Endpoint Reality Becomes Monitored Supply-Chain Evidence
A desktop-based EDR angle unique to SBOMator: the Bumblebee collector inventories installed software and MCP servers, normalizes them to CycloneDX, detects integrity drift, and catches malicious packages before the public advisory โ routing actionable changes to your team.
Collect โ Baseline โ Control
The first run establishes the comparison baseline; every run after that is measured against it.
Collect
Registry software, runtimes, packages, browser/editor extensions, MCP servers, and agent skills โ inventoried read-only across Windows and developer endpoints.
Baseline
Normalized to CycloneDX with requested references, MCP pin status, and correlated CVEs โ establishing the integrity baseline for the endpoint.
Control
Integrity drift and package watchers trigger email/webhook alerts with delta JSON, HTML diff, and a hash-chained audit history.
Implemented Endpoint Controls
Endpoint-aware supply-chain assurance available through both the GUI and CLI.
Windows & Developer Inventory
Registry, NuGet, Scoop, Chocolatey, runtimes, browser/editor extensions, MCP, and agent skills โ the software actually installed, not just the manifest.
MCP Integrity Monitoring
Tracks server identity, requested references, and pin status; alerts on reference/pin drift with an optional Ed25519-signed audit chain.
Bounded Scan Profiles
Baseline, project, and deep modes plus ecosystem filters keep endpoint scans focused and repeatable.
GUI Alerts & Evidence
Email and webhook alerts for new CVEs or integrity changes, with delta JSON, HTML diff, and audit history โ SMTP presets and safe secret handling.
Catch Malicious Packages Before the Advisory
Registry malware intelligence and zero-day install-hook heuristics run in every scan and continuously on monitored endpoints.
Watch
Every SBOM scan and the endpoint watcher screen added and changed npm packages in real time.
Corroborate
OSV.dev MAL-* malware advisories (with an offline cache) plus an install-hook delta heuristic and multi-source IOC evidence.
Alert
“Malicious โ known bad” and “New install hook โ suspicious” verdicts surface in the endpoint tab and notifications.
Proven Against a Real Attack
Reproducible keyv/cacheable (“Mini Shai-Hulud”, August 2026) demonstration with a manifest-only victim project and a client-ready impact report โ flagged by the install-hook zero-day heuristic before any public advisory existed.
See EDR-SBOM Monitoring in Action
Turn the software actually installed on your engineering and operational endpoints into continuous, defensible supply-chain evidence.