Chip-off and in-circuit access
Direct component and board-level acquisition where normal software routes cannot provide the required access or evidence.
Device hardware security
Hands-on security testing for embedded, automotive and connected devices. Rootworks extracts and analyses firmware, verifies boot and debug controls, and builds the modifications and custom test harnesses needed for repeatable assessment.
Below the software boundary
Production devices are designed to conceal their internal state, not expose it to an attacker. Useful security evidence may depend on recovering firmware, understanding storage, validating the boot chain or reaching interfaces that were disabled before release.
Rootworks works directly with the device to establish that access, then creates a controlled environment in which findings can be investigated and reproduced.
Hardware assessment capabilities
Each engagement combines the techniques needed to answer the product-security question, rather than stopping at the interfaces exposed by default.
Direct component and board-level acquisition where normal software routes cannot provide the required access or evidence.
Identify storage devices and recover firmware, partitions and supporting data for preservation and deeper analysis.
Examine boot integrity, trust decisions and enforcement behaviour to determine whether unauthorised code can execute.
Identify JTAG and other engineering paths, then verify how effectively production devices restrict privileged access.
Unpack and examine recovered firmware to understand exposed services, security controls, secrets and attack paths.
Re-enable engineering features or introduce purpose-built test functionality to support a deeper, evidence-led assessment.
Test enablement
A production unit is not always a useful security test target. Rootworks can re-enable engineering functionality, add controlled instrumentation and modify the device so its behaviour can be observed without losing sight of the original production configuration.
The result is a practical research environment for investigating attack paths, validating controls and reproducing findings with stronger evidence.
Custom test harness engineering
Standard laboratory equipment rarely connects cleanly to a finished product. Rootworks designs and builds test harnesses around the device under test, exposing the signals and controls needed for safe, repeatable investigation.
Break out and organise the interfaces required for firmware acquisition, debug access and device instrumentation.
Provide consistent power, state control and connection paths so tests can be repeated without fragile manual setup.
Connect the device to the tools, instrumentation and workflows needed to capture evidence and verify results.
Add controlled functionality where necessary to support deeper investigation, regression checks or automation.
Engagement workflow
The sequence adapts to the product and assurance goal, while keeping modifications, evidence and conclusions traceable.
Map the hardware, storage and available interfaces.
Establish or restore the engineering access needed for testing.
Add controlled visibility into device state and behaviour.
Build a stable, repeatable connection around the target.
Investigate firmware, controls and credible attack paths.
Reproduce findings and provide evidence-led remediation.
Useful engineering evidence
Start with the device
Share the device, available documentation and the security questions your team needs answered. Rootworks will propose a practical route into the hardware and a clear next step.