Browse guides

Getting started

FDIE overview

Firmware analysis, release comparisons and technical evidence from a Magdox product.

Guide type: Product guide

In this guide

FDIE starts with firmware images you are authorised to analyse. It extracts supported filesystems and binaries, identifies components, matches vulnerability intelligence, runs supported checks and records evidence for analyst review. The application is at fdie.magdox.io; all public documentation, pricing and policies are on magdox.io.

FDIE overview
StageWhat to doWhat to retain
PrepareConfirm image ownership, format, release identity and handling requirementsImage hash, authorisation and product context
AnalyseUpload to the selected hosted or on-premises FDIE deploymentJob state, assessed stages, warnings and unassessed areas
ReviewValidate component identification, advisory applicability and runtime observationsEvidence, reviewer, rationale and unresolved questions
CompareChoose analysed releases from the same product lineageComponent/function delta and reviewed carry-forward decisions
DeliverExport reviewed inventories, VEX and assessment evidenceAssessment scope, feed context and recipient requirements

Choose the product by input

Code Security scans source repositories locally through the magdox CLI. FDIE processes firmware within the FDIE deployment you select. They are separate products from the same company, with separate subscriptions and evidence stores. A Code Security upload flag does not govern FDIE firmware uploads.

Compare Magdox products

Start your first FDIE assessment

FDIE dashboard showing finding severity, assessment history and framework coverage
Security overview · Sample product captureSample assessment history and finding occurrences across a firmware library. Counts can include the same vulnerability in multiple images; they are not unique CVEs, a detection benchmark or current statements about a vendor.Select the image to view it at full size in a new tab.

Choose a useful first assessment

Start with a firmware image your engineers already understand. A known component, a previous finding or a documented update gives the team something concrete to compare with the automated result. Keep the product, version and source of the image in the review record.

  • Open the image's coverage before reviewing the total finding count.
  • Inspect one identified component and trace it back to its recovered path or other available evidence.
  • Review one candidate vulnerability with an engineer and record the applicability decision.
  • Export the artifact your release process needs and check that a second reviewer can interpret it.

For a release-comparison evaluation, repeat the process on a related image. Compare the coverage and intelligence context on both sides before using the delta as evidence of a firmware change.