Practice 03
Binary & Supply Chain Security
What ships is a binary, not a repository. We analyse the artefact: static and dynamic reverse engineering, coverage-guided and directed fuzzing, binary-level SBOM recovery, and provenance that a downstream verifier can check without trusting us.
Engagement parameters
TargetsFirmware · drivers · TEE · WASM runtimes · mobileToolingGhidra · IDA · AFL++ · LibAFL · syzkaller · angrFormatsSPDX 3.0 · CycloneDX 1.6 · VEX · in-toto · SLSADeliverablesAttack surface map · crash corpus · SBOM/VEX · provenance policy
Data sheet · A4 · SP-SVC-03Open PDF sheet
Operators · identities withheld
Named to clients under NDA at scoping19
Architectures with in-house lifters
48h
Crash to root-cause triage, median
SLSA L3
Provenance level delivered
100%
SBOMs reconciled against the binary
Operators · identities withheld
Named to clients under NDA at scopingReferences
What this practice is currently working against.
Next: Defensive Operations →
