Microcontroller reverse engineer
Microcontroller reverse engineer
Everything they make, We can break! 
  HOME COMPANY PCB COPY MCU HACK FAQ CONTACT US
Disassembler Software   
WHY US ?
World first mcu hack company
In business since 1998
Reversed tens of thousands of chips
Copied thousands of pcbs
Foreseen all pertential problems
Integrity with payments
crack ic
 
 
Introduction to Reverse Engineering Software

Chapter 7. Debugging

Table of Contents

User-level Debugging

User‑Level Debugging & Executable Formats

Practical debugging, memory inspection, and the internals of ELF and PE binaries.

DDD – The Data Display Debugger

DDD provides a graphical front‑end to GDB, the GNU debugger. While command‑line GDB is perfectly capable, reverse engineering often benefits from having multiple views—stack, registers, disassembly—simultaneously visible in one workspace. DDD offers this, and also includes a GDB command‑line pane, so nothing is lost.

Knowing GDB’s internal commands remains useful for actions that are awkward to perform via the GUI. GDB has a topic‑based help system (help lists categories). DDD can even echo GUI‑triggered commands to the console, helping you learn the command syntax. Key commands we frequently use include:

  • run, break, cont, stepi, nexti, finish, disassemble, bt, info [registers|frame], and x.

Every GDB command can be prefixed with a repeat count, e.g., stepi 1000 steps through 1000 assembly instructions.

Setting Breakpoints

A breakpoint halts execution at a specific location. The break command accepts a function name, a filename:line_number, or *0xaddress. For instance, break __libc_start_main sets a breakpoint on that well‑known symbol. GDB also supports tab completion, which helps when exploring available symbols—though in production binaries, those are often scarce.

Viewing Assembly

After setting a breakpoint (say, on __libc_start_main), DDD can display the disassembly in the lower half of the source window. To switch to Intel syntax, go to Edit → GDB Settings and choose the desired Disassembly flavor, or issue set disassembly-flavor intel at the GDB prompt. Using DDD’s menus saves your preference across sessions.

Examining Memory and the Stack

The x (examine) command is the primary tool for memory inspection. Its syntax is:

x /<count><format><size> <address>
  • Format letters: o (octal), x (hex), d (decimal), u (unsigned), t (binary), f (float), a (address), i (instruction), c (char), s (string).
  • Size letters: b (byte), h (halfword), w (word), g (giant, 8 bytes).

For example, x /32xw 0x400000 dumps 32 words (4‑byte values) starting at that address. You can also use registers as addresses by prefixing with $, e.g., x /32xw $esp displays the top 32 words on the stack.

In DDD, the Data Window (via View → Data Window) lets you create persistent displays. You can type any expression or even a GDB command (in backticks) such as `x /32xw $esp` and have it update automatically as you step. Add these to the menu for quick access.

Displaying Memory as Data Structures

DDD excels at visualising structured data. By casting an address to a pointer of a known type, DDD will render the structure graphically. If the structure contains pointers, clicking on them opens further displays.

When the target binary lacks debug symbols, you can still define custom types. Compile a .c file with your suspect structures (and any required headers) as a shared library (gcc -shared). Then, before debugging, set set env LD_PRELOAD=file.so in GDB. From then on, those types become available as if they were native to the program.

💡 Watchpoints – a separate breakpoint type that triggers on data access – are also supported; the document notes they are useful but leaves detailed examples for later.

WinDbg – The Windows Debugger

WinDbg is part of Microsoft’s free Debugging Tools for Windows. It provides a GUI with an embedded command line, similar to console debuggers like ntsd. The help file offers comprehensive documentation.

Breakpoints

Breakpoints can be set via the GUI (Edit → Breakpoints, or Alt+F9). From the command line: bp (set), bl (list), bc (delete). Breakpoints can be placed on function names (if symbols exist) or absolute addresses, and even on source lines when source is available (bX filename:linenumber).

Viewing Assembly

Use View → Disassembly in WinDbg, or the u command in ntsd.

Stack Operations

The k command (and variants) shows the call stack. To examine local stack frame contents, db esp ebp is a common shortcut, but this assumes ebp is the frame pointer. If frame‑pointer omission is used, you can inspect memory starting from esp directly. Use .frame X to switch to a specific stack frame (frame numbers from kn).

Memory Access

The d* family of commands reads memory. For instance, dp displays pointers, dw shows words, db dumps bytes. You can specify ranges or lengths: db 77f75a58 l 10 displays 0x10 bytes. The dt command, when symbols are available, attempts to format the data according to its type.

Tips & Tricks

The poi() function dereferences a pointer and returns the pointed‑to value. Combined with user‑defined aliases, this becomes a handy shortcut.

The document includes a full WinDbg session example, stepping through a simple C program, setting breakpoints, examining variables (dt), and dumping memory.


Executable Formats – ELF and PE

Once you understand low‑level code generation, the next question is: how is this code stored on disk? This chapter examines ELF (Linux/UNIX) and PE (Windows) formats, with a focus on the information needed for code modification.

Working with ELF

Under Linux, program execution starts at _start, then __libc_start_main, and eventually main. The OS loads code from various sources into memory based on the ELF specification. ELF defines a standard mapping from disk to a complete runtime image (code, stack, heap, libraries).

ELF Layout

Three main header areas:

  • ELF file header (at the very beginning) – contains the magic number, entry point (e_entry), offsets to program headers (e_phoff) and section headers (e_shoff), plus sizes and counts.
  • Program headers – an array of Elf32_Phdr structures that describe loadable segments (code, data, etc.). Key fields: p_offset (file offset), p_filesz (size in file), p_memsz (size in memory).
  • Section headers – optional, describe named sections (e.g., .text, .data). Used by linkers and debuggers but not required for execution.

Editing ELF

Tools like HT Editor allow direct modification of headers and instructions. However, changing segment sizes can break the binary; more nuanced insertion techniques are discussed in the code modification chapter.

📘 Note: ELF is extremely flexible; some programs deliberately craft abnormal but valid headers to hinder reverse engineering.

Working with PE (Portable Executable)

The PE format is more complex, with multiple ways to refer to locations:

  • File Offset – raw offset in the file.
  • Relative Virtual Address (RVA) – offset from the image base when loaded (not the same as file offset, due to alignment padding).
  • Section Offset – offset within a specific section.
  • Virtual Address (VA) – absolute address in process memory: VA = RVA + ImageBase (typically 0x400000 for executables, variable for DLLs).

PE Headers

Three main structures:

  1. IMAGE_DOS_HEADER – a legacy DOS stub; only the e_lfanew field matters, pointing to the NT headers.
  2. IMAGE_NT_HEADERS – contains the signature (PE\0\0), a IMAGE_FILE_HEADER (with NumberOfSections and SizeOfOptionalHeader), and the IMAGE_OPTIONAL_HEADER.
  3. IMAGE_OPTIONAL_HEADER – holds critical fields like ImageBase, AddressOfEntryPoint, SectionAlignment, FileAlignment, and a DataDirectory array of 16 IMAGE_DATA_DIRECTORY entries.

The Data Directory

Each entry gives an RVA and size. Index 1 points to the Import Directory, which is an array of IMAGE_IMPORT_DESCRIPTOR structures, one per imported DLL.

Import Descriptor

Contains:

  • OriginalFirstThunk (RVA to the “unbound” import thunk table)
  • Name (RVA to the DLL name string)
  • FirstThunk (RVA to the Import Address Table, IAT)

Thunk Tables

Each thunk is a union (IMAGE_THUNK_DATA) that can be an ordinal (high bit set) or an RVA to an IMAGE_IMPORT_BY_NAME structure. The IAT is overwritten at load time with the actual function addresses, serving a role similar to the ELF PLT. Pre‑bound executables may already have guessed addresses, but these can become stale.

The document also notes that PEView is a helpful tool for visual exploration, and that the IAT’s function pointers are the primary target for code hooking (covered in the next chapter).


Code Modification – Overview

The final chapter introduces practical techniques for altering binary behaviour.

Motivations

Modifying closed‑source software, bypassing copy protection, or injecting new functionality.

Library Hooking

On Linux, LD_PRELOAD lets you override standard library functions with your own shared library (except for setuid programs). Example: compiling a .so and setting the variable before running the target.

Instruction Modification

The simplest form: change the mnemonic or its arguments. HT Editor allows direct hex editing with real‑time disassembly feedback. Changing arguments is straightforward; changing the mnemonic is trickier because of varying instruction lengths.

Inserting Instructions / Functions

Single instructions can be inserted if there is unused space (identified by disasm.pl). Entire functions can be added by placing code in unused regions (careful with main and indirect calls). Multiple function insertion may require more elaborate methods, such as using mmap to allocate executable memory.

Attacking Copy Protection

The chapter promises concrete examples, applying these techniques to defeat common protection schemes.

💡 Key insight: Understanding the binary format and the debugger’s capabilities is the foundation for any successful modification. Practice with small test programs before tackling real targets.
📘 Note: The original document contained placeholders (FIXME) for some diagrams, additional examples, and deeper coverage of COM and memory layouts. Those have been summarised here to maintain focus on the core concepts.

This HTML rendering is based on the “User‑Level Debugging & Executable Formats” document. All content is for educational purposes.

  • Mikatech mcu reverse engineer list:
Holtek integrated circuit (ic) attack view more types...
  HT36R/HT45R series mcu crack: HT36RA4 HT36RM4 ...
HT45R02 HT45R03 HT45R04 HT45R05 HT45R06 HT45R07 HT45R09 HT45R0D HT45R0E HT45R23 HT45R24 ...
HT46R series mcu unlock: HT46R04 HT46R12 HT46R14 HT46R22 HT46R23 HT46R232 HT46R24 HT46R46 HT46R47 HT46R48 HT46R51 HT46R52 HT46R53 HT46R54 HT46R62 HT46R63 HT46R64 HT46R65 HT46R652 HT46R71 HT46R72 HT46R73 HT46R74 HT46R82 HT46R83 HT46R84 HT46RB50 HT46RB70 HT46RU25 HT46RU66...
HT47R10 HT47R20...
HT48R series Microprocessor duplicate: HT48R05 HT48R06 HT48R07 HT48R08 HT48R09 HT48R10 HT48R30 HT48R37 HT48R50 HT48R52 HT48R70 HT48RA0 HT48RA1 HT48RA3 HT48RA5 HT48RB8 HT48RU90 HT48X50...
HT49R series mcu unlock: HT49R30 HT49R50 HT49R70 HT49R84 HT49RA0 HT49RB50 HT49RB70 HT49RU90 HT49RV3 HT49RV5 HT49RV7 HT49RV9 ...
HT57R20
HT81R03 HT81R09 HT81R18 HT81R36 ...
HT48F series Microprocessor read software: HT48F06E HT48F10E HT48F30E HT48F50E HT48F70E ...
HT48E series mcu unlock: HT48E06 HT48E10 HT48E30 HT48E50 HT48E70 ...
Infineon Integrated Circuit (ic) Reverse Engineer view more types...
  SAB series mcu code receovery: SAB-C501 SAB-C504 SAB-C505 SAB-C508 SAB-C513 SAB-C515 SAB-C540 SAB-C541 SAB-C516 SAB-XC167 ...
SAF series mcu code retreive: SAFC504 SAF-C164CI-8EM SAF-C504-2EM SAF-C505A-4EM SAF-C505CA-4EM SAF-C505L-4EM SAF-C508-4EM SAF-C508-4EP SAF-C513 SAF-C515 SAF-XC161 SAF-XC164 SAF-XC167C SAF-XC846 SAF-XC856 SAF-XC878 SAF-XC167C886 SAF-XC888 ...
SAH series mcu firmware unlock: SAH-C504-2EM SAH-C505 ...
SAK series Microprocessor code receovery: SAK-C164 SAK-C504 SAK-C505 SAK-C515 SAK-XC161 SAK-XC164 SAK-XC167 SAK-XC846 SAK-XC866 SAK-XC886 SAK-XC888 ...
SAX series mcu code unlock: SAX-XC878 ...
SDA series Microprocessor code receovery: SDA2516 SDA2526 SDA2546 SDA2586 SDA3546 SDA3586...
Intel Microcontroller Reverse Engineer view more types...
  87xx series mcu code extraction: 8741 8741AH 8742 8742AH 8744 8744H 8748 8748H 8749 8749H 8751 8751BH 8751H 8751H-8 87551SB 8752BH 8796BH 8796JF 8797BH 8797JF 8798 ...
87Cxx series mcu code extraction: 87C151SA 87C151SB 87C194 87C196CA 87C196JQ 87C196JR 87C196JT 87C196JV 87C196KB 87C196KC 87C196KD 87C196KQ 87C196KR 87C196KS 87C196KT 87C196LA 87C196MC 87C196MH 87C198 87C251SA 87C251SB 87C251SP 87C251SQ 87C42 87C51 87C51FA 87C51FB 87C51FC 87C51GB 87C51RA 87C51RB 87C51RC 87C52 87C54 87C58 ...
87Lxx series Microprocessor code retreive: 87L42 87L51FA 87L51FB 87L51FC 87L52 87L54 87L58 ...
D87Cxx series mcu code extraction: D87C51 D87C52 D87C54 D87C58 D87C51FA D87C51FB D87C51FC D87C196KC D87C196MC D87C196MD D87C196MH D89C196MD ...
ICT/GOULD Chip Reverse Engineer view more types...
  Peel1/2xx series mcu security read: PEEL153 PEEL173 PEEL153P PEEL173P PEEL253 PEEL273 ...
Peel16xx series mcu security hack: PEEL16CV8 PEEL16V8 ...
Peel18xx series Microprocessor security hack: PEEL18CV8 PEEL18CV8Z PEEL18LV8Z ...
Peel20xx series mcu security hack: PEEL20CG10 PEEL20CG10A PEEL20V8 ...
Peel22xx series controller security hack: PEEL22CV10 PEEL22CV8 PEEL22CV10 PEEL22CV10A PEEL22CV10A PEEL22CV10A PEEL22CV10AZ PEEL22CV10AZ PEEL22CV10AZ PEEL22LV10AZ PEEL22LV10AZ PEEL22LV10AZ ...
Lattice Microcontroller Clone view more types...
  GAL series mcu program receovery: GAL16V8 GAL16V8A GAL16V8B GAL16V8C GAL16V8D GAL16V8Z GAL16LV8 ...
GAL18V10 GAL18V10B ...
GAL20V8A GAL20V8B GAL20V8C GAL20V8Z GAL20LV8 GAL20VP8 GAL20VP8B ...
GAL22V10D GAL22V10C GAL22V10B GAL22V10 GAL22LV10UES GAL22VX10 GAL20XV10B GAL20XV10 GAL20RA10B GAL20RA10 ...
PALCE series mcu program retreive: PALCE610 PALCE610H PALCE630H ...
PALCE16V8Z PALCE16V8Q PALCE16V8H ...
PALCE20V8Q PALCE20V8H ...
PALCE22V10 PALCE22V10H PALCE22V10Q PALCE22V10Z PALCE20RA10Q PALCE20RA10H PALCE20RA10 ...
LCxxx series mcu program software read: LC4032 LC4064 LC4128 LC4256 LC4384 LC4512 LC4032V LC4064V LC4128V LC4256V LC4384V LC4512V ...
IMXXX series Microprocessor program unlock: IM4A3-64 IM4A3-32 IM4A3-96 IM4A3-128 IM4A3-256 IM4A5 IM4A5-64 IM4A5-96 IM4A5-128 IM4A5-256 IM4A5-32 ...
ispLSI series mcu program receovery: ispLSI1016 ispLSI1024 ispLSI1032 ispLSI1048 ispLSI2064 ispLSI2096 ispLSI2128 ispLSI1016E ispLSI1024E ispLSI1032E ispLSI1048E ispLSI2064E ispLSI2096E ispLSI2128E ispLSI3160 ispLSI3192 ispLSI3256 ispLSI3256A ispLSI3256E ispLSI3320 ispLSI8840 ispLSI8600V ispLSI8840V ispLSI81080V ...
ispLST series controller program receover: ispLST1016 ispLST1024 ispLST1032 ispLST2032 ispLST2064 ispLST4032V ispLST4064V ispLST4128 ispLST4256 ispLST4512 ...
Mach series mcu source code program unlock: MACH110 MACH111 MACH120 MACH130 MACH131 MACH210 MACH211 MACH230 MACH436 ...
ispMach series mcu program receovery: ispMach4032C ispMach4064C ispMach4128C ispMach4256C ispMach4384C ispMach4512C ispMach4032B ispMach4064B ispMach4128B ispMach4256B ispMach4384B ispMach4512B ispMach4032V ispMach4064V ispMach4128V...
Maxim Microcontroller Unlock view more types...
  MAX187 series mcu unlock: MAX187ACPA MAX187BCPA MAX187CCPA MAX187AEPA MAX187BEPA MAX187CEPA MAX187ACWE MAX187ACWE MAX187BCWE MAX187BCWE MAX187CCWE MAX187CCWE MAX187CCWE MAX187AEWE MAX187BEWE MAX187BEWE MAX187BEWE MAX187CEWE ...
MAX189 series mcu source code unlock MAX189ACWE MAX189BCWE MAX189CCWE MAX189AEWE MAX189BEWE MAX189CEWE MAX189ACPA MAX189CCPA MAX189AEPA MAX189BEPA MAX189CEPA MAX187AMJA MAX187BMJA ...
MAX813 series mcu unlock MAX813L MAX813LCA MAX813LCEA MAX813LCESA MAX813LCP MAX813LCPA MAX813LCPA MAX813LCSA MAX813LCSAT MAX813LCSE MAX813LCSS MAX813LCST MAX813LCUA MAX813LCXSA MAX813LDPA MAX813LE MAX813LEDA MAX813LEP MAX813LEPA MAX813LEPE MAX813LEPI MAX813LESA ...
MDT/Micon MCU Reverse Engineer view more types...
  MDTxx series mcu software reverse engineer: MDT10P05 MDT10P10 MDT10P20 MDT10P21 MDT10P22 MDT10P23 MDT10P43 MDT10P61 MDT10P62 MDT10P64 MDT10P65 MDT10P72 MDT10P73 MDT10P74 MDT10P41A1 MDT10P41A2 MDT10P621 MDT10P651 MDT10P721 MDT10P55A1 MDT10P55A2 MDT10P55A3 MDT10P55A4 MDT10P55B1 MDT10P55B2 MDT10P55B3 MDT10P55B4 MDT10P56A1 MDT10P56A2 MDT10P56A3 MDT10P56A4 MDT10P57A1 MDT10P57A2 MDT10P57A3 MDT10P57A4 MDT10F84 MDT10F841 MDT2005 MDT2010 MDT2015 MDT2020 MDT2030 MDT2051 MDT53A1 MDT53A2 MDT53A3 MDT53A4 MDT10P712 MDT10P716 ...
Magawin Microcontroller source code Recovery view more types...
  MPC82xx series mcu code receovery: MPC82E52 MPC82E54 MPC82LE52 MPC82LE54 ...
MPC89xx series mcu code receover: MPC89E51 MPC89E52 MPC89E53 MPC89E54 MPC89E58 MPC89E515 MPC89LE51 MPC89LE52 MPC89LE53 MPC89LE54 MPC89LE58 MPC89LE515 ...
MG87Fxx series mcu code receover: MG87FE_L52 MG87FE_L52AE MG87FE_L52AF MG87FE_L52AP MG87FE_L52GE MG87FE_L52GF MG87FE_L52GP MG87FE52AE MG87FE52AF MG87FE52AP MG87FE52GE MG87FE52GF MG87FE52GP MG87FL52AE MG87FL52AF MG87FL52AP MG87FL52GE ...
NEC Microcontroller Program Dump view more types...
  10PIN nec mcu retreive code clone: uPD78F9200 uPD78F9201 uPD78F9202 ...
16PIN nec mcu code clone: uPD78F9210 uPD78F9211 uPD78F9212 uPD78F9510 uPD78F9511 uPD78F9512 ...
20PIN nec microcontroller firmware dump: uPD78F9221 uPD78F9222 uPD78F9521 uPD78F9522 ...
30PIN nec mcu code clone: uPD78F9232 uPD78F9234 uPD78F9532 uPD78F9534 ...
44PIN nec microcontroller memory duplicate: uPD78F0511 uPD78F0512 uPD78F0513 ...
48PIN nec Microprocessor code clone: uPD78F0511 uPD78F0512 uPD78F0513 uPD78F0514 uPD78F0515 ...
52PIN nec microcontroller firmware dump: uPD78F0521 uPD78F0522 uPD78F0523 uPD78F0524 uPD78F0525 uPD78F0526 uPD78F0527 ...
64PIN nec mcu code clone: uPD78F0531 uPD78F0532 uPD78F0533 uPD78F0534 uPD78F0535 uPD78F0536 uPD78F0537 ...
80PIN nec microcontroller dump: uPD78F0544 uPD78F0545 uPD78F0546 uPD78F0547 ...
Nuvoton/Winbond MCU Copy Protection Break view more types...

W77Exx series ic code extraction: W77E51 W77E52 W77E54 W77E58 W77E058A W77E516 W77E516A W77E532 W77E532A W77E058 W77E58A W77I058A 77L058 W77L516A W77LE58 W77IE58 W77L058A W77L516A W77L532A W77LE516 W77LE532 ...
W78Exx series ic code recovery: W78E51 W78E51B W78E52 W78E52B W78E54 W78E54B W78E58 W78E58B W78E516 W78E051A W78E62 W78E65 W78E65B W78E516B W78E051B W78E051C W78E052A W78E052B W78E052C W78E054A W78E054B W78E054C W78E058A W78E058B W78E065A W78E365 W78E365A W78E378 W78E378E W78E51 W78E516B W78E51B W78E51C W78E52 W78E52B W78E52C W78E54 W78E54B W78E54C W78E58 W78E58B W78E62 W78E65 W78E858 W78ERD2 W78ERD2A W78E051DDG W78E051DFG W78E051DLG W78E051DPG W78E052DDG W78E052DFG W78E052DLG W78E052DPG W78E054DDG W78E054DFG W78E054DLG W78E054DPG W78E058DDG W78E058DFG W78E058DLG W78E058DPG W78E065 W78E354 W78E374B W78E378P W78E516DDG W78E516DFG W78E516DLG W78E516DPG W78E62B ...
W78IExx series ic code extraction: W78IE52 W78IE54 W78IRD2 W78IRD2A W78I051DDG W78I051DFG W78I051DLG W78I051DPG W78I052 W78I052DDG W78I052DFG W78I052DLG W78I052DPG W78I054 W78I054DDG W78I054DFG W78I054DLG W78I054DPG ...
W78Lxx series ic code recovery: W78L051A W78L051C W78L052A W78L052C W78L054A W78L054C W78L058A W78L365A W78L516A W78L812A W78L051 W78L052 W78L054 W78L058 W78L365 W78L516 W78L812 ...
W78LExx series ic code extraction: W78LE58 W78LE58B W78LE051A W78LE365 W78LE51 W78LE516 W78LE51C W78LE52 W78LE52C W78LE54 W78LE54C W78LE812 ...
W79Exx series ic code recover: W79E201 W79E201A W79E532 W79E532A W79E533A W79E548 W79E548A W79E549 W79E549A W79E558A W79E559A W79E632 W79E632A W79E633A W79E648 W79E648A W79E649 W79E649A W79E658A W79E659A W79E801 W79E802 W79E803 W79E804 W79E821 W79E822 W79E823 W79E824 W79E825 W79E82J W79E832 W79E833 W79E834 W79E83J W79E2051 W79E216AFG W79E217AFG W79E225A W79E226A W79E227A W79E4051 W79E633 W79E83J W79E801A W79E802A W79E803A W79E804A W79E821A W79E822A W79E822B W79E823A W79E823B W79E824A W79E825A W79E831A W79E832A W79E833A W79E834A ...
W79Lxx series ic code extraction: W79L532 W79L532A W79L548 W79L548A W79L549 W79L549A W79L558A W79L559A W79L632 W79L632A W79L633A W79L648 W79L648A W79L649 W79L649A W79L658A W79L659A W79L633 ...
W83Lxx series ic code recovery: W83L950D W83L950G W83L951D W83L951DG W83L951F W83L951FG W83L951ADG W83L951DF ...
 
 
     
 
PCB Copying Service
PCB Projects Overview
PCB Clone
PCB Reverse Engineering
PCB Prototype
PCB Assembly Production
 
 
 
Mcu Hacking Service
Atmel / Analog Mcu Hack
Actel Mcu Attack
Altera Microcontroller Crack
Cygnal Mcu Unlock
Cypress IC Reverse Engineer
Dallas / Elan Mcu Code Extract
Fujitsu Microprocessor Decryption
Freescale IC Code Extraction
Giga Device circuit Hack
Hitachi Mcu Code Extract
Holtek Chip Reverse Engineer
Infineon Microcontroller Dump
Intel Mcu Read Code Protection
ICT Microcontroller Duplication
Lattice Microcontroller Clone
Microchip Source Code Recovery
Motorola Microcontroller Crack
Maxim Mcu Attack
MDT Controller Hack
Megawin Microcontroller Unlock
NEC Mcu Reverse Engineer
NTK Microcontroller Code Extract
Nuvoton Chip Decryption
NXP Semiconductor Code Extraction
Philips integrated circuit Crack
Renesas Microcontroller Dump
ST Processor Reverse Engineer
Silicon Labs Mcu Read Protection
Samsung Mcu Duplication
SST Mcu Clone
Sinowealth Source Code Recovery
SyncMOS Mcu Unlock
Sonix Mcu Read Source Code
STC Microprocessor Code Extract
Tenx Microcontroller Decryption
Texas Instruments MCU Hack
Winbond MCU Code Extraction
Xilinx integrated circuit Crack
Zilog MCU Reverse Engineer
 
     
 
 
More MCU brands we can reverse engineer below, please contact us if yours not listed here:
AMD Feeling LG / Hyundai Myson STK
ChipON Hynix Mitsubishi National Semi Temic
Coreriver ICSI Mosel Vitelic Portek Toshiba
Dallas ISSI MXIC SSSC Gal / Pal / Palce
Copyright © 2013 Mikatech. All rights reserved. Full dedicated reverse engineering company