Supported formats
What LegacyMind reads and what you get back
Firmware images with Linux, bare-metal builds from Keil, IAR or GNU Arm, and your suppliers' SBOMs. No source code, no agent on the device.
Input
Firmware
File size 10 KB to 2 GB per upload. As of 5 October 2026.
| Input | What is read | File extensions |
|---|---|---|
Firmware images with LinuxThe image as you ship it: archives, raw images, file systems (SquashFS, JFFS2, CramFS, UBI, YAFFS2, ext), kernel and boot images including ARM zImage, update containers and VM disks. The analysis unpacks down to the root file system and reads package databases (dpkg, opkg, apk, rpm), binaries and the kernel. .zip .tar .gz .tgz .bz2 .xz .lzma .lz4 .zst .7z .rar .cpio .bin .fw .img .rom .raw .dd .squashfs .jffs2 .cramfs .ubi .ubifs .yaffs2 .ext2 .ext3 .ext4 .iso .uimage .zimage .vmlinuz .itb .fit .initrd .trx .chk .npk .swu .mender .raucb .wup .vmdk .qcow2 .vdi .vhd .vhdx | Components, versions, vulnerabilities | .zip .tar .gz .tgz .bz2 .xz .lzma .lz4 .zst .7z .rar .cpio .bin .fw .img .rom .raw .dd .squashfs .jffs2 .cramfs .ubi .ubifs .yaffs2 .ext2 .ext3 .ext4 .iso .uimage .zimage .vmlinuz .itb .fit .initrd .trx .chk .npk .swu .mender .raucb .wup .vmdk .qcow2 .vdi .vhd .vhdx |
Bare-metal builds (ELF, AXF)Microcontroller builds from Keil MDK, IAR or GNU Arm. Read: CMSIS packs, versioned from the pack vendor's own description, version records in the binary (for example RTX5) and versions from source paths (FreeRTOS, lwIP, mbedTLS, STM32Cube). Plus hardening (stack canary, MPU, privilege separation) and embedded keys. .elf .axf .out | Components, versions, vulnerabilities | .elf .axf .out |
Raw microcontroller images (BIN)A BIN without a file system is read byte by byte. Components are named where the bytes evidence them, for example through the version strings of TLS libraries. .bin | Read, components where the bytes evidence them | .bin |
Windows CE imagesThe ROM module table and the version resources of the programs are read. | Read, components where the bytes evidence them | |
Intel HEX and Motorola S-recordAccepted and recognised. Until the conversion to bytes is done, please upload the BIN or the AXF of the same build. .hex .ihex .s19 .srec .mot | Accepted and recognised | .hex .ihex .s19 .srec .mot |
Components, versions, vulnerabilities: parts with their versions, matched against the vulnerability sources. Read: the content is read, and components are named where the bytes evidence them. Accepted and recognised: the upload takes the file and recognises the format; the content is not read yet.
Input
Supplier SBOMs
Your suppliers' SBOMs in CycloneDX (JSON, XML) or SPDX (JSON, tag-value, SPDX 3.0 JSON-LD), up to 64 MB. The format is detected from the document, not the file name. Every component is matched against the vulnerability sources.
Formats: CycloneDX 1.x JSON · CycloneDX 1.x XML · SPDX 2.x JSON · SPDX 2.x Tag-Value · SPDX 3.0.x JSON-LD
Image and SBOM on the same device
Today you get two results side by side: the measured inventory of the image and the CVE matching of the supplier SBOM. Both sit on the same device, so you can read them next to each other. The automatic check of which declared component is actually in the image is in progress.
Output
What you get back
SBOM export
CycloneDX 1.6 JSON and CSV. Every component says where in the image it was read.
Vulnerabilities
Matched against 16 sources, enriched with CISA KEV and EUVD. For supplier SBOMs it is 12 sources: your suppliers' component names go to no public query API.
A decision per finding
A CERT/CC SSVC decision for every vulnerability found, with the inputs it follows from.
Two reports
A management summary and a technical findings report, both in German, with findings against EU CRA Annex I and § 30 BSIG.
Your data
The uploaded firmware image is deleted after the analysis, on every path an analysis can end on.
You make the conformity statement. The reports provide technical findings as its basis.
In progress
Next
- VEX and CSAF export
- SBOM export as SPDX
- Firmware Extractor (closed beta)
Questions
- Can LegacyMind check Keil builds?
- Yes. Upload the AXF. It reads the CMSIS packs with their versions, version records in the binary and versions from source paths, plus hardening and embedded keys. An Intel HEX file is accepted but not yet converted to bytes; upload the BIN or the AXF of the same build instead.
- Which SBOM formats are read?
- CycloneDX as JSON or XML, and SPDX as JSON, tag-value or SPDX 3.0 JSON-LD. The format is detected from the document, not from the file extension.
- Does the analysis need source code?
- No. It needs only the shipped image or the SBOM: no source code, no agent on the device and no connection into your network.
Check one of your own images
The app and the reports are in German. Questions in English are welcome.