LegacyMind GmbH · Ingolstadt, Germany
Firmware analysis for industrial and IoT devices
Upload a firmware image. LegacyMind reads it at the binary level, without source code and without an agent on the device: which components are inside, which known vulnerabilities match them, and where hardening is missing.
Input
What it reads
Firmware images with Linux
The image as you ship it: archives, raw images, file systems (SquashFS, JFFS2, CramFS, UBI, YAFFS2, ext), kernel and boot images including ARM zImage, update containers and VM disks. The analysis unpacks down to the root file system and reads package databases (dpkg, opkg, apk, rpm), binaries and the kernel.
Bare-metal builds (ELF, AXF)
Microcontroller builds from Keil MDK, IAR or GNU Arm. Read: CMSIS packs, versioned from the pack vendor's own description, version records in the binary (for example RTX5) and versions from source paths (FreeRTOS, lwIP, mbedTLS, STM32Cube). Plus hardening (stack canary, MPU, privilege separation) and embedded keys.
Raw microcontroller images (BIN)
A BIN without a file system is read byte by byte. Components are named where the bytes evidence them, for example through the version strings of TLS libraries.
Windows CE images
The ROM module table and the version resources of the programs are read.
Supplier SBOMs
Your suppliers' SBOMs in CycloneDX (JSON, XML) or SPDX (JSON, tag-value, SPDX 3.0 JSON-LD), up to 64 MB. The format is detected from the document, not the file name. Every component is matched against the vulnerability sources.
File extensions, what each one yields, and what is not built yet.
Output
What you get
SBOM
CycloneDX 1.6. For every component it detects: the name, where in the image it sits, and the version where the image proves it.
Known vulnerabilities
Matched from 16 sources plus CISA KEV and EUVD. What is actively exploited comes first, not CVSS alone.
Confirmed or assumed
Every match says whether the version is confirmed in the image or assumed.
Secrets
Credentials, private keys, certificates and password hashes in the image.
Hardening
RELRO, NX, PIE and stack canaries per binary, and unsafe C functions with their CWE.
CRA and NIS2 findings
Findings against EU CRA Annex I and § 30 BSIG, Germany's NIS2 law. No percentage, no conformity verdict: you make the conformity statement.
Answers to the questions buyers ask most, with sources: knowledge.
Customers
Who it is for
Device manufacturers
Preparing for the EU Cyber Resilience Act.
Operators under NIS2
Entities under § 30 BSIG, critical facilities included.
Managed service providers
Looking after devices for their customers.
Company
LegacyMind GmbH
- Company
- LegacyMind GmbH
- Address
- Falkenstr. 10, 85049 Ingolstadt, Germany
- Register
- Amtsgericht Ingolstadt, HRB 12510
- Founded
- September 2025
- Founders
- Ben Plannet, co-founder and CTO. Marco Plannet, co-founder and managing director.
- Funding
- Self-funded, no investors
- Engine
- The analysis stages, the scoring and the CVE correlation are our own code.
Write to us in English
The app and the reports are in German. Questions in English are welcome.