Top 6 C iot-security Projects
-
IoTGoat
IoTGoat is a deliberately insecure firmware created to educate software developers and security professionals with testing commonly found vulnerabilities in IoT devices.
-
Kargo
Stop Scripting Promotions. Start Shipping with Kargo. Kargo automates promotion across dev, staging, and prod with approval gates and verification. Open source, built by the team behind Argo CD. Download now.
-
-
Embedded-Hacking
A FREE comprehensive step-by-step embedded hacking course covering Embedded Software Development to Reverse Engineering.
-
snif
Public, browser-trusted HTTPS for any device behind NAT — the device keeps its private key, the relay forwards SNI-routed ciphertext and can't read the traffic. Relay + connector + CA proxy; IETF draft-zubov-snif.
-
wolfCOSE
A fast, portable, and lightweight COSE + CBOR implementation for embedded systems. Supports PQC, FIPS 140-3, DO-178, and MISRA C. Powered by wolfSSL.
Project mention: wolfSSL releases a new product; wolfCOSE a zero alloc C embbedded COSE stack | news.ycombinator.com | 2026-05-302 things of notice in the readme as recently I've been in the efficient binary communication hunt:
1. .text size without clarifying the architecture, flags, and compiler is meaningless unless it's all rodata
2. Saying it takes 0 .bss and .data just means it allocates everything elsewhere and that can be helpful to know. Of course in compilation that'll also be dependent on how and for what it's built. To say it's zero alloc is incorrect or at best misleading. Here's a line of code that allocates. Pretty close to the start of the real code: https://github.com/wolfSSL/wolfCOSE/blob/b90b34abcba90aa7b8a... . Sure it's just 1 pointer but anyone in embedded who's had to increase stack size to use a fancy function knows what I'm talking about. I'm looking at you, sscanf. Some of this code will allocate hundreds if not low thousands of bytes onto the stack. Which is maybe fine but don't say it's zero alloc just because it's all on the stack.
-
wolfCOSE
Fast, lightweight COSE + CBOR implementation for embedded systems. Supports PQC, FIPS 140-3, and MISRA C. Powered by wolfSSL. (by aidangarske)
Project mention: Show HN: WolfCOSE, a zero alloc C COSE with multi-sign/recipient, and PQC | news.ycombinator.com | 2026-05-05