​â¶Ä‹â¶Ä‹â¶Ä‹SBOM (Software Bill of Materials) Generation, Import & Analysis
- ​â¶Ä‹â¶Ä‹â¶Ä‹â€‹â¶Ä‹â¶Ä‹â¶Ä‹â€‹â¶Ä‹â¶Ä‹â¶Ä‹â€‹â€‹Entercept allows users to generate or import SBOMs (Software Bill of Materials) to analyze dependencies and security risks.
- It supports API-based ingestion, making it useful for integration into existing security workflows.​â¶Ä‹â¶Ä‹â¶Ä‹â€‹â€‹â€‹
Dependency Analysis & Blast Radius
- The platform visualizes software dependencies through a dependency tree.
- It helps organizations understand the blast radius of a vulnerable or compromised package within their environment.
Open Source Optics (OSO) – Contributor & Threat Attribution
- One of Entercept’s unique features is its ability to track open-source maintainers and their affiliations.
- It pulls contributor data from repositories (e.g., GitHub) and flags contributors based on location, employer, and activity.
- Example: If a package maintainer is located in a sanctioned country (e.g., Russia, China), the platform flags it as a potential supply chain risk.
Threat Intelligence & Risk Assessment
- Entercept goes beyond traditional Software Composition Analysis (SCA) by identifying risk factors such as:
- Unmaintained dependencies (stale projects with inactive maintainers).
- Projects with weak security governance (e.g., no code reviews or branch protection).
- Packages controlled by groups in adversarial nations.​â¶Ä‹â¶Ä‹â¶Ä‹â€‹â¶Ä‹â¶Ä‹â¶Ä‹â€‹â¶Ä‹â¶Ä‹â¶Ä‹
Automated Alternative Recommendations
- Entercept suggests alternative open-source libraries that provide similar functionality when a risky package is identified.
Continuous Monitoring & Alerting
- It tracks software packages over time and alerts users if an update introduces a new risk or threat actor.