If you really want to understand a security researcher, look at the tools they tinker with after hours. To celebrate our final runZero Hour of 2025 (and the fact that we’re giving away three $200 Hak5 gift cards) we asked the runZero research crew to share their favorite hacker toys.

These are the gadgets that spark their curiosity and inspire experimentation.

Tod Beardsley’s pick: WiFi Pineapple #

The WiFi Pineapple is a portable wireless auditing platform for exploring the behavior and security of Wi-Fi networks. It can detect rogue access points, capture packets, identify client vulnerabilities, and emulate various wireless attack scenarios. It’s extremely flexible, making it a go-to device for anyone interested in understanding how networks respond to untrusted or impersonated access points.

HD Moore’s pick: The Key Croc #

The Key Croc is a stealth USB keystroke logger disguised as a simple keyboard passthrough. Once connected, it records keystrokes, triggers payloads when specific text patterns appear, and even provides remote shell access for deeper testing. It’s ideal for assessing how well systems defend against malicious USB peripherals — and it’s powerful enough to bypass certain input-approval prompts on modern OSes.

HD Moore’s second pick: The Hacker Pager (by Amir) #

Built by Amir and the exploitee.rs collective, the Hacker Pager is a fully open-source, retro-style wireless communicator powered by Meshtastic and LoRa. It creates its own off-grid mesh network for peer-to-peer messaging (no cell towers, Wi-Fi, or infrastructure needed). With its built-in LCD screen, LoRa radio, ESP32-S3 processor, and SD card support, it works as both a standalone communicator and a playground for experimenting with long-range wireless tech. It can capture and log LoRa traffic, run spectrum scans, be customized down to the firmware and UIK, and even play CHIP-8 games.

Matthew Kienow’s pick: 4-Port UART Adapter #

UART adapters are essential tools for hardware exploration. A 4-port UART board makes it easy to connect to serial consoles on IoT devices, routers, embedded boards, and anything hiding behind a debug header. With it, researchers can intercept boot logs, recover bricked systems, dump firmware, and uncover hidden menus. It’s simple, inexpensive, and endlessly useful for hardware reverse engineering.

Matthew Kienow’s other go-to: Shodan.io #

Alongside his hardware tools, Matthew also relies heavily on Shodan. Shodan.io scans the global internet and indexes exposed devices, services, and protocols—from forgotten RDP servers to ICS equipment. It’s an invaluable resource for mapping real-world attack surfaces, spotting configuration mistakes, and tracking exposure trends across industries. If it’s online, Shodan probably knows about it.

Want to win your own hacker gear? #

We’re closing out the year with runZero Hour Episode 25: The Holiday Hackstravaganza on Wednesday, December 17 at 1PM ET / 10AM PT and we’re giving away three $200 Hak5 gift cards live during the event.

Just show up, join our trivia, and drop the fastest correct answer in the chat.

We’ll look back at 2025’s wildest vulnerabilities, share runZero research highlights and feature releases, make some predictions for 2026, and bring in a few familiar guests for sharp insights, good humor, and a bit of holiday chaos.

Save your spot now.

Written by runZero Team

Great research and development is a team effort! Multiple runZero team members collaborated on this post. Go team!

More about runZero Team
Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.

Explore more runZero

Product
Announcing runZero 4.9: Unmask attack paths and segmentation gaps with advanced topology and deep OT device intelligence
With runZero 4.9, visualize attacker lateral movement, harden network choke points, gain deep OT telemetry to secure converged environments, and more.
Webcasts
runZero Hour, Ep. 30: Segmentation - stop assuming & start verifying with runZero 4.9
See runZero 4.9 in action! Join HD Moore and Tod Beardsley to learn how interactive attack path mapping and advanced OT intelligence expose hidden...
Product Videos
runZero 4.9: Advanced topology, attack path mapping, & deep OT intelligence
With runZero 4.9, visualize attacker lateral movement, harden network choke points, gain deep OT telemetry to secure converged environments, and more.
runZero Perspective
Dawn of the apex agentic adversary
When agentic AI can weaponize exploits in seconds, visibility is everything. Stop the predator with runZero’s exposure management for the AI-attack...
Webcasts
Defending in the shadow era: when the CVE feed goes dark
HD Moore walks through the three eras of vulnerability management: the predictable cycles era, the triage ara of AI-scale discovery, and now the...
Webcasts
runZero Hour, Ep. 31: The New Rules of Risk: EPSS v5 and Agentic Adversaries
In this episode, learn how your security team can use EPSS v5 to inform daily risk decisions in a world increasingly targeted by the apex agentic...
Webcasts
Beyond the Zero-Day: Mapping the network attackers actually see
Breaches are inevitable. Learn from HD Moore how attackers exploit the seams between IT, IoT, and OT networks — and how to fix the segmentation...
Podcasts
Risky Biz Interview: Navigating the AI vibe shift with HD Moore
runZero Founder and CEO HD Moore drops by in this week's Risky Biz sponsor interview to talk about the concerning AI vibe shift and what to do...

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.