LegacyMind GmbH · Ingolstadt, Germany

Firmware analysis for industrial and IoT devices

Upload a firmware image. LegacyMind reads it at the binary level, without source code and without an agent on the device: which components are inside, which known vulnerabilities match them, and where hardening is missing.

Input

What it reads

  • Firmware images with Linux

    The image as you ship it: archives, raw images, file systems (SquashFS, JFFS2, CramFS, UBI, YAFFS2, ext), kernel and boot images including ARM zImage, update containers and VM disks. The analysis unpacks down to the root file system and reads package databases (dpkg, opkg, apk, rpm), binaries and the kernel.

  • Bare-metal builds (ELF, AXF)

    Microcontroller builds from Keil MDK, IAR or GNU Arm. Read: CMSIS packs, versioned from the pack vendor's own description, version records in the binary (for example RTX5) and versions from source paths (FreeRTOS, lwIP, mbedTLS, STM32Cube). Plus hardening (stack canary, MPU, privilege separation) and embedded keys.

  • Raw microcontroller images (BIN)

    A BIN without a file system is read byte by byte. Components are named where the bytes evidence them, for example through the version strings of TLS libraries.

  • Windows CE images

    The ROM module table and the version resources of the programs are read.

  • Supplier SBOMs

    Your suppliers' SBOMs in CycloneDX (JSON, XML) or SPDX (JSON, tag-value, SPDX 3.0 JSON-LD), up to 64 MB. The format is detected from the document, not the file name. Every component is matched against the vulnerability sources.

  • Every format, tier by tier

    File extensions, what each one yields, and what is not built yet.

Output

What you get

  • SBOM

    CycloneDX 1.6. For every component it detects: the name, where in the image it sits, and the version where the image proves it.

  • Known vulnerabilities

    Matched from 16 sources plus CISA KEV and EUVD. What is actively exploited comes first, not CVSS alone.

  • Confirmed or assumed

    Every match says whether the version is confirmed in the image or assumed.

  • Secrets

    Credentials, private keys, certificates and password hashes in the image.

  • Hardening

    RELRO, NX, PIE and stack canaries per binary, and unsafe C functions with their CWE.

  • CRA and NIS2 findings

    Findings against EU CRA Annex I and § 30 BSIG, Germany's NIS2 law. No percentage, no conformity verdict: you make the conformity statement.

Answers to the questions buyers ask most, with sources: knowledge.

Customers

Who it is for

  • Device manufacturers

    Preparing for the EU Cyber Resilience Act.

  • Operators under NIS2

    Entities under § 30 BSIG, critical facilities included.

  • Managed service providers

    Looking after devices for their customers.

Company

LegacyMind GmbH

Company
LegacyMind GmbH
Address
Falkenstr. 10, 85049 Ingolstadt, Germany
Register
Amtsgericht Ingolstadt, HRB 12510
Founded
September 2025
Founders
Ben Plannet, co-founder and CTO. Marco Plannet, co-founder and managing director.
Funding
Self-funded, no investors
Engine
The analysis stages, the scoring and the CVE correlation are our own code.

Write to us in English

The app and the reports are in German. Questions in English are welcome.