IoT use is growing rapidly through a research study sponsored by Trustwave, it was revealed that sixty-four percent of organizations surveyed have deployed some level of IoT technology, and another twenty percent plan to do so within the next twelve months. The result of this will be that, by the end of 2018, only one in six organizations will not be using at least a minimal level of IoT technology for business purposes. While IoT devices are exploding in deployments, still very little is being done to secure these solutions. The security defenses being employed within this domain tend to be at least a decade old and of insufficient strength to hold back today's attackers. In this same Trustwave sponsored survey, it was found that only twenty-eight percent of organizations surveyed considered their IoT security strategy to be very important. This combination makes IoT devices very attractive targets for malicious attackers, red teamers and others interested parties. One of the most common ways to analyze and find vulnerabilities in IoT devices is through the use of their JTAG ports. In this talk, we'll be discussing what JTAG is and how it can be used in order to find vulnerabilities in IoT devices. The presentation will cover a bit of history about JTAG and will then jump into the technical details on how to find JTAG ports, what software and hardware tools can be used to identify pinouts, and how to extract and debug the firmware running on a target device. Several examples and small demos will be used during the presentation to show practical applications of the lessons being conveyed. Finally, pointers will be provided as to what to look out for once you have achieved access to a device via JTAG.