Digital forensics EU-developed

unblob

Recursively extracts firmware and other binary containers, carves unknown chunks and produces structured reports for analysts examining embedded-device images.

By ONEKEY GmbH / unblob project · Germany

EU-developed

The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.

At a glance

Recorded facts
Response workflow
Digital forensics
Developer or maintainer
ONEKEY GmbH / unblob project
Recorded country
Germany
Product model
Open source
Deployment
Desktop/CLI
Software license
MIT
Upstream status
Active
Evidence class
EU-developed

What the sources establish

Origin note

ONEKEY announced its standalone unblob extraction suite from Düsseldorf in 2022, and the current project license names ONEKEY GmbH as copyright holder.

Reported capabilities

  • Recursive firmware/container extraction
  • Unknown-region carving and entropy analysis
  • CLI and container deployment

Scope and limits

unblob is a standalone extraction utility released from the commercial ONEKEY platform and does not itself provide a vulnerability verdict. Some optional external extractors have their own licenses and system requirements; the MIT grant applies to the upstream unblob repository.

Inspect the research evidence 5 source observations
  1. identity / capabilities / deployment

    Upstream describes a standalone extraction suite with recursive parsing, unknown-chunk carving, entropy and JSON reports; README gives pip, Docker, CLI and source installation.

    Read source
  2. license / origin

    Actual root LICENSE is the MIT grant with 2022 ONEKEY GmbH copyright.

    Read source
  3. origin / country

    Düsseldorf-dated July 2022 ONEKEY announcement explicitly releases unblob as an open-source extraction suite and core platform component for independent security researchers.

    Read source
  4. deployment

    Official unblob documentation gives local installation and an OCI container command, separate from access to the commercial ONEKEY SaaS.

    Read source
  5. maintenance

    Upstream release list includes version 26.6.4 dated 4 June 2026 with new extractors and fixes; release activity is not a support guarantee.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Plan targeted evidence collection, check acquisition gaps and produce a traceable timeline. Source-linked guidance for Acquire, Dissect and DFIR ORC.

A digital forensics triage and evidence workflow