PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Guide4 min readReviewed September 20269 sources

HBOM tools: open-source building blocks for hardware and firmware inventory

No single open-source tool produces a complete HBOM. A small set of well-established projects, each covering one layer, can be combined into a reliable pipeline.

Key takeaways
  • In-band tools such as dmidecode and lshw read what the platform firmware and buses report; dmidecode’s own documentation warns this data is not always reliable.
  • fwupd and the LVFS expose device firmware versions on Linux and distribute vendor updates.
  • DMTF Redfish provides out-of-band firmware and software inventories from BMCs.
  • CHIPSEC assesses platform firmware security, while uSWID and CycloneDX CLI handle firmware SBOM metadata and BOM validation.

Think in layers, not products

An HBOM combines data from several vantage points: what the operating system can see, what the management controller reports out of band, what the firmware says about itself, and what the supplier declares. The open-source projects below each cover one of those layers. They are described as their maintainers describe them; none of them is an HBOM platform by itself.

Tool overview

ProjectLayerWhat it providesLicence
dmidecodeIn-band, SMBIOS/DMISystem manufacturer, model, serial number, BIOS version, slots and memory modulesGPL
lshwIn-band, buses and DMIMemory, firmware version, mainboard, CPU and cache configuration; text, XML or HTML outputGPL-2.0
fwupd / LVFSDevice firmwareDetected devices and firmware versions; vendor firmware distributionLGPL-2.1 (fwupd)
DMTF RedfishOut-of-band, BMCFirmware and software inventory collections via a standard APIOpen standard
CHIPSECPlatform securitySecurity analysis of hardware, BIOS/UEFI and platform componentsGPL-2.0
uSWIDFirmware SBOMEmbeds coSWID metadata in firmware; converts to CycloneDX and SPDXOpen source
CycloneDX CLIBOM handlingValidate, diff, merge, convert and sign BOMsOpen source

dmidecode and lshw

dmidecode “reports information about your system’s hardware as described in your system BIOS according to the SMBIOS/DMI standard”, including manufacturer, model name, serial number, BIOS version and asset tag [1]. Its maintainers are candid about the limits: DMI data “have proven to be too unreliable to be blindly trusted” because dmidecode “does not scan your hardware, it only reports what the BIOS told it to” [1]. Treat it as a declaration, not proof.

lshw reports “exact memory configuration, firmware version, mainboard configuration, CPU version and speed, cache configuration, bus speed”, drawing on DMI, PCI, USB, SCSI and other sources, and can output plain text, XML or HTML [2]. Because it walks several buses, it can surface components that DMI tables omit.

fwupd and the LVFS

fwupd is “a system daemon to allow session software to update firmware” on Linux; fwupdmgr get-devices displays “all devices detected by fwupd” along with their firmware details [3]. The Linux Vendor Firmware Service is the portal through which hardware vendors upload firmware updates, run as a Series of LF Projects [4]. For HBOM purposes, fwupd is a practical source of device firmware versions on Linux endpoints and servers.

DMTF Redfish

Redfish is DMTF’s standard for “simple and secure management for converged, hybrid IT and the Software Defined Data Center” [5]. Its update service exposes two collections: FirmwareInventory, which contains platform firmware that does not execute within a host operating system, and SoftwareInventory, for components that execute in the host context such as drivers [6]. Entries carry properties including version, manufacturer, release date and related hardware resources, which map well to HBOM fields. Because Redfish works out of band, it can inventory servers without an agent in the host OS.

CHIPSEC

CHIPSEC is “a framework for analyzing the security of PC platforms including hardware, system firmware (BIOS/UEFI), and platform components”, running on Windows, Linux and the UEFI shell [7]. It answers a different question from the inventory tools (is this platform configured securely?) and its maintainers state it is “for security testing purposes. Use at your own risk” [7]. Use it in a lab or on representative samples, not as a fleet inventory agent.

uSWID and CycloneDX CLI

uSWID is “a tiny tool for embedding CoSWID tags in EFI binaries”, supporting PE, FIT and other firmware images and exporting to CycloneDX and SPDX [8]. It helps firmware producers ship SBOM metadata inside the image. The CycloneDX CLI provides validate, diff, merge, convert and signing commands [9], which cover the plumbing once hardware data is expressed as CycloneDX.

Putting them together

  1. Use Redfish for servers with BMCs and fwupd, lshw or dmidecode for in-band detail.
  2. Normalise the output into CycloneDX device and firmware components (see CycloneDX for hardware BOMs).
  3. Validate and diff with CycloneDX CLI; use CHIPSEC for sampled integrity checks.
  4. Reconcile against supplier HBOMs, as described in HBOM generation.

How IntelliXBOM helps

IntelliXBOM ingests CycloneDX and SPDX output from collection pipelines such as these, validates it against required-field policies and keeps version history and diffs. It correlates the resulting hardware and firmware inventory with vulnerabilities, EOL data and business services, and maps it to framework controls as evidence.

Frequently asked questions

Can dmidecode alone produce an HBOM?

No. dmidecode reports what the BIOS declares in SMBIOS tables, and its maintainers warn that DMI data should not be blindly trusted. It is one useful input that should be combined with bus-level, out-of-band and supplier data.

How do I get firmware versions from servers without installing an agent?

Redfish-capable BMCs expose a FirmwareInventory collection through the Redfish update service. Querying it returns platform firmware entries with version and manufacturer properties, without touching the host operating system.

Is CHIPSEC an inventory tool?

Not primarily. CHIPSEC assesses the security of hardware and firmware configuration and is intended for security testing. It complements inventory tools by checking whether a platform is protected, rather than listing what it contains.

Sources

  1. Dmidecodedmidecode project (Savannah)www.nongnu.org/dmidecode/
  2. lshw, Hardware Listerlshw project (GitHub)github.com/lyonel/lshw
  3. fwupd, firmware update daemonfwupd project (GitHub)github.com/fwupd/fwupd
  4. Linux Vendor Firmware Service (LVFS)LVFS, a Series of LF Projectsfwupd.org/
  5. RedfishDMTFwww.dmtf.org/standards/redfish
  6. DSP2062, Redfish Firmware Update White PaperDMTFwww.dmtf.org/sites/default/files/standards/documents/DSP2062_1.0.0.pdf
  7. CHIPSEC: Platform Security Assessment FrameworkCHIPSEC project (GitHub)github.com/chipsec/chipsec
  8. python-uswiduSWID project (GitHub)github.com/hughsie/python-uswid
  9. CycloneDX CLIOWASP CycloneDX (GitHub)github.com/CycloneDX/cyclonedx-cli

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related HBOM guides

Across the BOM Suite

Put your HBOM under governance.Hardware & firmware trust with continuous correlation and timestamped evidence.