HBOM tools: open-source building blocks for hardware and firmware inventory
No single open-source tool produces a complete HBOM. A small set of well-established projects, each covering one layer, can be combined into a reliable pipeline.
- In-band tools such as dmidecode and lshw read what the platform firmware and buses report; dmidecode’s own documentation warns this data is not always reliable.
- fwupd and the LVFS expose device firmware versions on Linux and distribute vendor updates.
- DMTF Redfish provides out-of-band firmware and software inventories from BMCs.
- CHIPSEC assesses platform firmware security, while uSWID and CycloneDX CLI handle firmware SBOM metadata and BOM validation.
Think in layers, not products
An HBOM combines data from several vantage points: what the operating system can see, what the management controller reports out of band, what the firmware says about itself, and what the supplier declares. The open-source projects below each cover one of those layers. They are described as their maintainers describe them; none of them is an HBOM platform by itself.
Tool overview
| Project | Layer | What it provides | Licence |
|---|---|---|---|
| dmidecode | In-band, SMBIOS/DMI | System manufacturer, model, serial number, BIOS version, slots and memory modules | GPL |
| lshw | In-band, buses and DMI | Memory, firmware version, mainboard, CPU and cache configuration; text, XML or HTML output | GPL-2.0 |
| fwupd / LVFS | Device firmware | Detected devices and firmware versions; vendor firmware distribution | LGPL-2.1 (fwupd) |
| DMTF Redfish | Out-of-band, BMC | Firmware and software inventory collections via a standard API | Open standard |
| CHIPSEC | Platform security | Security analysis of hardware, BIOS/UEFI and platform components | GPL-2.0 |
| uSWID | Firmware SBOM | Embeds coSWID metadata in firmware; converts to CycloneDX and SPDX | Open source |
| CycloneDX CLI | BOM handling | Validate, diff, merge, convert and sign BOMs | Open source |
dmidecode and lshw
dmidecode “reports information about your system’s hardware as described in your system BIOS according to the SMBIOS/DMI standard”, including manufacturer, model name, serial number, BIOS version and asset tag [1]. Its maintainers are candid about the limits: DMI data “have proven to be too unreliable to be blindly trusted” because dmidecode “does not scan your hardware, it only reports what the BIOS told it to” [1]. Treat it as a declaration, not proof.
lshw reports “exact memory configuration, firmware version, mainboard configuration, CPU version and speed, cache configuration, bus speed”, drawing on DMI, PCI, USB, SCSI and other sources, and can output plain text, XML or HTML [2]. Because it walks several buses, it can surface components that DMI tables omit.
fwupd and the LVFS
fwupd is “a system daemon to allow session software to update firmware” on Linux; fwupdmgr get-devices displays “all devices detected by fwupd” along with their firmware details [3]. The Linux Vendor Firmware Service is the portal through which hardware vendors upload firmware updates, run as a Series of LF Projects [4]. For HBOM purposes, fwupd is a practical source of device firmware versions on Linux endpoints and servers.
DMTF Redfish
Redfish is DMTF’s standard for “simple and secure management for converged, hybrid IT and the Software Defined Data Center” [5]. Its update service exposes two collections: FirmwareInventory, which contains platform firmware that does not execute within a host operating system, and SoftwareInventory, for components that execute in the host context such as drivers [6]. Entries carry properties including version, manufacturer, release date and related hardware resources, which map well to HBOM fields. Because Redfish works out of band, it can inventory servers without an agent in the host OS.
CHIPSEC
CHIPSEC is “a framework for analyzing the security of PC platforms including hardware, system firmware (BIOS/UEFI), and platform components”, running on Windows, Linux and the UEFI shell [7]. It answers a different question from the inventory tools (is this platform configured securely?) and its maintainers state it is “for security testing purposes. Use at your own risk” [7]. Use it in a lab or on representative samples, not as a fleet inventory agent.
uSWID and CycloneDX CLI
uSWID is “a tiny tool for embedding CoSWID tags in EFI binaries”, supporting PE, FIT and other firmware images and exporting to CycloneDX and SPDX [8]. It helps firmware producers ship SBOM metadata inside the image. The CycloneDX CLI provides validate, diff, merge, convert and signing commands [9], which cover the plumbing once hardware data is expressed as CycloneDX.
Putting them together
- Use Redfish for servers with BMCs and fwupd, lshw or dmidecode for in-band detail.
- Normalise the output into CycloneDX
deviceandfirmwarecomponents (see CycloneDX for hardware BOMs). - Validate and diff with CycloneDX CLI; use CHIPSEC for sampled integrity checks.
- Reconcile against supplier HBOMs, as described in HBOM generation.
How IntelliXBOM helps
IntelliXBOM ingests CycloneDX and SPDX output from collection pipelines such as these, validates it against required-field policies and keeps version history and diffs. It correlates the resulting hardware and firmware inventory with vulnerabilities, EOL data and business services, and maps it to framework controls as evidence.
Frequently asked questions
Can dmidecode alone produce an HBOM?
No. dmidecode reports what the BIOS declares in SMBIOS tables, and its maintainers warn that DMI data should not be blindly trusted. It is one useful input that should be combined with bus-level, out-of-band and supplier data.
How do I get firmware versions from servers without installing an agent?
Redfish-capable BMCs expose a FirmwareInventory collection through the Redfish update service. Querying it returns platform firmware entries with version and manufacturer properties, without touching the host operating system.
Is CHIPSEC an inventory tool?
Not primarily. CHIPSEC assesses the security of hardware and firmware configuration and is intended for security testing. It complements inventory tools by checking whether a platform is protected, rather than listing what it contains.
Sources
- Dmidecodedmidecode project (Savannah)www.nongnu.org/dmidecode/
- lshw, Hardware Listerlshw project (GitHub)github.com/lyonel/lshw
- fwupd, firmware update daemonfwupd project (GitHub)github.com/fwupd/fwupd
- Linux Vendor Firmware Service (LVFS)LVFS, a Series of LF Projectsfwupd.org/
- RedfishDMTFwww.dmtf.org/standards/redfish
- DSP2062, Redfish Firmware Update White PaperDMTFwww.dmtf.org/sites/default/files/standards/documents/DSP2062_1.0.0.pdf
- CHIPSEC: Platform Security Assessment FrameworkCHIPSEC project (GitHub)github.com/chipsec/chipsec
- python-uswiduSWID project (GitHub)github.com/hughsie/python-uswid
- CycloneDX CLIOWASP CycloneDX (GitHub)github.com/CycloneDX/cyclonedx-cli
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.