Digital forensics EU-developed
unblob
Recursively extracts firmware and other binary containers, carves unknown chunks and produces structured reports for analysts examining embedded-device images.
By ONEKEY GmbH / unblob project · Germany
The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.
At a glance
Recorded facts- Response workflow
- Digital forensics
- Developer or maintainer
- ONEKEY GmbH / unblob project
- Recorded country
- Germany
- Product model
- Open source
- Deployment
- Desktop/CLI
- Software license
- MIT
- Upstream status
- Active
- Evidence class
- EU-developed
What the sources establish
Origin noteONEKEY announced its standalone unblob extraction suite from Düsseldorf in 2022, and the current project license names ONEKEY GmbH as copyright holder.
Reported capabilities
- Recursive firmware/container extraction
- Unknown-region carving and entropy analysis
- CLI and container deployment
Scope and limits
unblob is a standalone extraction utility released from the commercial ONEKEY platform and does not itself provide a vulnerability verdict. Some optional external extractors have their own licenses and system requirements; the MIT grant applies to the upstream unblob repository.
Inspect the research evidence 5 source observations
identity / capabilities / deployment
Upstream describes a standalone extraction suite with recursive parsing, unknown-chunk carving, entropy and JSON reports; README gives pip, Docker, CLI and source installation.
Read sourcelicense / origin
Actual root LICENSE is the MIT grant with 2022 ONEKEY GmbH copyright.
Read sourceorigin / country
Düsseldorf-dated July 2022 ONEKEY announcement explicitly releases unblob as an open-source extraction suite and core platform component for independent security researchers.
Read sourcedeployment
Official unblob documentation gives local installation and an OCI container command, separate from access to the commercial ONEKEY SaaS.
Read sourcemaintenance
Upstream release list includes version 26.6.4 dated 4 June 2026 with new extractors and fixes; release activity is not a support guarantee.
Read source
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Put the tool in context.
Plan targeted evidence collection, check acquisition gaps and produce a traceable timeline. Source-linked guidance for Acquire, Dissect and DFIR ORC.
A digital forensics triage and evidence workflow