ONEKEY Webinar: RTOS Binary Analysis - Uncovering Hidden Vulnerabilities in Embedded Systems

READY TO UPGRADE YOUR RISK MANAGEMENT?
Make cybersecurity and compliance efficient and effective with ONEKEY.
.avif)
Tanja Sommer
tanja.sommer@onekey.com
RTOS Binary Analysis is becoming increasingly important as manufacturers and security teams seek greater visibility into the software running inside embedded devices.
RTOS-based systems power critical products across automotive, medical, industrial, and IoT environments. Yet unlike Linux-based systems, they often provide little visibility into the software components running beneath the surface. Source code, symbols, software manifests, and vendor documentation are frequently unavailable, making software transparency and vulnerability assessment a significant challenge.
Without this visibility, organizations are often left with a simple question: What is actually running inside this device?
In this webinar, we demonstrate how ONEKEY performs RTOS Binary Analysis directly from firmware images—even when no source code, SBOM, debugging information, or vendor documentation exists.
RTOS Binary Analysis: From Firmware Extraction to Component Discovery
Effective RTOS Binary Analysis begins long before vulnerabilities can be identified. We walk through the complete analysis pipeline, starting with firmware extraction and the unique challenges that make RTOS firmware fundamentally different from Linux-based systems.
Participants will learn how CPU architecture detection, load address reconstruction, and binary disassembly establish the foundation for meaningful firmware analysis. Building on this, we demonstrate how software components such as RTOS kernels, TCP/IP stacks, cryptographic libraries, and third-party software libraries can be identified automatically.
The result is a comprehensive component inventory that provides software transparency even when no Software Bill of Materials (SBOM) is available.
RTOS Binary Analysis for Vulnerability Discovery
Understanding which components are present is only the first step.
We also show how RTOS Binary Analysis enables the identification of vulnerabilities directly within firmware binaries, helping security teams uncover weaknesses that traditional software inventory approaches often miss.
Finally, we explain how component intelligence and automated CVE reduction work together to eliminate noise, reduce false positives, and focus attention on vulnerabilities that are genuinely relevant to the device under analysis.
What You Will Learn
- Why RTOS firmware remains a security blind spot for many organizations
- How RTOS Binary Analysis differs from traditional software composition analysis
- How firmware extraction works in RTOS environments
- How CPU architectures and load addresses can be identified automatically
- How software components can be discovered without source code or documentation
- How complete component inventories can be generated when no SBOM exists
- How RTOS Binary Analysis helps uncover vulnerabilities hidden within firmware
- How automated CVE reduction improves the accuracy of vulnerability assessments
Who Should Attend?
This webinar is designed for:
- Product Security Professionals
- Firmware Analysts
- Vulnerability Researchers
- PSIRT Teams
- Embedded Software Engineers
- Device Manufacturers and Product Owners
Whether you are responsible for firmware security, vulnerability management, or product cybersecurity, this session provides practical insights into how RTOS Binary Analysis improves visibility into embedded software and helps identify vulnerabilities that would otherwise remain hidden.
Register Now
Join us to learn how RTOS Binary Analysis can reveal software components, uncover hidden vulnerabilities, and provide deeper visibility into embedded systems.
Register now to secure your spot.
Meet us there

SPEAKERS
ON-SITE TEAM

Roman Wagner
Roman conducts offensive security research on IoT and OT devices specializing in firmware analysis, vulnerability research, and reverse engineering of embedded systems. He translates research findings into scalable product capabilities for automated firmware and device security assessment.

Maximilian Kleemann
In his current role, Max helps enterprises automate and continuously monitor the security aspects of their embedded devices, using binary analysis, software bill of materials, and CI/CD pipeline integration.
RELATED Events

ONEKEY Webinar: CRA Phase I: Incident Reporting & Operational Readiness
Learn how to prepare CRA reporting, escalation, and PIRT processes for operational compliance readiness. Register Now!
About Onekey
ONEKEY is the leading European specialist in Product Cybersecurity & Compliance Management and part of the investment portfolio of PricewaterhouseCoopers Germany (PwC). The unique combination of the automated ONEKEY Product Cybersecurity & Compliance Platform (OCP) with expert knowledge and consulting services provides fast and comprehensive analysis, support, and management to improve product cybersecurity and compliance from product purchasing, design, development, production to end-of-life.

CONTACT:
Sara Fortmann
Senior Marketing Manager
sara.fortmann@onekey.com
euromarcom public relations GmbH
team@euromarcom.de
Ready to automate your Product Cybersecurity & Compliance?
Make cybersecurity and compliance efficient and effective with ONEKEY.


