket multi-tool: sub-GHz radio, NFC, infrared, GPIO and BadUSB, with the tooling built in.
Sniffs 802.15.4 and BLE. Flash a sniffer firmware to watch Zigbee and Bluetooth.
A half-duplex TX/RX software radio, 1 MHz to 6 GHz. The step up from an RTL-SDR when a job needs to transmit.
A purpose-built Bluetooth/BLE sniffer that follows a live connection across its frequency-hopping channels.
Debug & automotive
JTAG/SWD and the CAN bus
Halt the CPU, read memory, extract keys. A cheap ST-Link for SWD, an FT2232H for full JTAG.
Put your laptop on a vehicle CAN bus. Read frames, replay them, and speak UDS.
One FT2232H board for UART, JTAG, SWD, SPI and I2C. Replaces carrying a separate adapter for each bus.
A cheap Wi-Fi/Bluetooth SoC board: the go-to practice target for flash dumps, eFuses and secure boot, and a scriptable attack platform.
RFID & NFC
clone badges and cards
CORE
The RFID/NFC reference tool. LF and HF antennas on one box: read, emulate, and brute-force a huge range of tags.
A cheap PC/SC 13.56 MHz reader driven by libnfc. Covers HF/NFC recon without the Proxmark3's price tag.
A gen1a/gen2 MIFARE Classic clone with a writable block 0. The blank every recovered dump gets cloned onto.
Fault injection
glitch a chip into misbehaving
CORE
A synchronized side-channel and glitch platform. Capture power traces for CPA, or trigger a voltage/clock glitch to skip a check.