SupplyScan
Offline Mode
HomeScanUSP ShowdownThreat SandboxHistorySettings
v0.1.0-alpha
Multi-Layer Threat Evaluation

Threat Sandbox

Test dependencies using focused scans. Compare database vulnerability lookups against behavioral zero-day protection layers.

Configure Test Scan
Toggle the scanning mode to isolate CVE database audits from behavioral checks.
Active Protection Layers
Visualizing how filters map to the selected scanner mode.
Active in Scan:
Typosquatting AuditsInspects name distance and mimicry patterns against top dependencies.
Maintainer Risk EvaluationAssesses account hijacking, new package owners, and release anomaly signals.
AST Semantic AnalysisChecks code syntax trees for base64 shell injections and file modifications.
Code Obfuscation CheckMeasures Shannon entropy of strings to find hidden payload blocks.
Outbound Call HeuristicsDetects socket calls, raw IPs, and dns lookup vectors in setup files.
YARA Malware RulesRuns signature matching targeting trojans, ransomware, and miners.
Custom Semgrep RulesApplies specialized security rules for execution patterns (eval, popen).
Bypassed / Not Checked:
✕
CVE Database LookupQueries global database sources for known CVE publications.
✕
Threat Intelligence FeedAudits against local curated indicators and compromised versions.