<!-- Text version of https://kedloc.com/services -->

# A focused review of your firmware.

Software-focused firmware security, from an accessible image to a selected component or release change. Each engagement is assessed for feasibility and fit. Hardware testing and complete IoT ecosystem assessments are outside the service.

## Firmware image review

Initial pilot focus

Build an evidence-led understanding of one accessible firmware release.

**The question**

What does this image contain, and which areas warrant closer investigation?

**Potential scope**

Image structure, architecture, component identification, startup configuration and selected management services.

**Inputs**

A customer-supplied, accessible firmware image, authorization to review it, product context and available technical documentation. Physical extraction from a device is not included.

**Proposed output**

A technical report with observations, supporting evidence, coverage limits and prioritized next steps.

## Focused firmware research

Fit assessed per project

Investigate a defined security question about software inside the firmware.

**The question**

Can a selected firmware component, suspected issue or documented software change be better understood through a bounded investigation?

**Potential scope**

A selected binary, source component or software security question within firmware, where my exploit-development background fits the target.

**Inputs**

A clear firmware-related question, the relevant binary or source material and agreed conditions for software-based validation.

**Proposed output**

Technical observations and supporting evidence, with verified conclusions separated from unresolved questions.

## Firmware release and fix review

Separately scoped follow-on work

Understand what changed and what the evidence supports.

**The question**

What changed between the supplied firmware versions, and does the available software evidence support a proposed fix?

**Potential scope**

Selected firmware component or configuration changes, and review of a proposed software fix within the original assessment boundaries.

**Inputs**

The relevant firmware versions, change context, prior findings and software inputs needed to reproduce the agreed checks.

**Proposed output**

A change summary or retest note. A different version alone does not demonstrate successful remediation.

## Agree the boundaries first.

Hardware work is not offered. Device teardown, physical firmware extraction, debug-port testing, radio testing, fault injection and side-channel testing are excluded. Cloud, companion-app, network and full IoT ecosystem assessments are also outside the service. An offline review does not validate device behavior or hardware-backed protections.

## Define a realistic engagement.

- Confirm scope, authorization and feasibility.
- Agree evidence handling and deliverables.
- Set the fee and schedule before paid work starts.
- Define any walkthrough or retest in the proposal.

Source: [Services](https://kedloc.com/services)
