Keep release decisions connected to the evidence.
Analyse supported firmware images, compare identified components and review vulnerability decisions across releases. FDIE brings component history, bounded runtime observations and SBOM/VEX exports into one workflow for connected-device teams.
Firmware formats
Security test cases
CVE records in FDIE's NVD mirror
Compliance frameworks
From a supported image pair to a reviewable decision.
Start with two releases of one product. Agree compatibility and coverage, then use the analysis to focus your team’s next review.
Scope
Confirm image access, product and hardware variant, supported format and hosting requirements.
Analyse
Extract supported content, identify components and collect static and available runtime evidence. Review coverage gaps.
Compare
Inspect component, finding and function changes alongside engine and vulnerability-feed context.
Review
Decide which earlier assessments remain applicable and investigate changes that need fresh triage.
Export
Share SBOM, VEX and review evidence with stated limitations as part of your release documentation.
Keep firmware and coverage in view.
Find a release, review its processing state and check how much of the image was assessed before opening the results. Partial and unassessed images remain visible in the same library.
What is actually running under the hood.
All capabilities are included in the Enterprise plan. Analysis coverage depends on the image; hosting, usage and support are scoped in your contract.
CVE and vulnerability matching
NVD correlation with CPE version-range filtering for fewer false matches, plus EPSS scoring and CISA KEV flagging. Matching runs on identifiers recovered from the binary: dynamic-linking metadata, version banners, strings and component signatures.
Binary intelligence
Inspect available decompiled functions, call graphs and extracted strings alongside a finding. Coverage depends on the binary format, architecture and analysis outcome; missing decompilation remains visible.
Delta Intelligence
Component lineage, known dependency relationships and reviewable triage suggestions across analysed releases of your product.
Dynamic analysis
Emulates supported binaries and attempts supported Linux boots in an isolated sandbox. Observations are bounded by the paths and environments exercised.
Automated extraction
Recover supported filesystems and wrappers, including SquashFS, UBI, JFFS2, CramFS, ext, FAT, raw NAND and common vendor wrappers.
Continuous monitoring and alerts
Once analysed, every image is re-matched against the NVD mirror daily and checked against the CISA KEV catalogue every six hours; EPSS scores refresh daily. A new match raises a notification after that check, so the lag is the sync interval plus the feed's own publication delay, not real time. You can also re-match on demand.
Reporting and integrations
Export reviewable PDF evidence and configure webhooks, Slack or Microsoft Teams notifications for findings raised by analysis or scheduled rechecks.
60-point security test suite
Credentials, cryptography, binary hardening, attack surface, known vulnerabilities, update mechanisms and secure boot, in one pass.
SBOM, CBOM and VEX
CycloneDX and SPDX inventories of identified components and licences, plus VEX documents recording vulnerability assessments, uncertainty and reviewed decisions.
Threat modeling
TARA and MITRE EMB3D built automatically from what FDIE found: components, exposed services, the boot chain and observed runtime behaviour.
Malware and threat intelligence
YARA content rules surface matching indicators in extracted files for investigation alongside CVE candidates. A match needs review; absence of a match does not establish that an image is malware-free.
Compliance scoring
Assessed-control grades across eleven frameworks: ETSI EN 303 645, EN 18031-1, EN 18031-2, EN 18031-3, OWASP FSTM, NIST SP 800-193, NIST IR 8259A, IEC 62443-4-2, IEC 81001-5-1, FDA 524B and TEC 31318, with explicit coverage gaps. CRA disclosure review is available separately.
Your firmware deserves careful handling.
Firmware images and everything extracted from them are encrypted at rest and in transit, access is scoped per organisation, and nothing you upload is sold, used to train a model, or disclosed beyond the hosting and service providers named in our DPA.
Full security and trust detailsEncryption
Encrypted at rest and in transit
Isolation
Per-organisation isolation on every query
Sandboxing
Sandboxes destroyed after every run
Data region
India, or on-premises in your own environment
Move from a finding to the file behind it.
Inspect source locations and recorded results in context. Recovery and analysis coverage remain part of the review.
Start with one product and two releases.
Review a sample comparison with us. Then scope a supported image pair, hosting requirements and the evidence your team needs to evaluate.
21-day free trial on the full platform. No card, no automatic conversion.