Like the Raspberry π SoC is based on a television tuner box. The vast majority of the die is related to the TV tuner functions that are completely undocumented. What techniques exist to explore undocumented physical hardware? Are we limited to reverse engineering code to find when and how these undocumented areas are used, or are there other fuzzing type techniques to find relationships between memory, flags, and potential byte instructions?
This is an abstract thought and generalization that potentially patches a hole in my understanding. There is no broader purpose in asking.


Money.
Doing this type of research is extremely time consuming so research needs funding, to eat food and pay rent and even if you discover things worth sharing, the current legal system often prevents you from publishing it, which costs more money to fight.