Everything you need to deploy an Ayewo scanner node on your own hardware.
A pre-registered Ayewo scanner node delivered as a single .iso file you flash directly to a disk with Balena Etcher, Rufus, dd, or Raspberry Pi Imager. Once flashed and booted, the target hardware becomes a full Ayewo scanner — identical to the Virtual product, on hardware you own and control.
Price: $579/month per node ($5,790/year prepay — 2 months free). x86-64 and ARM64 available.
/order). Pick x86-64 or ARM64.{customerID}.{arch}.{orderID}.iso — the disk image.iso.minisig — cryptographic signature (ed25519).iso.sha256 — integrity checksumEvery target falls into one of three tiers. Pick accordingly — the Unsupported list is the one we'll cite when closing tickets.
| Tier | Examples |
|---|---|
| Supported | Intel NUC (7th gen+), Dell Optiplex Micro (7th gen+), HP EliteDesk Mini (G3+), ProtectLi Vault line, MikroTik CHR, generic UEFI mini-PCs with Intel/AMD 4+ core CPUs |
| Best Effort | ESXi and Proxmox VMs meeting minimums (USB passthrough for wireless is customer-dependent), Dell R-series / HP DL-series, IPMI-managed bare-metal servers |
| Unsupported | Hyper-V (no reliable USB passthrough for wireless), Legacy BIOS-only systems, Atom/Celeron below 4 cores, anything below 8 GB RAM |
| Tier | Examples |
|---|---|
| Supported | Raspberry Pi 5 (8 GB), Raspberry Pi CM5 on official carrier boards |
| Best Effort | Orange Pi 5 Plus (8 GB+), Radxa ROCK 5B+, Pi 4 8 GB variant |
| Unsupported | Pi 4 4 GB variant, Pi 3 and older, Pi Zero series, any 32-bit ARM board, SD card as primary storage for production workloads |
| Component | Minimum | Notes |
|---|---|---|
| CPU | 4 cores (x86-64 or ARM64) | Below 4 cores the node will run but deep scans throttle heavily |
| RAM | 8 GB | Encrypted RAM disk + Nuclei Java heap peak around 5 GB; below 8 GB the node OOMs on deep scans |
| Storage | 10 GB internal (SSD/NVMe strongly recommended) | HDD works but scan performance drops; SD card only recommended for SBC best-effort targets |
| Firmware | UEFI (x86); UEFI or U-Boot (ARM) | Legacy BIOS not supported — image uses GPT |
| Network | Wired Ethernet for initial boot | Wi-Fi only supported via USB adapter once booted |
hardware-precheck service at boot. If your hardware is under-spec it will still boot and scan, but the admin panel flags the node and we'll decline related support tickets citing this policy.| Your OS | Recommended Tool | Command / Path |
|---|---|---|
| macOS / Linux | dd (built-in) | sudo dd if=ayewo.iso of=/dev/sdX bs=4M status=progress conv=fsync |
| Windows | Rufus (GPT + UEFI mode) | Open Rufus → select ISO → select target disk → "Start" → keep default (DD mode works fine) |
| Any OS | Balena Etcher | GUI, cross-platform, built-in validation. Recommended for most users. |
| Raspberry Pi / ARM SBC | Raspberry Pi Imager | "Use custom image" → select ISO → choose SD/NVMe target → write |
No operator interaction required. No installer prompts. No passwords to enter.
Optional but recommended — especially for MSPs redistributing the ISO to sub-clients. Every ISO is signed with our ed25519 signing key; verifying proves you received an unmodified image from Hudson Infosec.
macOS: brew install minisign
Linux: sudo apt-get install minisign # Debian / Ubuntu
sudo dnf install minisign # Fedora
Windows: winget install jedisct1.Minisign
Our signing public key lives at https://www.hudsoninfosec.com/trust/ayewo-iso-signing-key-v1.pub. Download it once and cache it locally.
minisign -Vm customer-id.x86.order-id.iso -p ayewo-iso-signing-key-v1.pub # Expected output: # Signature and comment signature verified # Trusted comment: Ayewo ISO | key_id=v1 | sha256=<hash>
If verification fails, do not flash the ISO. Contact support.
Separately, the .sha256 file contains the full SHA-256 hash. Verify with:
sha256sum -c customer-id.x86.order-id.iso.sha256
ARM and x86 ISO nodes both support 802.11 wireless scanning via a USB Wi-Fi adapter passed through from your hardware. The node automatically detects the adapter and puts it in monitor mode during a wireless scan command dispatched from the portal.
The ISO image ships with a strict USBGuard policy:
e0), USB hubs, USB-Ethernet adapters (CDC).ff).This prevents a bad actor with physical access from plugging in a USB stick to exfiltrate scan data or boot unauthorized code. Plugged-in storage devices simply don't appear — dmesg will show them blocked by USBGuard.
The node needs outbound internet. No inbound ports required.
| Port | Protocol | Destination | Purpose |
|---|---|---|---|
| 8883 | MQTT / TLS | *.iot.us-east-1.amazonaws.com | Scan commands + heartbeat |
| 443 | HTTPS | AWS S3 + IoT credential provider + portal API | Config, cert fetch + validation, scan result upload |
If your firewall policy is allow-list, whitelist the two hosts above.
Each ISO is keyed to one node — the deviceId baked into the image during boot verification. Flashing the same ISO to multiple machines results in all of them being suspended.
Our backend detects dupes in two ways:
deviceId heartbeating from different public IPs within a 5-minute window → immediate suspend of all instances.Legitimate hardware upgrades (NIC swap, disk replaced) are tolerated via a similarity check — 3 of 5 signals matching is treated as a drift and silently rebound. Migration between entirely different machines is treated as a clone attempt. If you need to move the node to new hardware, contact support and we'll rebind the cert manually.
| Tier | What we support | SLA |
|---|---|---|
| Supported | Tested hardware targets (see platforms table). Full troubleshooting from initial boot through scanning + pentest operation. | Per your customer agreement |
| Best Effort | Hardware that meets minimums but isn't on the tested list. We'll help where we can; hardware-specific issues are your responsibility. | No guarantee |
| Unsupported | Known-incompatible platforms or under-spec hardware. We'll decline tickets and refer to this policy. | N/A |
Before writing the ISO to disk, run our 30-second preflight script on your current OS. It verifies UEFI mode, Secure Boot, RAM, CPU, disk size, and outbound network reachability — catching the 5 issues that cause ~90% of boot failures.
curl -sL https://www.hudsoninfosec.com/ayewo-preflight.sh | bash
Full details: ISO Preflight. Runs on any Linux live USB, WSL on Windows, or macOS. Exits 0 if you're good to go, 1 if there's a blocker.
If your hardware genuinely can't boot the ISO after ruling out Secure Boot and UEFI misconfiguration, you have two options within 7 days of purchase:
Running the preflight script and attaching its output to the ticket speeds up the swap/refund process — it shows us exactly what blocked the boot. Refunds are declined if the hardware was below the published minimums.
*.iot.us-east-1.amazonaws.com and *.amazonaws.com.iw dev via emergency SSH (see below) to confirm the adapter is visible to the kernel.SSH is disabled by default. From your portal, send enable_ssh via Node Monitoring → your node → Enable SSH. SSH is enabled for 30 minutes and auto-disables. Your default hsecworker password is visible on the device detail page when SSH is enabled.