Firmware Security Workbench is a defensive analysis project.
The project supports:
- analyzing firmware files that you own or are authorized to inspect
- identifying risky strings, secrets, components, and configuration
- generating reports for defensive review
- comparing firmware versions for security regression analysis
The project does not support:
- exploit generation
- unauthorized device access
- credential theft or abuse
- malware deployment
- bypassing access controls on systems you do not own
If you find a security issue in the tool itself, open a private report if the project is hosted on GitHub with security advisories enabled. If private reporting is not available, open a minimal public issue without sharing exploit details.