Official Website link
Date: Thursday, August 6 | 2:50pm-3:50pm
Event: BlackHat USA 2026 Arsenal
Location: Arsenal Station 6, Business Hall
Track: Code Assessment
Presenter: Anant Shrivastava
SBoM Play is a SBoM Exploration and Intelligence extraction platform. SBoM Play exists because “we have SBOMs” does not automatically mean “we can use SBOMs.” Most teams either end up with heavy tooling, custom scripts, or workflows that require uploading dependency data somewhere just to explore it.
SBoM Play is browser-first and privacy-aware. It runs entirely in the browser, so there is no server-side setup and no backend to maintain. It can import SBOMs or extract SBOMs from GitHub repositories, then enrich what you see using sources like osv.dev, deps.dev, and ecosyste.ms. The main focus is a unified view across repositories and organizations so you can stop treating SBOMs as one-project-at-a-time artifacts.
This session shows SBOM usage beyond vulnerability tracking — surfacing tech debt patterns, redundant packages, version drift and sprawl, license posture, SBOM quality gaps, and maintainer risk. SBoM Play was previously presented at Black Hat Europe 2025 and Black Hat Asia 2026; newer releases add more coverage and depth for this USA demo.
Resources
- Live URL: SBOM Play
- Source Code: GitHub Repository