We build the firmware security tooling we wish had existed.
Every other part of the software supply chain got real tooling years ago. Firmware didn’t. CVEs got matched by hand, SBOMs lived in spreadsheets, and compliance turned into a once-a-year scramble. We got tired of watching that happen, so we built FDIE.
Security got automated everywhere. Except firmware.
Modern software teams have CI, SAST, SCA, and continuous CVE scanning built into how they ship code. Firmware teams are still doing this the hard way: reverse engineering by hand, SBOMs in a spreadsheet, and CVE lookups that only happen right before a deadline.
The result is firmware that ships with known vulnerabilities, no SBOM, and nothing to show an auditor. Regulators have noticed. The EU Cyber Resilience Act, ETSI EN 303 645, and IEC 62443 are turning what used to be optional into a legal requirement.
So we started Magdox. Not to build another once-a-year audit tool, but something that runs on every build automatically, without anyone having to remember to kick it off.
Invisible risk in every release
Most firmware images are packed with open-source components, and some of them have known vulnerabilities. Nobody catches it without extraction and analysis, so it ships anyway, sometimes into devices that will run for a decade.
Manual analysis doesn’t scale
Reverse engineering one firmware image by hand takes days. Doing that for every release, every product variant, and every customer just isn’t realistic without automation.
Regulation arrived faster than tooling
EU CRA Article 14 reporting becomes binding in September 2026, and full conformity requirements follow in December 2027. Most manufacturers we talk to aren’t ready for either.
Four beliefs that shape everything we build.
Automation is the product, not a feature
If something can be automated, we automate it. Running a security check once a year before an audit isn’t security, it’s paperwork. FDIE runs on every build, every time, without anyone needing to remember to turn it on.
Determinism over black-box AI
Every finding FDIE gives you traces back to a rule, a CVE record, or a fact in the binary you can go check yourself. No generative AI anywhere in the pipeline. Scan the same firmware twice and you get the same answer both times.
Compliance as a byproduct of good engineering
You shouldn’t need a whole separate project to satisfy EU CRA, ETSI, NIST, or IEC. Every analysis FDIE runs already doubles as evidence for your audit, so there’s no extra work and no separate checklist to maintain.
Transparency builds trust. Obscurity does not.
We publish exactly what FDIE checks, how it scores things, and what data it touches. Our engine architecture, test categories, and CVE sources are all written down and public. A security tool that’s a black box isn’t one we’d trust either.
We built the disassembler. From scratch.
At the core of FDIE is FirmBin, our own binary analysis and disassembly engine. We built it from published ISA manuals ourselves, not by wrapping Ghidra, Capstone, or radare2.
It disassembles ELF, PE, and raw firmware images across 15+ CPU architectures, including x86, ARM, ARM64, MIPS, RISC-V, PowerPC, SPARC, S390, MSP430, TriCore, PIC/dsPIC, MicroBlaze, Nios II, and more. Every engine ships self-contained, with nothing external to install at runtime.
The control-flow graph engine does real reachability analysis, checking whether a vulnerable code path can actually be hit. That’s what makes our VEX justifications something an auditor can trust, not just a checkbox.
0
CPU architectures
0
Firmware and filesystem formats
0
Security test cases
0
CVEs in NVD database
No third-party black boxes
FirmBin doesn’t depend on Ghidra, Capstone, radare2, or any other external tool at runtime. Every analysis runs entirely on its own.
Built for the compliance wave that’s already here.
FDIE maps every analysis result straight to the requirements of six global frameworks, so you don’t have to be the one interpreting the regulations.
EU Cyber Resilience Act
Article 14 vulnerability reporting obligations binding from September 2026. Full conformity assessment required by December 2027.
ETSI Consumer IoT Security
European baseline for consumer IoT security, covering credential management, software updates, secure communications, and more.
NIST Platform Firmware Resilience
US guidelines for firmware protection, detection, and recovery, increasingly referenced in US federal procurement requirements.
IEC Industrial Cybersecurity
Component-level security requirements for industrial automation and control systems, the gold standard for OT/ICS device manufacturers.
OWASP Firmware Security Testing
The established methodology guide for firmware penetration testing. FDIE automates the analysis phases that would otherwise take weeks to complete by hand.
NIST IoT Device Cybersecurity
Core baseline for IoT device cybersecurity capabilities, referenced by US federal agencies and enterprise procurement teams alike.
Founder-led, built from firsthand experience.
Magdox was founded by Manish Sharma. Before this, he spent years on the other side of the audit table: chasing CVEs in vendor SDKs, building SBOMs by hand the night before a deadline, and starting from zero on every new firmware version. FDIE is the tool he wished he’d had back then, so he built it.
Founder & Chief Executive Officer
Comes from a cybersecurity background spanning application security, exploit development, and offensive security, with binary analysis and firmware security as a deeper specialization. Built FDIE and the FirmBin disassembly engine from the ground up, with correctness as the starting point, not something bolted on later. Wants enterprise-grade firmware security to be something every hardware team can use, not just the big ones.
LinkedIn ↗Small and founder-led, for now.
We’re not hiring yet, but when firmware, embedded security, or compliance tooling roles open up, you’ll see them on our careers page first.
West Bengal, India
Registered company, India
CRA-ready output, early access pricing
See your firmware’s security score in minutes.
Book a 30-minute walkthrough with our team. Bring your own firmware image or use one of ours.
