Repository navigation
Quick Start
This page takes you from a fresh install to a recovered AES key in a few minutes. Walkthrough 1 uses the built-in simulator, so you can follow it on any computer; walkthrough 2 does the same with a real ChipWhisperer-Lite ARM.
Before you start, install Studio and start it. Studio opens in its own window (or in your browser with the Web build) with the Connect tab open.
The simulator behaves like a ChipWhisperer scope attached to an unprotected AES target, so every feature works exactly as with real hardware.
- In the left navigation, click Connect.
- Under Scope, set Device to Simulator (no hardware). The target Protocol switches to Simulated AES target automatically. Leave Simulate as on Husky.
- Leave default_setup() ticked and click Connect scope.
Studio connects the simulated scope, then connects the simulated target for you, and switches to the Scope tab. The chips in the top bar now read ChipWhisperer-Simulator (Husky) · SIM000001 and SimTarget with green dots.
Tip: Starting Studio with
--simulate(orChipWhispererStudio-simulator.baton Windows) preselects the simulator in the Connect tab.
Click Single in the top bar (or press S). One power trace appears in the waveform area on the right. The footer under the plot shows the number of samples, the sample rate, min, max, peak to peak and mean, and the plaintext (pt), ciphertext (ct) and key used for this trace.
- Click Capture in the left navigation.
- Set Traces to
500. - Leave Mode on SimpleSerial: send data, read reply, Key on fixed (the default key
2b7e151628aed2a6abf7158809cf4f3c) and Plaintext on random. - Click Run (in the panel or in the top bar, or press R).
The waveform updates live while the progress bar fills. When the capture finishes, the top bar shows 500 traces and the Trace set card shows the number of traces, samples per trace and memory used.

- Click Analysis in the left navigation.
- Leave Leakage model on HW of SBox output (round 1, software AES). That matches software AES implementations such as the simulator and NewAE's TINYAES128C firmware.
- Leave the other fields as they are and click Run CPA.
Within a few seconds all 16 key bytes appear as tiles under Result. Because the key is stored with every trace, Studio knows the correct key and colours each tile green when the best guess is correct. The line below shows best guess: and known:; with 500 simulated traces they match. The Convergence plot shows the partial guessing entropy (PGE) of every byte dropping to 0 as more traces are used.


That is the whole attack. From here you can try a glitch sweep in the Glitch tab (the simulator also models glitches, see Simulator), explore the Waveform Viewer, or open a notebook.
This walkthrough uses a ChipWhisperer-Lite with its built-in STM32F3 (ARM) target, platform CWLITEARM. Other hardware works the same way with a different platform and programmer; see Firmware Builds and Target and Programming.
Note: Studio has been tested with the simulator and in CI, but not yet on physical ChipWhisperer hardware. If a step behaves differently on your device, please open an issue.
- Windows: make sure the WinUSB driver is installed (see Installation).
- Linux: install the udev rule shown in the Connect tab, log out and in again, and re-plug the device (see Installation).
- macOS: nothing to do.
- Plug in the ChipWhisperer-Lite.
- In the Connect tab, click Scan USB. Your device should be listed with its serial number.
- Set Device to Auto-detect (or ChipWhisperer-Lite), keep default_setup() ticked and click Connect scope.
- Studio switches to the Scope tab. Go back to Connect, set the target Protocol to SimpleSerial v2 (default firmware) and click Connect target.
Both chips in the top bar should turn green. If the scope is not found, see Connecting Hardware.
The target needs NewAE's simpleserial-aes firmware. Studio builds it for you.
- Click Firmware in the left navigation.
- Scroll to the Firmware sources card and click Download. Studio downloads ChipWhisperer's firmware folder from NewAE's GitHub. This happens only once.
- Back in the Build firmware card, set Project to
simpleserial-aesand Platform toCWLITEARM · CW-Lite Arm (STM32F3). - Leave Compiler on GCC, Crypto on
TINYAES128Cand SimpleSerial onv2.1. - The Toolchain line tells you whether a compiler is installed. If it says No GCC for Arm Cortex-M, click Install now and wait for the download (about 300 MB) to finish in the Toolchains card.
- Click Build & program.
Studio builds the firmware, shows the result (sizes and the .hex path), and programs the target with the STM32F programmer. A toast confirms how many bytes were written.

- Click Target.
- In the SimpleSerial card, click Send key, then click Send next to Command
p.
The response box should show r followed by 16 bytes of ciphertext. If it shows (no response), check that the firmware was programmed and that the protocol is SimpleSerial v2. See Target and Programming.
- Click Single in the top bar. You should see an AES power trace. If the trace is flat or clipped at the top and bottom, adjust
gain.dbin the Scope tab (see Scope Settings). - In the Capture tab set Traces to
500and click Run. - In the Analysis tab click Run CPA with the default leakage model.
With an unprotected software AES, a few hundred traces are usually enough for every key byte to turn green. If some bytes stay red, capture more traces (with clear first unticked they are added to the existing ones) and run CPA again.
- Save your traces: Capture tab, Export as a ChipWhisperer project (
.cwp) or NumPy file. See Capturing Traces. - Learn the rest of the window: Interface Tour.
- Try fault injection: the Glitch tab sweeps glitch parameters; set up the glitch module first in the Scope tab (see Scope Settings).
- Run NewAE's tutorials: Notebooks.
Getting started
Using Studio
- Scope settings
- Target and programming
- Capturing traces
- Waveform viewer
- Protocols and interfaces
- Logic analyser
- Code on the waveform
Building and coding
Automation
Help
Developers
Links