Supported formats

What LegacyMind reads and what you get back

Firmware images with Linux, bare-metal builds from Keil, IAR or GNU Arm, and your suppliers' SBOMs. No source code, no agent on the device.

Input

Firmware

File size 10 KB to 2 GB per upload. As of 5 October 2026.

InputWhat is readFile extensions

Firmware images with Linux

The image as you ship it: archives, raw images, file systems (SquashFS, JFFS2, CramFS, UBI, YAFFS2, ext), kernel and boot images including ARM zImage, update containers and VM disks. The analysis unpacks down to the root file system and reads package databases (dpkg, opkg, apk, rpm), binaries and the kernel.

.zip .tar .gz .tgz .bz2 .xz .lzma .lz4 .zst .7z .rar .cpio .bin .fw .img .rom .raw .dd .squashfs .jffs2 .cramfs .ubi .ubifs .yaffs2 .ext2 .ext3 .ext4 .iso .uimage .zimage .vmlinuz .itb .fit .initrd .trx .chk .npk .swu .mender .raucb .wup .vmdk .qcow2 .vdi .vhd .vhdx

Components, versions, vulnerabilities.zip .tar .gz .tgz .bz2 .xz .lzma .lz4 .zst .7z .rar .cpio .bin .fw .img .rom .raw .dd .squashfs .jffs2 .cramfs .ubi .ubifs .yaffs2 .ext2 .ext3 .ext4 .iso .uimage .zimage .vmlinuz .itb .fit .initrd .trx .chk .npk .swu .mender .raucb .wup .vmdk .qcow2 .vdi .vhd .vhdx

Bare-metal builds (ELF, AXF)

Microcontroller builds from Keil MDK, IAR or GNU Arm. Read: CMSIS packs, versioned from the pack vendor's own description, version records in the binary (for example RTX5) and versions from source paths (FreeRTOS, lwIP, mbedTLS, STM32Cube). Plus hardening (stack canary, MPU, privilege separation) and embedded keys.

.elf .axf .out

Components, versions, vulnerabilities.elf .axf .out

Raw microcontroller images (BIN)

A BIN without a file system is read byte by byte. Components are named where the bytes evidence them, for example through the version strings of TLS libraries.

.bin

Read, components where the bytes evidence them.bin

Windows CE images

The ROM module table and the version resources of the programs are read.

Read, components where the bytes evidence them

Intel HEX and Motorola S-record

Accepted and recognised. Until the conversion to bytes is done, please upload the BIN or the AXF of the same build.

.hex .ihex .s19 .srec .mot

Accepted and recognised.hex .ihex .s19 .srec .mot

Components, versions, vulnerabilities: parts with their versions, matched against the vulnerability sources. Read: the content is read, and components are named where the bytes evidence them. Accepted and recognised: the upload takes the file and recognises the format; the content is not read yet.

Input

Supplier SBOMs

Your suppliers' SBOMs in CycloneDX (JSON, XML) or SPDX (JSON, tag-value, SPDX 3.0 JSON-LD), up to 64 MB. The format is detected from the document, not the file name. Every component is matched against the vulnerability sources.

Formats: CycloneDX 1.x JSON · CycloneDX 1.x XML · SPDX 2.x JSON · SPDX 2.x Tag-Value · SPDX 3.0.x JSON-LD

Image and SBOM on the same device

Today you get two results side by side: the measured inventory of the image and the CVE matching of the supplier SBOM. Both sit on the same device, so you can read them next to each other. The automatic check of which declared component is actually in the image is in progress.

Output

What you get back

  • SBOM export

    CycloneDX 1.6 JSON and CSV. Every component says where in the image it was read.

  • Vulnerabilities

    Matched against 16 sources, enriched with CISA KEV and EUVD. For supplier SBOMs it is 12 sources: your suppliers' component names go to no public query API.

  • A decision per finding

    A CERT/CC SSVC decision for every vulnerability found, with the inputs it follows from.

  • Two reports

    A management summary and a technical findings report, both in German, with findings against EU CRA Annex I and § 30 BSIG.

  • Your data

    The uploaded firmware image is deleted after the analysis, on every path an analysis can end on.

You make the conformity statement. The reports provide technical findings as its basis.

In progress

Next

  • VEX and CSAF export
  • SBOM export as SPDX
  • Firmware Extractor (closed beta)

Questions

Can LegacyMind check Keil builds?
Yes. Upload the AXF. It reads the CMSIS packs with their versions, version records in the binary and versions from source paths, plus hardening and embedded keys. An Intel HEX file is accepted but not yet converted to bytes; upload the BIN or the AXF of the same build instead.
Which SBOM formats are read?
CycloneDX as JSON or XML, and SPDX as JSON, tag-value or SPDX 3.0 JSON-LD. The format is detected from the document, not from the file extension.
Does the analysis need source code?
No. It needs only the shipped image or the SBOM: no source code, no agent on the device and no connection into your network.

Check one of your own images

The app and the reports are in German. Questions in English are welcome.