A streamlined, user-friendly tool for extracting and analyzing ESP32 firmware - whether from a physical device or an existing firmware dump.
- 🚀 Auto-Detection: Automatically detects ESP32 device, port, and flash size
- ⚡ Quick Mode: One-command extraction with
--autoflag - 🔌 Direct Device Extraction: Download firmware directly from ESP32 via serial port
- 📁 File-Based Extraction: Analyze existing firmware dumps
- 🔍 Automatic Partition Detection: Identifies and extracts all partitions
- 🛠️ ELF Generation: Creates analyzable ELF files from app partitions
- 📊 Comprehensive Analysis: Generates detailed reports using esptool
- 🎨 User-Friendly Interface: Interactive menu with colored output
- 📦 Organized Output: Creates timestamped directories with all results
# Install Python dependencies
pip install esptool makeelf# Just connect ESP32 and run:
./quick_extract.shNo questions asked - automatically detects, downloads, and extracts everything!
# Auto-detect ESP32 and download firmware with options
./extract.sh --auto# Run with menu options
./extract.sh# Process existing firmware file
./extract.sh --file flash.bin
# Show help
./extract.sh --help-
Choose Source:
- Download from ESP32 device (via serial)
- Use existing firmware file
-
Automatic Processing:
- Reads partition table
- Extracts all partitions (nvs, ota, factory, etc.)
- Creates ELF files for reverse engineering
- Generates analysis report
-
Output:
- Organized directory with timestamp
- All extracted partitions
- ELF executables for IDA/Ghidra/radare2
- Detailed analysis report
- README with next steps
extraction_YYYYMMDD_HHMMSS/
├── flash_dump.bin # Original firmware
├── partition_table.txt # Partition layout
├── nvs.bin # NVS partition
├── otadata.bin # OTA data
├── ota_0.bin # Application partition 0
├── ota_0.elf # ELF for analysis
├── factory.bin # Factory app
├── factory.elf # Factory ELF
├── analysis_report.txt # Detailed analysis
└── README.md # Next steps guide
- nvs: Non-Volatile Storage (WiFi creds, configs)
- otadata: OTA update data
- phy_init: PHY initialization
- ota_0/ota_1: Application partitions
- factory: Factory application
- storage: User storage
- IDA Pro: Industry-standard disassembler
- Ghidra: Free reverse engineering suite
- radare2: Open-source RE framework
- objdump: Basic disassembly
- hexdump/xxd: Command-line hex viewers
- HxD: Windows hex editor
- Hex Fiend: macOS hex editor
# USB serial typically appears as:
/dev/ttyUSB0
/dev/ttyACM0# USB serial typically appears as:
/dev/tty.usbserial-XXXX
/dev/tty.usbmodem-XXXXCOM3, COM4, etc.
- 2MB: Minimal ESP32 modules
- 4MB: Most common (ESP32-WROOM-32)
- 8MB: ESP32-WROVER modules
- 16MB: High-capacity modules
# Linux: Add user to dialout group
sudo usermod -a -G dialout $USER
# Then logout and login againpip install esptool- Try reducing baud rate (default: 921600)
- Check cable quality
- Ensure proper grounding
Based on ESP32 Image Parser tools. See LICENSE file for details.