Matthew 'wrongbaud' Alt reconstructed a device's firmware without touching the flash chip. Using a logic analyzer to sniff the SPI bus on a W25Q-series flash chip at boot, he captured what the CPU actually read, then decoded it with Scapy, a Python tool built for network packets, not embedded systems. The output fed directly into binwalk.
The method has a hard limit: you only recover what the CPU requests, not the full chip contents. That gap became literal. The reconstructed image contained the bootloader and Linux kernel but had a hole where the filesystem belonged. The CPU had switched to Quad-SPI for that section, adding two more data lines and requiring a second capture pass. A dd one-liner merged both images into a single usable binary.
Read the full write-up for the SPI protocol breakdown alone. Alt works through the datasheet and logic analyzer output signal by signal, making this useful well beyond firmware extraction. The Scapy implementation, handling logic analyzer capture files instead of network traffic, is the detail worth studying carefully.
[READ ORIGINAL →]