---
title: S4x23 SBOM Challenge — Part 1
description: aDolus participated in the S4x23 SBOM Challenge run by Idaho National Labs (INL) to share SBOM capabilities with attendees. This is part 1 of a series.
image: https://blog.adolus.com/hubfs/SBOM%20Pavilion.png
---

[![aDolus Logo](https://adolus.com/images/adolus-white-new60px.webp)](https://adolus.com/) [Blog](https://blog.adolus.com/)

Product

- ##### Fact Platform
- [Overview](https://adolus.com/fact/overview/)
- [Benefits](https://adolus.com/fact/benefits/)
- [Technical Details](https://adolus.com/fact/technical/)

- ##### Fact Features
- [Software Validation & Scoring](https://adolus.com/product/software-validation-scoring/)
- [SBOM Creation](https://adolus.com/product/sbom/)
- [VEX Documents](https://adolus.com/product/vex-documents/)
- [Malware Detection](https://adolus.com/product/malware-detection/)
- [Certificate Validation](https://adolus.com/product/certificate-validation/)
- [Software Supplier Discovery](https://adolus.com/product/software-supplier-discovery/)

Solutions

- ##### By use case
- [Vulnerability Management](https://adolus.com/solutions/vulnerability-management/)
- [Compliance](https://adolus.com/solutions/compliance/)
- [Risk Management](https://adolus.com/solutions/risk-management/)
- [Operational Insights](https://adolus.com/solutions/operational-insights/)

- ##### By job function
- [Product Managers](https://adolus.com/solutions/product-managers/)
- [Security Managers](https://adolus.com/solutions/security-managers/)
- [Engineering Managers](https://adolus.com/solutions/engineering-managers/)
- [Procurement Managers](https://adolus.com/solutions/procurement-managers/)

- ##### By role in the supply chain
- [Vendors & OEMs](https://adolus.com/solutions/vendors-oems/)
- [Asset Owners](https://adolus.com/solutions/asset-owners/)

Resources

- ##### A Deeper Dive
- [Blog](https://blog.adolus.com/)
- [Videos & Podcasts](https://adolus.com/resources/video-podcasts/)
- [Infographics](https://adolus.com/resources/infographics/)
- [FAQ](https://adolus.com/resources/faq/)
- [Document Library](https://adolus.com/resources/document-library/)

- ##### Educational Tools
- [Executive Order 14028 Timeline](https://info.adolus.com/eo14028-timeline)
- [Log4j Resources](https://adolus.com/vulnerabilities/log4j/)

Company

- [About Us](https://adolus.com/company/about/)
- [Our Partners](https://adolus.com/company/partners/)
- [News](https://adolus.com/company/news/)
- [Careers](https://adolus.com/company/careers/)
- [Contact aDolus](https://adolus.com/company/contact/)

[Get a Demo](https://info.adolus.com/schedule-a-fact-demo-3)

[#S4](https://blog.adolus.com/tag/s4) [Vulnerability Tracking](https://blog.adolus.com/tag/vulnerability-tracking) [SBOM](https://blog.adolus.com/tag/sbom) [VEX](https://blog.adolus.com/tag/vex)

# S4x23 SBOM Challenge — Part 1

 By [Derek Kruszewski](https://blog.adolus.com/author/derek-kruszewski) on February, 24 2023

[Back](https://blog.adolus.com)

S4x23 SBOM Challenge — Part 1

Share

<https://twitter.com/intent/tweet?text=&url=https://blog.adolus.com/s4x23-sbom-challenge-part-1> <http://www.facebook.com/share.php?u=https://blog.adolus.com/s4x23-sbom-challenge-part-1> <http://www.linkedin.com/shareArticle?mini=true&url=https://blog.adolus.com/s4x23-sbom-challenge-part-1> [mailto:?subject=Check%20out%20https://blog.adolus.com/s4x23-sbom-challenge-part-1%20&body=Check%20out%20https://blog.adolus.com/s4x23-sbom-challenge-part-1&media=https://6687498.fs1.hubspotusercontent-na1.net/hubfs/6687498/SBOM%20Pavilion.png](mailto:?subject=Check%20out%20https://blog.adolus.com/s4x23-sbom-challenge-part-1%20&body=Check%20out%20https://blog.adolus.com/s4x23-sbom-challenge-part-1&media=https://6687498.fs1.hubspotusercontent-na1.net/hubfs/6687498/SBOM%20Pavilion.png)

[Back to main blog](https://blog.adolus.com)

Share

<https://twitter.com/intent/tweet?text=&url=https://blog.adolus.com/s4x23-sbom-challenge-part-1> <http://www.facebook.com/share.php?u=https://blog.adolus.com/s4x23-sbom-challenge-part-1> <http://www.linkedin.com/shareArticle?mini=true&url=https://blog.adolus.com/s4x23-sbom-challenge-part-1> [mailto:?subject=Check%20out%20https://blog.adolus.com/s4x23-sbom-challenge-part-1%20&body=Check%20out%20https://blog.adolus.com/s4x23-sbom-challenge-part-1&media=https://6687498.fs1.hubspotusercontent-na1.net/hubfs/6687498/SBOM%20Pavilion.png](mailto:?subject=Check%20out%20https://blog.adolus.com/s4x23-sbom-challenge-part-1%20&body=Check%20out%20https://blog.adolus.com/s4x23-sbom-challenge-part-1&media=https://6687498.fs1.hubspotusercontent-na1.net/hubfs/6687498/SBOM%20Pavilion.png)

The aDolus Team has just returned from participating in the [SBOM Challenge](https://s4xevents.com/sbom/) at the S4x23 cybersecurity conference in Miami, Florida. This blog is the first of a series reporting on what we did during the challenge and what we learned from the process.

The challenge was run by Idaho National Labs (INL) who noted “*the S4x23 conference has organized a challenge event to explore the functionality of tools available in the SBOM market and share information about SBOMs and tools with S4x23 attendees.*”

INL specifically looked at Software Bill of Materials ([SBOM](https://blog.adolus.com/ntia-publishes-minimum-components-of-an-sbom)) creation and ingestion, vulnerability analysis and management, and [Vulnerability Exploitability eXchange (VEX) document](https://blog.adolus.com/what-is-vex-and-what-does-it-have-to-do-with-sboms) ingestion. The challenge wasn’t framed as a head-to-head bake-off but rather a more thoughtful survey and comparison of the different approaches available in the SBOM market. INL advised that “*No scoring or comparative evaluation of the tool’s performance will be provided. However, where informative, functionality descriptions or screenshots may be used to illustrate differences in approach or show different ways specific tools performed analysis and presented results.*”

Our team reported back that this was, for the most part, a really collegial affair with lots of SBOM-vendor cooperation and a genuine desire to drive more education about SBOMs. We'd like to thank the other participants for bringing different perspectives and approaches to the challenge.

## The Targets

For the challenge, INL presented the challenge participants with three software/firmware targets for analysis:

| ![Windows installer icon](https://blog.adolus.com/hs-fs/hubfs/image-png-2.png?width=82&height=72&name=image-png-2.png) | A Windows installer for OSIsoft’s PI ProcessBook 2015 R3 Patch 1 |
| --- | --- |
| ![Motorola 68000 chip](https://blog.adolus.com/hs-fs/hubfs/image-png-1.png?width=93&height=43&name=image-png-1.png) | A firmware image for a Motorola 68000 Transformer Protection Unit 2000R |
| ![Linux penguin](https://lh5.googleusercontent.com/F4chAOK-hiKM2UgX_-T2kBHOuJ4cvJKOzBQgLWalInVpWDifz7dgU0fwz1IGPIIAbPdELV3n-RhGvgDsP3fTHQQQTCNdXrGT9vlnD1OmKOpebG-H7ANp1a1dibbv4av5OoBQmRzSGjgEpkNA6U090FE) | A Linux-based OpenWRT firmware archive for a Cisco Meraki MR26 Device |

## The Tasks

INL then asked the participants to do three tasks for each target:

| ![SBOM icon](https://lh5.googleusercontent.com/xwvf1Fj_6wcXe1JLgme-XHYNNJx-kBGr1uQtK_7VwObyLlkrG1bpUHTFtVo-2Pd0HYQ45OGYT3yhqfgm7KiNaLo1Wv9wQHUJDSVVO5IFaKYSwUbeoDackewq04V3085b2SZsGv_WnzdPD8KnlwZrGIo) | Create an accurate SBOM |
| --- | --- |
| ![Vulnerability management icon](https://lh5.googleusercontent.com/PN2H4kgaN9T4wguWPFd9trcOvFI5K1mhBWMPNYetN8Z8fjWLK5O-DXuXeTK4I3W2UWfXhHOo1mmy8pzphJ_C0eUsgQRuIgrAj8rOCcgspwOBzZz50Is3WRINpeW-iQZp0zxUtvdPVP0caOJIv3MF0AY) | Identify known vulnerabilities in the components in the SBOM |
| ![VEX ingestion icon](https://lh4.googleusercontent.com/SDnTDwd3tttj3XmlC40Q6CF5z4VGQFRiIWzUeFg_7ecRkw_g5HcmcrCujmQY0t6JGSVM6p3PMWW_4TlMmlSPThYbB7V5_rXTOqz5FjTDe4ABZ3QTkrudVoV06BbtQp8HWjyGmoDCjirVye9C3pF95b0) | Read in and apply vulnerability applicability data feeds (VEX and possibly others |

## Day 1: Generating SBOMs and Identifying Vulnerabilities

Using our [FACT platform](https://adolus.com/fact/overview/), we broke down two of the three targets in less than an hour. Here is a summary of the extraction results:

|   | Type | Files Detected | Unique Products | Vulnerabilities Detected | Malware Detected |
| --- | --- | --- | --- | --- | --- |
| ![Windows installer icon](https://blog.adolus.com/hs-fs/hubfs/image-png-2.png?width=46&height=40&name=image-png-2.png) | Windows installer for OSIsoft’s PI ProcessBook | 3376 | 30 | 0 (+ 1 False Positive) | 0 |
| ![Motorola 68000](https://blog.adolus.com/hs-fs/hubfs/image-png-1.png?width=59&height=27&name=image-png-1.png) | Motorola 68000 “bare-metal” binary | 1 | 1 | 0 | 0 |
| ![Linux penguin](https://lh5.googleusercontent.com/F4chAOK-hiKM2UgX_-T2kBHOuJ4cvJKOzBQgLWalInVpWDifz7dgU0fwz1IGPIIAbPdELV3n-RhGvgDsP3fTHQQQTCNdXrGT9vlnD1OmKOpebG-H7ANp1a1dibbv4av5OoBQmRzSGjgEpkNA6U090FE) | WRT-Linux firmware | 7467 | 18 | 140 (+ 3 False Positives) | 0 (+1 False Positive) |

## *Analysis Results by Artifact*

### Windows Installer

![Windows installer icon](https://blog.adolus.com/hs-fs/hubfs/image-png-2.png?width=72&height=63&name=image-png-2.png)This Windows-based artifact was the installer for OSIsoft’s PI ProcessBook 2015 R3 Patch 1. It contained 30 unique products from 3rd-party software suppliers like Microsoft, LEAD Technologies Inc, and Rogue Wave Software. FACT also reported that the file was signed with a certificate chain that did not match a qualified certificate chain for OSIsoft. This was not unexpected, as the original installer had clearly been modified for the challenge.

FACT’s AI vulnerability detection initially suggested some potential vulnerability matches, in particular for the WIX Toolset (CVE-2019-16511). However, analysis showed that although the WIX toolset used in the binary was a vulnerable version (3.9), the software did not include the Microsoft.Deployment.Compression.Cab.dll needed for this vulnerability to be exploited. Thus, this vulnerability was considered non-exploitable and not associated with the product. 

Similarly, the installer contained 12 Lead Tools DLLs. While some versions of Lead Tools do have [known vulnerabilities](https://www.cvedetails.com/vulnerability-list/vendor_id-7935/Leadtools.html), FACT quickly determined that the version used in this artifact wasn’t one of the vulnerable versions. 

In the end, we were confident that there were no known *exploitable* vulnerabilities in this artifact.

### Bare-Metal Binary

![Motorola 68000 chip](https://blog.adolus.com/hs-fs/hubfs/image-png-1.png?width=94&height=44&name=image-png-1.png)This “bare-metal” binary came from an ABB/Hitachi TPU 2000R Transformer Protection Unit that was developed in the early 1990s. The symbol tables had been stripped out and it wasn’t based on a known operating system, such as Embedded Linux, QNX, or Windows. As a result, we weren’t able to decompose this “bare-metal” binary into a detailed SBOM in the 10 hours provided, and frankly, no one else could either.

Binaries that aren’t based on a known operating system but are custom developed for an ancient chipset like Motorola 68000 are rare in 2023. They can be analyzed, but it requires extensive custom engineering that wasn’t feasible in the time provided. Because of their rarity, “bare-metal” binary analysis is an edge case that really isn’t suited for SBOM analysis. That said, if someone really wants us to look at microcontroller firmware, we’d be happy to (for a price 😉). 

### Embedded Linux

![Linux penguin](https://lh5.googleusercontent.com/F4chAOK-hiKM2UgX_-T2kBHOuJ4cvJKOzBQgLWalInVpWDifz7dgU0fwz1IGPIIAbPdELV3n-RhGvgDsP3fTHQQQTCNdXrGT9vlnD1OmKOpebG-H7ANp1a1dibbv4av5OoBQmRzSGjgEpkNA6U090FE)The embedded Linux artifact had an abundance of open-source software with numerous vulnerabilities. FACT was able to confidently identify 18 common applications, such as Linux kernel, OpenSSL, Postfix, BusyBox, Sqlite, Python, and Broadcom firmware — and many of these had documented vulnerability disclosures. FACT also alerted us to possible malware in a text file that contained “suspicious Linux command line commands,” but upon further analysis, this was found to be a false positive.

Note that when analyzing software there can be a lot of additional analysis beyond CVE vulnerability counts. For example, FACT found 178 high risk executables, 886 buffer overflows, and 66 command injection flaws. While interesting as an indicator of software quality, this information can create a lot of false positive issues for the end user if compensating measures such as stack protectors are present. Since testing SBOM and VEX vulnerability capabilities was the focus of the challenge, we omitted this additional depth from our submissions.

## 1-Click SBOMs

After completing this analysis, we generated — with just the click of a button — NTIA-compliant SPDX SBOMs for each of the three targets (albeit the bare-metal SBOM was pretty “bare”). Along with these SBOMs, we submitted three separate Vulnerability Disclosure Report (VDR) JSON documents. Why were the SBOMs separate from the VDRs? Because NTIA’s best practice guidelines recommend “that vulnerability data be tracked in separate data structures from the SBOM” because of the “dynamic” nature of vulnerability data compared to a static SBOM. 

We strongly agree with NTIA and CISA on this guideline because our vulnerability data is continuously updated for every binary in our database. Just wait a few months and all of these targets could have new vulnerabilities popping up. We don’t want stale vulnerability data being passed around in a static SBOM. Instead we allow our partners to monitor their SBOMs continuously through an API where they can access the most up-to-date vulnerability data on demand.

## The Threat of False Positives

You probably noticed we mentioned detecting and managing false positives several times in this blog. False positives are the curse of both the vulnerability and malware detection worlds. Like the boy crying “Wolf” in Aesop's famous fable, a technology that cries “Vulnerability” where none exists (False Positive), soon becomes ignored even when real (True Positive) vulnerabilities are present. This is especially true for SBOMs. Our own Eric Byres presented last year at S4x22 on the risk that SBOMs could generate a [tsunami of false-positive vulnerabilities](https://www.youtube.com/watch?v=TE-j_sZxzT0) that would overwhelm security teams. Just because a platform claims to find dozens or hundreds of vulnerabilities in an SBOM doesn’t mean it is a better solution. 

At aDolus, we’ve taken the position that fewer, more precise results are better than a lot of low confidence reports. A key feature of FACT is its ability to reduce false positives and provide less noisy, more actionable intelligence. We take great care to minimize false positives for our users by only presenting high confidence vulnerabilities to our partners based on calculated probabilities of association. This means our AI system vulnerability analysis coverage is significantly beyond “embedded Linux firmware” and designed to maintain precision across a broad spectrum. For any of those data science junkies out there, we’ve basically favored precision over recall. 

[Stay tuned for Part 2 where I’ll go into more details on SBOM and VEX ingestion](https://blog.adolus.com/s4x23-sbom-challenge-part-2) — the primary tasks during Day 2 of the challenge.

And if you would like to see how FACT generates SBOMs, we'd be happy to show you!

[![Book a Demo](https://no-cache.hubspot.com/cta/default/6687498/1ab3838b-33d4-4d36-a60b-3952add74c33.png)](https://cta-redirect.hubspot.com/cta/redirect/6687498/1ab3838b-33d4-4d36-a60b-3952add74c33)

![Derek Kruszewski](https://blog.adolus.com/hubfs/image-png.png)

###### Derek Kruszewski

 Derek Kruszewski is a data scientist and mechanical engineer with a passion for automating control systems using AI, particularly at oil and gas facilities. Derek leads the vulnerability management innovations at aDolus and (with his extensive yoga background) can fix your back if it hurts.

<https://adolus.com> <https://www.facebook.com/aDolus.Inc/> <https://www.linkedin.com/in/derek-kruszewski-p-eng-46bb4124/> <https://twitter.com/aDolus_Inc>

[Previous Post](https://blog.adolus.com/a-flurry-of-regulatory-action) [View All](https://blog.adolus.com) [Next Post](https://blog.adolus.com/three-quick-takeaways-from-bidens-national-cybersecurity-strategy)

##### Stay up to date

##### Browse Posts

 Popular

 Recent

 Archive

[![What is VEX and What Does it Have to Do with SBOMs?](https://blog.adolus.com/hubfs/VEX-SBOM-main-image.png)](https://blog.adolus.com/what-is-vex-and-what-does-it-have-to-do-with-sboms)

[What is VEX and What Does it Have to Do with SBOMs?](https://blog.adolus.com/what-is-vex-and-what-does-it-have-to-do-with-sboms)

[![Sniffing Out Fakes: From Saffron in Marrakech to Digital Certificates](https://blog.adolus.com/hubfs/Imported_Blog_Media/Eric-on-Camel-small-1024x769.png)](https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates)

[Sniffing Out Fakes: From Saffron in Marrakech to Digital Certificates](https://blog.adolus.com/2019/10/08/sniffing-out-fakes-from-saffron-in-marrakech-to-digital-certificates)

[![A Deeper Dive into VEX Documents](https://blog.adolus.com/hubfs/Anatomy%20of%20VEX%20Documents2.png)](https://blog.adolus.com/a-deeper-dive-into-vex-documents)

[A Deeper Dive into VEX Documents](https://blog.adolus.com/a-deeper-dive-into-vex-documents)

[![Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/hubfs/SolarWinds%20Attack%20Infographic.png)](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

[Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

[![Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/hubfs/Rod-Campbell-CEO.png)](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

[Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

[![Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/hubfs/XZ%20Backdoor%20thumbnail-aspect-corrected.png)](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

[Harnessing FACT for Swift Cyberthreat Response](https://blog.adolus.com/harnessing-fact-for-swift-threat-response)

[![Evolving Threats and Regulations in Software Supply Chain Security](https://blog.adolus.com/hubfs/laptop-gavel.png)](https://blog.adolus.com/evolving-threats-and-regulations-in-software-supply-chain-security)

[Evolving Threats and Regulations in Software Supply Chain Security](https://blog.adolus.com/evolving-threats-and-regulations-in-software-supply-chain-security)

[![EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/hubfs/flags%20and%20binary.png)](https://blog.adolus.com/eu-cra-clears-penultimate-step)

[EU Cyber Resilience Act (CRA) Clears Penultimate Step](https://blog.adolus.com/eu-cra-clears-penultimate-step)

[![The Wretched State of OT Firmware Patching](https://blog.adolus.com/hubfs/negelct.png)](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

[The Wretched State of OT Firmware Patching](https://blog.adolus.com/the-wretched-state-of-ot-firmware-patching)

[![Microsoft Digital Defense Report: Behind the Scenes Creating OT Vulnerabilities](https://blog.adolus.com/hubfs/MDDR2-backstage-pass-featureimage.png)](https://blog.adolus.com/microsoft-digital-defense-report-behind-the-scenes-creating-ot-vulnerabilities)

[Microsoft Digital Defense Report: Behind the Scenes Creating OT Vulnerabilities](https://blog.adolus.com/microsoft-digital-defense-report-behind-the-scenes-creating-ot-vulnerabilities)

- [May 2024](https://blog.adolus.com/archive/2024/05)
- [February 2024](https://blog.adolus.com/archive/2024/02)
- [December 2023](https://blog.adolus.com/archive/2023/12)
- [October 2023](https://blog.adolus.com/archive/2023/10)
- [April 2023](https://blog.adolus.com/archive/2023/04)
- [March 2023](https://blog.adolus.com/archive/2023/03)
- [February 2023](https://blog.adolus.com/archive/2023/02)
- [October 2022](https://blog.adolus.com/archive/2022/10)
- [April 2022](https://blog.adolus.com/archive/2022/04)
- [February 2022](https://blog.adolus.com/archive/2022/02)
- [December 2021](https://blog.adolus.com/archive/2021/12)
- [November 2021](https://blog.adolus.com/archive/2021/11)
- [August 2021](https://blog.adolus.com/archive/2021/08)
- [July 2021](https://blog.adolus.com/archive/2021/07)
- [June 2021](https://blog.adolus.com/archive/2021/06)
- [May 2021](https://blog.adolus.com/archive/2021/05)
- [February 2021](https://blog.adolus.com/archive/2021/02)
- [January 2021](https://blog.adolus.com/archive/2021/01)
- [December 2020](https://blog.adolus.com/archive/2020/12)
- [September 2020](https://blog.adolus.com/archive/2020/09)
- [August 2020](https://blog.adolus.com/archive/2020/08)
- [July 2020](https://blog.adolus.com/archive/2020/07)
- [May 2020](https://blog.adolus.com/archive/2020/05)
- [April 2020](https://blog.adolus.com/archive/2020/04)
- [January 2020](https://blog.adolus.com/archive/2020/01)
- [October 2019](https://blog.adolus.com/archive/2019/10)
- [September 2019](https://blog.adolus.com/archive/2019/09)
- [November 2018](https://blog.adolus.com/archive/2018/11)
- [September 2018](https://blog.adolus.com/archive/2018/09)
- [May 2018](https://blog.adolus.com/archive/2018/05)

##### Browse by topics

- [Supply Chain Management (16)](https://blog.adolus.com/tag/supply-chain)
- [SBOM (15)](https://blog.adolus.com/tag/sbom)
- [Vulnerability Tracking (15)](https://blog.adolus.com/tag/vulnerability-tracking)
- [#supplychainsecurity (10)](https://blog.adolus.com/tag/supplychainsecurity)
- [Regulatory Requirements (10)](https://blog.adolus.com/tag/regulatory-requirements)
- [VEX (8)](https://blog.adolus.com/tag/vex)
- [EO14028 (6)](https://blog.adolus.com/tag/eo14028)
- [ICS/IoT Upgrade Management (6)](https://blog.adolus.com/tag/upgrades)
- [malware (6)](https://blog.adolus.com/tag/malware)
- [ICS (5)](https://blog.adolus.com/tag/ics)
- [vulnerability disclosure (5)](https://blog.adolus.com/tag/vulnerability-disclosure)
- [3rd Party Components (4)](https://blog.adolus.com/tag/3rd-party-components)
- [Partnership (4)](https://blog.adolus.com/tag/partnership)
- [Press-release (4)](https://blog.adolus.com/tag/press-release)
- [#S4 (3)](https://blog.adolus.com/tag/s4)
- [Software Validation (3)](https://blog.adolus.com/tag/sw-validation)
- [hacking (3)](https://blog.adolus.com/tag/hacking)
- [industrial control system (3)](https://blog.adolus.com/tag/industrial-control-system)
- [Code Signing (2)](https://blog.adolus.com/tag/code-signing)
- [Legislation (2)](https://blog.adolus.com/tag/legislation)
- [chain of trust (2)](https://blog.adolus.com/tag/chain-of-trust)
- [#nvbc2020 (1)](https://blog.adolus.com/tag/nvbc2020)
- [DoD CMMC (1)](https://blog.adolus.com/tag/dod-cmmc)
- [Dragonfly (1)](https://blog.adolus.com/tag/dragonfly)
- [Havex (1)](https://blog.adolus.com/tag/havex)
- [Log4Shell (1)](https://blog.adolus.com/tag/log4shell)
- [Log4j (1)](https://blog.adolus.com/tag/log4j)
- [Trojan (1)](https://blog.adolus.com/tag/trojan)
- [USB (1)](https://blog.adolus.com/tag/usb)
- [Uncategorized (1)](https://blog.adolus.com/tag/uncategorized)
- [energy (1)](https://blog.adolus.com/tag/energy)
- [medical (1)](https://blog.adolus.com/tag/medical)
- [password strength (1)](https://blog.adolus.com/tag/password-strength)
- [pharmaceutical (1)](https://blog.adolus.com/tag/pharmaceutical)

Sidebar

### Related Posts

[![S4x23 SBOM Challenge — Part 3: VEX Document Ingestion](https://blog.adolus.com/hubfs/INL%20Presentation.png)](https://blog.adolus.com/s4x23-sbom-challenge-part-3)

 7 min read

##### [S4x23 SBOM Challenge — Part 3: VEX Document Ingestion](https://blog.adolus.com/s4x23-sbom-challenge-part-3)

 By [Derek Kruszewski](https://blog.adolus.com/author/derek-kruszewski) on March 16, 2023

Three weeks ago I reported on the first part of the S4x23 SBOM Challenge run by Idaho National Laboratory (INL), which...

[Continue Reading](https://blog.adolus.com/s4x23-sbom-challenge-part-3)

[![S4x23 SBOM Challenge — Part 2: SBOM Ingestion](https://blog.adolus.com/hubfs/SBOM%20Pavilion%20Day%202.png)](https://blog.adolus.com/s4x23-sbom-challenge-part-2)

 7 min read

##### [S4x23 SBOM Challenge — Part 2: SBOM Ingestion](https://blog.adolus.com/s4x23-sbom-challenge-part-2)

 By [Derek Kruszewski](https://blog.adolus.com/author/derek-kruszewski) on March 8, 2023

Two weeks ago I reported on the first part of the SBOM Challenge at the S4x23 cybersecurity conference in Miami,...

[Continue Reading](https://blog.adolus.com/s4x23-sbom-challenge-part-2)

[![Verve Industrial and aDolus Partner to Reduce ICS Software Supply Chain Risk](https://blog.adolus.com/hubfs/Verve-aDolus.png)](https://blog.adolus.com/verve-industrial-and-adolus-partner-to-improve-ics-supply-chain-security)

 3 min read

##### [Verve Industrial and aDolus Partner to Reduce ICS Software Supply Chain Risk](https://blog.adolus.com/verve-industrial-and-adolus-partner-to-improve-ics-supply-chain-security)

 By [Norma Dowler](https://blog.adolus.com/author/norma-dowler) on February 4, 2021

Verve embeds aDolus’ ability to generate SBOMs and validate components aDolus Technology Inc., a global authority on...

[Continue Reading](https://blog.adolus.com/verve-industrial-and-adolus-partner-to-improve-ics-supply-chain-security)

[![Industrial Defender and aDolus Partner to Improve ICS Supply Chain Security](https://blog.adolus.com/hubfs/IndustrialDefender-aDolus-partnership.png)](https://blog.adolus.com/industrial-defender-and-adolus-partner-to-improve-ics-supply-chain-security)

 2 min read

##### [Industrial Defender and aDolus Partner to Improve ICS Supply Chain Security](https://blog.adolus.com/industrial-defender-and-adolus-partner-to-improve-ics-supply-chain-security)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on January 19, 2021

Industrial Defender’s integration with the aDolus FACT™ platform ensures updates are valid, tamper-free, and safe to...

[Continue Reading](https://blog.adolus.com/industrial-defender-and-adolus-partner-to-improve-ics-supply-chain-security)

[![ReFirm Labs and aDolus Partner to Improve IoT Supply Chain Security](https://blog.adolus.com/hubfs/Refirm-aDolus.png)](https://blog.adolus.com/refirm-labs-and-adolus-partner-to-improve-security-and-integrity-of-firmware-for-iot-in-critical-industries)

 2 min read

##### [ReFirm Labs and aDolus Partner to Improve IoT Supply Chain Security](https://blog.adolus.com/refirm-labs-and-adolus-partner-to-improve-security-and-integrity-of-firmware-for-iot-in-critical-industries)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on September 3, 2020

aDolus Technology Inc., a global authority on software intelligence for critical infrastructure, and ReFirm Labs, a...

[Continue Reading](https://blog.adolus.com/refirm-labs-and-adolus-partner-to-improve-security-and-integrity-of-firmware-for-iot-in-critical-industries)

[![Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/hubfs/SolarWinds%20Attack%20Infographic.png)](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

 4 min read

##### [Three Things the SolarWinds Supply Chain Attack Can Teach Us](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on December 18, 2020

Just in case you missed it, a software supply chain attack on the US government and industries is consuming the waking...

[Continue Reading](https://blog.adolus.com/three-things-the-solarwinds-supply-chain-attack-can-teach-us)

[![Wrapping Up 2020 with Dale Peterson](https://blog.adolus.com/hubfs/Unsolicited-Response-Eric-and-Dale.png)](https://blog.adolus.com/wrapping-up-2020-with-dale-peterson)

 2 min read

##### [Wrapping Up 2020 with Dale Peterson](https://blog.adolus.com/wrapping-up-2020-with-dale-peterson)

 By [Eric Byres](https://blog.adolus.com/author/eric-byres) on January 7, 2021

Wrapping up my year on December 31, I was delighted to join ICS cybersecurity luminary Dale Peterson for his December:...

[Continue Reading](https://blog.adolus.com/wrapping-up-2020-with-dale-peterson)

[![Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/hubfs/Rod-Campbell-CEO.png)](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

 2 min read

##### [Rod Campbell Joins aDolus as CEO](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

 By [Norma Dowler](https://blog.adolus.com/author/norma-dowler) on June 15, 2021

Seasoned financial and advisory executive to drive growth VICTORIA, BC, CANADA, June 15, 2021 /EINPresswire.com/ -- ...

[Continue Reading](https://blog.adolus.com/rod-campbell-joins-adolus-as-ceo)

[![What is VEX and What Does it Have to Do with SBOMs?](https://blog.adolus.com/hubfs/VEX-SBOM-main-image.png)](https://blog.adolus.com/what-is-vex-and-what-does-it-have-to-do-with-sboms)

 3 min read

##### [What is VEX and What Does it Have to Do with SBOMs?](https://blog.adolus.com/what-is-vex-and-what-does-it-have-to-do-with-sboms)

 By [Derek Kruszewski](https://blog.adolus.com/author/derek-kruszewski) on August 12, 2021

Recently, we have been fielding many inquiries here at aDolus regarding “VEX.” If you are not familiar with this...

[Continue Reading](https://blog.adolus.com/what-is-vex-and-what-does-it-have-to-do-with-sboms)

[![aDolus Wins Top Tech Innovation Contest, New Ventures BC 2020](https://blog.adolus.com/hubfs/newventuresbc_social-media-banner-1.png)](https://blog.adolus.com/adolus-wins-top-tech-innovation-contest-new-ventures-bc-2020)

 2 min read

##### [aDolus Wins Top Tech Innovation Contest, New Ventures BC 2020](https://blog.adolus.com/adolus-wins-top-tech-innovation-contest-new-ventures-bc-2020)

 By [Norma Dowler](https://blog.adolus.com/author/norma-dowler) on December 1, 2020

aDolus Technology Inc. bested 240 of BC’s most innovative tech startups, winning the New Ventures contest in Canada’s...

[Continue Reading](https://blog.adolus.com/adolus-wins-top-tech-innovation-contest-new-ventures-bc-2020)

### Post a comment

### Stay up to date

 Subscribe to our blog

### Stay up to date

![aDolus Logo in blue](https://adolus.com/_next/image/?url=%2Fimages%2Fadolus-blue-60px.png&w=128&q=100)

 200 - 535 Yates Street  
 Victoria, BC  
 Canada  
 V8W 2Z6

[+1-866-423-6587](tel:18664236587) [info@adolus.com](mailto:info@adolus.com)

<https://www.linkedin.com/company/adolus/> <https://twitter.com/adolus_inc> <https://facebook.com/aDolus.Inc> <https://infosec.exchange/@aDolus>

#### Product

- FACT Platform
- [Overview](https://adolus.com/fact/overview/)
- [Benefits](https://adolus.com/fact/benefits/)
- [Technical Details](https://adolus.com/fact/technical/)
- FACT Features
- [Software Validation & Scoring](https://adolus.com/product/software-validation-scoring/)
- [SBOM Creation](https://adolus.com/product/sbom/)
- [VEX Documents](https://adolus.com/product/vex-documents/)
- [Malware Detection](https://adolus.com/product/malware-detection/)
- [Certificate Validation](https://adolus.com/product/certificate-validation/)
- [Software Supplier Discovery](https://adolus.com/product/software-supplier-discovery/)

#### Solutions

- By use case
- [Vulnerability Management](https://adolus.com/solutions/vulnerability-management/)
- [Compliance](https://adolus.com/solutions/compliance/)
- [Risk Management](https://adolus.com/solutions/risk-management/)
- [Operational Insights](https://adolus.com/solutions/operational-insights/)
- By job function
- [Product Managers](https://adolus.com/solutions/product-managers/)
- [Security Managers](https://adolus.com/solutions/security-managers/)
- [Engineering Managers](https://adolus.com/solutions/engineering-managers/)
- [Procurement Managers](https://adolus.com/solutions/procurement-managers/)
- By role in the supply chain
- [Vendors & OEMs](https://adolus.com/solutions/vendors-oems/)
- [Asset Owners](https://adolus.com/solutions/asset-owners/)
- [Integrators & Consultants](https://adolus.com/solutions/integrators-consultants/)
- [Security Providers & Partners](https://adolus.com/solutions/security-providers-partners/)

#### Resources

- [Blog](https://blog.adolus.com/)
- [Videos & Podcasts](https://adolus.com/resources/video-podcasts/)
- [Infographics](https://adolus.com/resources/infographics/)
- [FAQ](https://adolus.com/resources/faq/)
- [Document Library](https://adolus.com/resources/document-library/)
- Educational Tools
- [Executive Order #14028 Timeline](https://info.adolus.com/eo14028-timeline)
- [Log4j Resources](https://adolus.com/vulnerabilities/log4j/)

#### Company

- [About Us](https://adolus.com/company/about/)
- [Our Partners](https://adolus.com/company/partners/)
- [News](https://adolus.com/company/news/)
- [Careers](https://adolus.com/company/careers/)
- [Contact](https://adolus.com/company/contact/)

Copyright © 2024 aDolus Technology Inc

[Privacy Policy](https://adolus.com/legal/privacy-policy/) [Terms of Service](https://adolus.com/legal/terms-of-service/)