← All courses

EMB3D – Threat Analysis for Embedded Devices

The in-depth method and reference course on the MITRE EMB3D™ threat model: from the foundations (risk, threat, vulnerability) through all device properties, all 81 threats, and all mitigations with their tiers, to a complete worked analysis of an example device. Every lesson is self-contained and can be called up individually as a reference chapter. Note: This course is voiced by AI voices (AI narrated).

What you'll learn

  • Justify why embedded devices need a threat model of their own
  • Explain EMB3D's three pillars (properties, threats, mitigations) and their mappings
  • Fully enumerate a device's properties and map them to threats
  • Assess and prioritize threats using maturity and evidence
  • Select mitigations tier-based (foundational first, complementary vs. superseding)
  • Carry out a complete EMB3D analysis and hand it over to risk management
  • Use the course as a knowledge base: every lesson is a reference chapter

Tags

securitythreat-modelingemb3dembeddedeacgAI narrated
Module 01 - Why Embedded Is Different
  • Introduction 2:21
  • The Most Unremarkable Device Is the Most Critical One 6:08
  • Without These Four Words, No Analysis Gets Off the Ground 6:47
  • Module Recap: The Questions Worth Sitting With 3:17
  • Match the Term to Its Meaning
Module 02 - What Is EMB3D? Origins, Blueprint, Boundaries
  • What Is EMB3D? Origins, Blueprint, Boundaries 0:16
  • EMB3D's Three Pillars — Built by an Operator, Two Researchers, and a Catalog-Keeper 13:36
  • EMB3D Delivers Atomic, Device-Bound Threats — Not a Full Deployment Model 5:33
  • In Scope or Out of Scope for EMB3D?
Module 03 - Device Properties: The Device's Map
  • Device Properties: The Device's Map 0:16
  • A Property Is Attack Surface — Even When Something's Missing 6:06
  • Hardware Properties: What the Board Itself Gives Away 8:35
  • System Software Properties: Who's Really in Control Once It Boots 11:06
  • Application Software Properties: Where Business Logic Meets the Attacker 7:34
  • Networking Properties: The Smallest Category, the One That Recurs Everywhere 6:31
  • The Property Inventory: Collecting It, Mapping It, Sharing It 8:20
  • Module Recap: From Populated Headers to Packet Captures 5:41
  • Match the Device Feature to Its Property Category
Module 04 - Reading & Rating Threats
  • Reading & Rating Threats 0:15
  • A TID Entry Always Answers the Same Three Questions 7:34
  • Maturity Separates Real Danger From Academic Risk — But Fifteen Years of Service Life Changes the Math 7:22
  • Module Recap: How Real, and How Long It Stays That Way 3:29
  • Rate the Maturity From the Evidence
Module 05 - The Threat Catalog: All 81 Attack Patterns, Explained
  • The Threat Catalog: All 81 Attack Patterns, Explained 0:24
  • Hardware Threats: Side-Channels & Fault Injection 13:06
  • Hardware Threats: Memory & Buses 10:57
  • Hardware Threats: Peripherals & Debug Ports 14:29
  • System Software Threats: Boot, Update Chain & Root of Trust 16:34
  • System Software Threats: OS, Kernel & Privileges 15:33
  • System Software Threats: Virtualization, Diagnostics & Logs 13:10
  • Match the Threat to Its Family
  • The Code Running On Your Device Is Its Own Battlefield 15:34
  • The Front Door Is Usually Unlocked, Not Broken Down 12:38
  • When Encryption Is Present But Doesn't Actually Protect You 10:13
  • The Web Vulnerabilities You Already Know, Now Running On a Device You Can Hold 11:38
  • The Network Assumes Good Faith, and Some Protocols Never Learned Otherwise 14:37
  • Match Each Scenario to Its Threat
  • Module Recap: Eighty-One Threats, One Question 7:10
Module 06 - Mitigations: What the Device Itself Must Do
  • Mitigations: What the Device Itself Must Do 0:29
  • A Mitigation Lives Inside the Device — 'Isolate It' Doesn't Count 7:24
  • Excursus: What Is IEC 62443, Before We Map to It? 10:08
  • Tiers Make Mitigations Plannable: Foundational First 9:57
  • Mitigations: Boot, Integrity & the Update Chain 28:36
  • Mitigations: Code & Memory Hardening 16:24
  • When an Attacker Can Touch the Board, These Mitigations Are What Stand Between Them and Your Secrets 26:52
  • The Buses and DMA Paths Between Chips Need Their Own Locks, Not Just the Chips Themselves 27:17
  • Every Other Mitigation in This Course Leans on Cryptography — Here's What Makes That Foundation Solid 24:26
  • Most Breaches Don't Need Cleverness — They Need a Door Nobody Locked, and This Family Locks It 27:18
  • Mitigations: Web & Network Protection 32:27
  • Mitigations: Isolation, Logging & Formal Methods 30:34
  • Order the Bootloader Tier Ladder, First Line of Defense to Strongest
  • Complementary or Superseding? Decide for Each Mitigation Pair
  • Module Recap: What the Device Itself Has to Prove 7:25
Module 07 - Running the Analysis: AquaSense 300, End to End
  • Running the Analysis: AquaSense 300, End to End 0:18
  • A Real Analysis Starts With the Device Defined, Not With the Catalog Open 6:04
  • Design-Time Beats the Finished Product 5:05
  • Step 1: Enumerate Every Property, and the Catalog Hands You the Threats 8:03
  • Step 2: Every Relevance Call Needs a Reason You Can Show Someone Else 5:54
  • Step 3: Naming the Gap Is What Turns a Threat Into a Roadmap 6:02
  • The Deliverable Is a Document That Carries Every Decision You Made 5:28
  • Module Recap: One Device, Three Steps, One Document 5:45
  • Transfer Check: Run the Process on a Smart Electricity Meter
Module 08 - Drawing Conclusions: Roles, Regulation, Staying Current
  • Drawing Conclusions: Roles, Regulation, Staying Current 0:18
  • Three Roles, Three Different Conclusions From the Same Analysis 6:56
  • EMB3D Is Alive, and So Is Your Analysis 6:55
  • Module Recap: One Analysis, Three Desks 4:12
Module 09 - Final Exam
  • Final Exam 0:14
  • Final Exam — 32 Questions Across All Eight Modules
  • Take-home messages 0:54