I see IoT is a massive attack surface now. Does the current CEH curriculum go into depth on hacking IoT devices, or is it mostly just a mention?
I am really interested in this specialization and I want to know if the CEH is a good starting point.
The CEH curriculum includes a module on IoT hacking that provides a foundational overview of architecture, common vulnerabilities, and attack surfaces, but it does not offer the technical depth required for advanced specialized firmware analysis or hardware exploitation.
1 answer
To provide an analytical assessment of your inquiry, one must look at the official EC-Council exam objectives for the Certified Ethical Hacker (CEH) certification. While the curriculum has been updated to include a module specifically titled Internet of Things (IoT) Hacking, it is imperative to temper your expectations regarding the depth of coverage provided.
Based on current industry standards and the EC-Council v12/v13 body of knowledge, the coverage remains foundational rather than granular. You will encounter the following components:
- Conceptual understanding of IoT architecture and communication protocols.
- High-level discussions on common vulnerabilities such as weak authentication and insecure interfaces.
- Basic methodologies for mapping the attack surface of IoT ecosystems.
If your goal is to achieve mastery in embedded systems security or reverse engineering firmware, the CEH will likely fall short of your requirements. The certification is designed as a broad-spectrum credential to establish a baseline of security literacy across diverse domains. For specialized IoT penetration testing, you would be better served by pursuing certifications focused on embedded security or hardware hacking, such as those offered by OffSec or specialized industry-specific training. The CEH serves as a generalist benchmark, not a specialized technical deep dive into the complexities of industrial or consumer IoT hardware exploitation.
Samuel, you’re spot on. CEH is basically a mile wide and an inch deep. If anyone expects to actually exploit hardware after reading their IoT module, they're in for a very rude awakening.