From my understanding is you’d probe the board during different operations, process the results and deduct what signals are useful and traffic transmitting across the board (I.E private keys, what protocols are used, debug interfaces, firmware components, chip functions, etc).