EDR-SBOM & Real-Time Threat Detection | ESL SBOMator
EDR-SBOM & Real-Time Threat Detection

Endpoint Reality Becomes Monitored Supply-Chain Evidence

A desktop-based EDR angle unique to SBOMator: the Bumblebee collector inventories installed software and MCP servers, normalizes them to CycloneDX, detects integrity drift, and catches malicious packages before the public advisory โ€” routing actionable changes to your team.

Collect โ†’ Baseline โ†’ Control

The first run establishes the comparison baseline; every run after that is measured against it.

1

Collect

Registry software, runtimes, packages, browser/editor extensions, MCP servers, and agent skills โ€” inventoried read-only across Windows and developer endpoints.

2

Baseline

Normalized to CycloneDX with requested references, MCP pin status, and correlated CVEs โ€” establishing the integrity baseline for the endpoint.

3

Control

Integrity drift and package watchers trigger email/webhook alerts with delta JSON, HTML diff, and a hash-chained audit history.

Implemented Endpoint Controls

Endpoint-aware supply-chain assurance available through both the GUI and CLI.

Windows & Developer Inventory

Registry, NuGet, Scoop, Chocolatey, runtimes, browser/editor extensions, MCP, and agent skills โ€” the software actually installed, not just the manifest.

MCP Integrity Monitoring

Tracks server identity, requested references, and pin status; alerts on reference/pin drift with an optional Ed25519-signed audit chain.

Bounded Scan Profiles

Baseline, project, and deep modes plus ecosystem filters keep endpoint scans focused and repeatable.

GUI Alerts & Evidence

Email and webhook alerts for new CVEs or integrity changes, with delta JSON, HTML diff, and audit history โ€” SMTP presets and safe secret handling.

Catch Malicious Packages Before the Advisory

Registry malware intelligence and zero-day install-hook heuristics run in every scan and continuously on monitored endpoints.

1

Watch

Every SBOM scan and the endpoint watcher screen added and changed npm packages in real time.

2

Corroborate

OSV.dev MAL-* malware advisories (with an offline cache) plus an install-hook delta heuristic and multi-source IOC evidence.

3

Alert

“Malicious โ€” known bad” and “New install hook โ€” suspicious” verdicts surface in the endpoint tab and notifications.

Proven Against a Real Attack

Reproducible keyv/cacheable (“Mini Shai-Hulud”, August 2026) demonstration with a manifest-only victim project and a client-ready impact report โ€” flagged by the install-hook zero-day heuristic before any public advisory existed.

Detection boundary. Detection is based on registry metadata, OSV malware intelligence, and lifecycle-script heuristics. EDR-SBOM is endpoint-aware supply-chain assurance that complements, not replaces, behavioral EDR or process/network telemetry. Bumblebee collection is read-only and suppresses sensitive MCP and skill details; it does not perform malware detection, quarantine, or host isolation.

See EDR-SBOM Monitoring in Action

Turn the software actually installed on your engineering and operational endpoints into continuous, defensible supply-chain evidence.