Skip to main content
ABOUT MAGDOX

We build the firmware security tooling we wish had existed.

Every other part of the software supply chain got real tooling years ago. Firmware didn’t. CVEs got matched by hand, SBOMs lived in spreadsheets, and compliance turned into a once-a-year scramble. We got tired of watching that happen, so we built FDIE.

WHY WE EXIST

Security got automated everywhere. Except firmware.

Modern software teams have CI, SAST, SCA, and continuous CVE scanning built into how they ship code. Firmware teams are still doing this the hard way: reverse engineering by hand, SBOMs in a spreadsheet, and CVE lookups that only happen right before a deadline.

The result is firmware that ships with known vulnerabilities, no SBOM, and nothing to show an auditor. Regulators have noticed. The EU Cyber Resilience Act, ETSI EN 303 645, and IEC 62443 are turning what used to be optional into a legal requirement.

So we started Magdox. Not to build another once-a-year audit tool, but something that runs on every build automatically, without anyone having to remember to kick it off.

Invisible risk in every release

Most firmware images are packed with open-source components, and some of them have known vulnerabilities. Nobody catches it without extraction and analysis, so it ships anyway, sometimes into devices that will run for a decade.

Manual analysis doesn’t scale

Reverse engineering one firmware image by hand takes days. Doing that for every release, every product variant, and every customer just isn’t realistic without automation.

Regulation arrived faster than tooling

EU CRA Article 14 reporting becomes binding in September 2026, and full conformity requirements follow in December 2027. Most manufacturers we talk to aren’t ready for either.

OUR PRINCIPLES

Four beliefs that shape everything we build.

Automation is the product, not a feature

If something can be automated, we automate it. Running a security check once a year before an audit isn’t security, it’s paperwork. FDIE runs on every build, every time, without anyone needing to remember to turn it on.

Determinism over black-box AI

Every finding FDIE gives you traces back to a rule, a CVE record, or a fact in the binary you can go check yourself. No generative AI anywhere in the pipeline. Scan the same firmware twice and you get the same answer both times.

Compliance as a byproduct of good engineering

You shouldn’t need a whole separate project to satisfy EU CRA, ETSI, NIST, or IEC. Every analysis FDIE runs already doubles as evidence for your audit, so there’s no extra work and no separate checklist to maintain.

Transparency builds trust. Obscurity does not.

We publish exactly what FDIE checks, how it scores things, and what data it touches. Our engine architecture, test categories, and CVE sources are all written down and public. A security tool that’s a black box isn’t one we’d trust either.

BUILT FROM FIRST PRINCIPLES

We built the disassembler. From scratch.

At the core of FDIE is FirmBin, our own binary analysis and disassembly engine. We built it from published ISA manuals ourselves, not by wrapping Ghidra, Capstone, or radare2.

It disassembles ELF, PE, and raw firmware images across 15+ CPU architectures, including x86, ARM, ARM64, MIPS, RISC-V, PowerPC, SPARC, S390, MSP430, TriCore, PIC/dsPIC, MicroBlaze, Nios II, and more. Every engine ships self-contained, with nothing external to install at runtime.

The control-flow graph engine does real reachability analysis, checking whether a vulnerable code path can actually be hit. That’s what makes our VEX justifications something an auditor can trust, not just a checkbox.

See the full platform →

0

CPU architectures

0

Firmware and filesystem formats

0

Security test cases

0

CVEs in NVD database

No third-party black boxes

FirmBin doesn’t depend on Ghidra, Capstone, radare2, or any other external tool at runtime. Every analysis runs entirely on its own.

REGULATORY LANDSCAPE

Built for the compliance wave that’s already here.

FDIE maps every analysis result straight to the requirements of six global frameworks, so you don’t have to be the one interpreting the regulations.

EU CRA

EU Cyber Resilience Act

Article 14 vulnerability reporting obligations binding from September 2026. Full conformity assessment required by December 2027.

ETSI EN 303 645

ETSI Consumer IoT Security

European baseline for consumer IoT security, covering credential management, software updates, secure communications, and more.

NIST SP 800-193

NIST Platform Firmware Resilience

US guidelines for firmware protection, detection, and recovery, increasingly referenced in US federal procurement requirements.

IEC 62443-4-2

IEC Industrial Cybersecurity

Component-level security requirements for industrial automation and control systems, the gold standard for OT/ICS device manufacturers.

OWASP FSTM

OWASP Firmware Security Testing

The established methodology guide for firmware penetration testing. FDIE automates the analysis phases that would otherwise take weeks to complete by hand.

NIST IR 8259A

NIST IoT Device Cybersecurity

Core baseline for IoT device cybersecurity capabilities, referenced by US federal agencies and enterprise procurement teams alike.

LEADERSHIP

Founder-led, built from firsthand experience.

Magdox was founded by Manish Sharma. Before this, he spent years on the other side of the audit table: chasing CVEs in vendor SDKs, building SBOMs by hand the night before a deadline, and starting from zero on every new firmware version. FDIE is the tool he wished he’d had back then, so he built it.

Manish Sharma

Founder & Chief Executive Officer

Comes from a cybersecurity background spanning application security, exploit development, and offensive security, with binary analysis and firmware security as a deeper specialization. Built FDIE and the FirmBin disassembly engine from the ground up, with correctness as the starting point, not something bolted on later. Wants enterprise-grade firmware security to be something every hardware team can use, not just the big ones.

LinkedIn ↗

Small and founder-led, for now.

We’re not hiring yet, but when firmware, embedded security, or compliance tooling roles open up, you’ll see them on our careers page first.

Visit careers page →
Founded 2025

West Bengal, India

Magdox Private Limited

Registered company, India

Now in Beta

CRA-ready output, early access pricing

See your firmware’s security score in minutes.

Book a 30-minute walkthrough with our team. Bring your own firmware image or use one of ours.

or get in touch →