Gear

The bench, one shelf at a time

Everything to start hardware hacking, grouped by what you are attacking. You do not need all of it: grab the core kit, then add a shelf when a course calls for it.

20 tools 6 categories from 2€ core kit ~22€
Start here

The core kit

A shell, a chip dump, and a look at any bus. Everything else is situational.

Serial & console

get a shell, read boot logs
USB-UART adapter CORE
TTL 5–10€
USB-UART adapter

Turns a debug serial header into a USB console. The single most useful tool on the bench.

Logic analyzer CORE
LA 10–15€
Logic analyzer

Captures and decodes UART, SPI and I2C off the wire. Find the baud rate, read the bus.

Multimeter
DMM 15–30€
Multimeter

Continuity to find GND, voltage to spot TX. The cheap tool that saves fried boards.

Flash & chips

dump firmware off the board
CH341A programmer CORE
SPI 3–6€
CH341A programmer

Reads and writes SPI flash chips over USB. With a clip, dumps a whole firmware image.

SOIC-8 test clip CORE
CLIP 4–8€
SOIC-8 test clip

Clamps onto a 25-series flash chip in-circuit, no desoldering. The other half of the dump.

Bus Pirate
BP 30–40€
Bus Pirate

One tool that speaks UART, SPI, I2C and more. Great for poking an unknown bus interactively.

Radio & RF

sniff and replay the air
RTL-SDR
SDR 25–35€
RTL-SDR

Receive-only software radio. Watch 433 MHz remotes, pagers and telemetry in the spectrum.

CC1101 module
RF 5–10€
CC1101 module

A bare 433/868 MHz transceiver that transmits as well as receives. Wire it to a host and drive it with rfcat.

Flipper Zero
MULTI 170€
Flipper Zero

An all-in-one pocket multi-tool: sub-GHz radio, NFC, infrared, GPIO and BadUSB, with the tooling built in.

nRF52840 dongle
nRF 10–15€
nRF52840 dongle

Sniffs 802.15.4 and BLE. Flash a sniffer firmware to watch Zigbee and Bluetooth.

HackRF One
HRF 320€
HackRF One

A half-duplex TX/RX software radio, 1 MHz to 6 GHz. The step up from an RTL-SDR when a job needs to transmit.

Ubertooth One
UBT 120€
Ubertooth One

A purpose-built Bluetooth/BLE sniffer that follows a live connection across its frequency-hopping channels.

Debug & automotive

JTAG/SWD and the CAN bus
JTAG/SWD probe
JTAG 3–25€
JTAG/SWD probe

Halt the CPU, read memory, extract keys. A cheap ST-Link for SWD, an FT2232H for full JTAG.

USB-CAN adapter
CAN 15–30€
USB-CAN adapter

Put your laptop on a vehicle CAN bus. Read frames, replay them, and speak UDS.

Tigard
FT2232 40€
Tigard

One FT2232H board for UART, JTAG, SWD, SPI and I2C. Replaces carrying a separate adapter for each bus.

ESP32 dev board
ESP 5–10€
ESP32 dev board

A cheap Wi-Fi/Bluetooth SoC board: the go-to practice target for flash dumps, eFuses and secure boot, and a scriptable attack platform.

RFID & NFC

clone badges and cards
Proxmark3 CORE
PM3 250–300€
Proxmark3

The RFID/NFC reference tool. LF and HF antennas on one box: read, emulate, and brute-force a huge range of tags.

NFC
NFC 30€
ACR122U

A cheap PC/SC 13.56 MHz reader driven by libnfc. Covers HF/NFC recon without the Proxmark3's price tag.

UID
UID 2–5€
Magic card (UID-writable)

A gen1a/gen2 MIFARE Classic clone with a writable block 0. The blank every recovered dump gets cloned onto.

Fault injection

glitch a chip into misbehaving
ChipWhisperer CORE
CW 250–350€
ChipWhisperer

A synchronized side-channel and glitch platform. Capture power traces for CPA, or trigger a voltage/clock glitch to skip a check.