re-firmware - Analyze firmware images offline and in isolated sandboxes
Extracts and analyzes authorized firmware images for filesystems, credentials, secrets, boot services, binary risks, and optional isolated QEMU emulation.
Tags
Updated: 2026-10-05Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Hash firmware images
- Identify formats and architectures
- Extract embedded filesystems
- Discover credentials and secrets
- Review boot scripts and services
- Triage binary vulnerabilities
- Emulate firmware in QEMU
Inputs
- Authorized firmware image path
- Firmware SHA-256 hash
- Isolated extraction environment
- Data handling scope
- Authorization cache
- Dynamic emulation approval
Outputs
- Extraction notes
- Evidence hash
- Command log
- Finding draft
- Extracted filesystem artifacts
- Credential and secret findings
- Architecture and entropy records
Requirements
- Revertible isolated environment
- Extraction network disabled
- Authorization for firmware inspection
- Explicit approval for dynamic emulation
- Required policy validation gates
