JTAGulator: Assisted Discovery Of On-Chip Debug Interfaces

Presented at DEF CON 21 (2013), Aug. 3, 2013, 5:30 p.m. (50 minutes)

On-chip debug (OCD) interfaces can provide chip-level control of a target device and are a primary vector used by hackers to extract program code or data, modify memory contents, or affect device operation on-the-fly. Depending on the complexity of the target device, manually locating available OCD connections can be a difficult and time consuming task, sometimes requiring physical destruction or modification of the device. In this session, Joe will introduce the JTAGulator, an open source hardware tool that assists in identifying OCD connections from test points, vias, or components pads. He will discuss traditional hardware reverse engineering methods and prior art in this field, how OCD interfaces work, and how JTAGulator can simplify the task of discovering such interfaces.


  • Joe Grand / Kingpin - aka Kingpin   as Joe Grand
    Joe Grand (@joegrand) is an electrical engineer and hardware hacker. He runs Grand Idea Studio (www.grandideastudio.com) and specializes in the design of consumer and hobbyist embedded systems. He created the electronic badges for DEFCON 14 through 18 and was a co-host of Discovery Channel's Prototype This. Back in the day when he was known as Kingpin, he was a member of the infamous hacker group L0pht Heavy Industries.