Come see how I used my jerry-rigged “EMBite” probe to capture an EM side-channels using a HackRF.
I used this to figure out the precise timing of where a completely unknown boot check fails - and then used that timing to bypass the check 😁
https://www.offensivecon.org/speakers/2024/stacksmashing.html

