Extraction & SBOM

Know what is inside each image.

Every review starts with an inventory you can trust. FDIE carves and unpacks supported filesystems, nested archives and vendor wrappers, identifies the components it can recognise and keeps unreadable or encrypted regions visible instead of guessing.

Extraction & SBOM

Unpack supported formats

Extraction handles common embedded filesystems and container formats, including nested archives and vendor wrappers. Opaque, encrypted or unsupported payloads are reported as such.

  • Recover files from supported filesystems such as SquashFS, UBI, JFFS2, cramfs, ext and FAT, and from raw flash images.
  • Record which regions could not be read, so coverage gaps stay part of the evidence.
  • Keep every recovered file connected to the image and the findings that refer to it.

Extraction & SBOM

Identify components

Component identification uses package metadata, version strings and function-hash fingerprints, which also help with statically linked code.

  • Review the evidence behind each identified component and version.
  • Treat low-confidence identifications as candidates for an analyst to confirm.
  • Detect licences alongside components for downstream review.

Extraction & SBOM

Export the inventory

Share the inventory with the teams and customers who need it, in the formats they already use.

  • Export CycloneDX or SPDX SBOMs for an analysed image.
  • Carry coverage limits with the export rather than implying completeness.
  • Pair the SBOM with VEX statements once your team has reviewed the findings.

FDIE · next step

Know what is inside each image.

Unpack supported firmware, identify components and export CycloneDX or SPDX SBOMs with licences and stated coverage limits.

Paid at checkout. 14-day money-back guarantee on the first payment if three or fewer new images have been analysed.