Binary Integrity Verification · Embedded Systems

Know exactly what changed in the firmware. Prove it.

AegisRE ingests compiled UAV, UGV and USV firmware binaries, runs reproducible analysis pipelines, and produces evidence reports identifying whether a binary has been tampered with — and what the modification likely intends.

Differential Analysis · ARM Cortex-M7
Certified baseline · v1.2.3
Field-extracted · v1.3.0
3 regions modified · localised to 0x08001242 Integrity 0.41
0.07
Integrity score on known-good firmware
100%
Analysis runs locally — binaries never leave
The gap since 2010

Safety-critical firmware ships every day. No commercial tool systematically verifies it.

Three events — sixteen years apart — share one root cause: compiled binaries running in systems where lives depend on them, with no standard way to check their integrity.

2010

Stuxnet

PLC firmware was surgically modified to cause physical destruction while reporting normal values to every monitoring layer. The change was discoverable by comparing against the certified baseline from the moment of deployment — but no tool existed to perform that comparison systematically.

discoverable by binary comparison · undetected
2015

The Volkswagen defeat device

ECU firmware detected EPA test cycles and switched to compliant calibration maps. Regulators had the binary but no tooling to analyse it. Nobody compared the certified binary against field-extracted firmware. The fraud ran for seven years.

7 years undetected · regulators held the evidence
17–25

Drone firmware supply chain

Researchers found 16 firmware vulnerabilities in a major drone manufacturer — serial-number forgery, geofence bypass for restricted airspace, and covert telemetry sent to the manufacturer without operator knowledge. The vendor was later added to the US FCC Covered List. Binary analysis could have surfaced the undocumented paths before deployment.

16 vulnerabilities · covert telemetry
The common thread: compiled binaries in safety-critical systems, with no systematic tool for verifying integrity or analysing modifications. AegisRE is built to close exactly that gap.
How it works

Ingest a binary. Get evidence a regulator can read.

A deterministic pipeline turns a compiled firmware image into a structured report with full provenance — tool versions, timestamps, and artifact hashes attached to every claim.

01

Ingest

Compiled firmware is hashed and registered. Baselines are recorded at certification time.

02

Compare

Field-extracted binaries are diffed against the registered baseline. Every change is detected and localised.

03

Identify

Multi-stage analysis surfaces meaningful changes and anomalies, each stage isolated from the rest.

04

Report

A structured evidence report separates observed facts from inference — written for procurement, legal, and regulators.

Validated on real firmware

Capabilities backed by a 0.07 integrity score on ArduCopter.

  • Baseline registration & cryptographic-hash binary comparison
  • Multi-stage integrity analysis with composite scoring
  • Modification & change-impact assessment
  • Backdoor and undocumented-path detection
  • Custom rules and signature detection
  • Detailed PQC (post-quantum cryptography) verification
  • Evidence reports with full provenance & alternative explanations
EVIDENCE REPORT · ArduCopter 4.6.3
target    STM32F765 · ARM Cortex-M7
platform  Pixhawk 4
baseline  sha256:9f2a…c41e
stages    6 complete · isolated
parsers   9 gaps fixed in validation
verdict   KNOWN-GOOD · within threshold
0.07
Composite integrity score
Target threshold < 0.15 · result well below

Trust your firmware. Assure your mission.

Request an evidence report