ONEKEY invites you to their event

From Firmware to SBOM: Building Evidence-Based Software Inventories

About this event

What if the firmware is all you have?

Having an SBOM is only useful if the information inside it is accurate, relevant, and suitable for the task at hand.

In embedded software environments, manufacturers and resellers do not always receive a complete SBOM from their suppliers. In some cases, the only artifact available is the firmware itself.

This creates a practical challenge: How can you identify the software components in the final firmware and build an SBOM that is useful internally and can also be shared with customers, partners, and other stakeholders?

In this webinar, we focus on the firmware-only scenario and show how binary analysis can help identify software components, build a usable software inventory, and review and enrich the available component information.

You will learn:

  • How to generate an SBOM when only the firmware binary is available
  • How binary analysis can identify software components in embedded firmware
  • How to review component evidence and improve the resulting software inventory
  • How to turn firmware analysis results into a usable and actionable SBOM
  • How to export and share the resulting SBOM using standard formats such as CycloneDX and SPDX
  • Live Demo of the ONEKEY platform

The session will include a live demonstration showing the complete journey from firmware analysis to component visibility and SBOM export.

Key Takeaways

After the webinar, you will have a clearer understanding of:

  • A missing supplier SBOM does not have to be a dead end — software inventories can be built directly from firmware binaries.
  • An SBOM is only as useful as the evidence behind it — component identification and supporting evidence are essential for confidence in the results.
  • SBOM generation is not the finish line — reviewing and improving the inventory is what makes it actionable.
  • Standardized output makes SBOM data usable beyond the analysis itself — formats such as CycloneDX and SPDX enable integration, sharing, and downstream processes.

This webinar is designed for professionals working in product cybersecurity, product security, software supply chain security, SBOM management, vulnerability management, compliance, and embedded software development who need reliable visibility into the software components contained in connected products and embedded systems.

Go beyond SBOM generation — build software inventories you can actually use.

Can’t join live? No problem — register now, and you’ll receive the on-demand recording after the webinar.

Hosted by

  • Team member
    T
    Tushar Bhanage Product Marketing Manager @ ONEKEY

    Tushar has several years of experience in product marketing across the automotive, manufacturing, and IoT sectors. At ONEKEY, he helps customers navigate complex topics such as firmware security, SBOM, and vulnerability management, translating technical capabilities into clear business value.

  • Team member
    T
    Jen-Chih Lo Sales Manager @ ONEKEY GMBH

    Jen-Chih has years of experience with customers within semi-conductor industry and industrial automation specifically in East Asia. His expertise helps customer understanding how to increase ROI by reducing repetitive monitoring tasks.

ONEKEY

We automate software security & compliance of connected products at scale.

ONEKEY is a specialist for Product Cybersecurity for IoT & OT. Using automatically generated "Digital Twins" and "Software Bill of Materials" of devices, ONEKEY analyzes firmware for security vulnerabilities & compliance violations, without source code, device, or network access.