Official Website link
Date: August 7, 2026 | 1 Day Training (Friday)
Time: 8:30 AM – 5:30 PM
Location: Las Vegas Convention Center W224
Level: Intermediate
Format: 1 Day Hands-on Training
Instructors: Anant Shrivastava (Founder, Cyfinoid Research), Sunil Yadav (Founder / Head of Security, x-biz Techventures)
Course Overview
This course takes practitioners inside real supply chain attack chains, from compromised packages to tampered upstream artifacts to abused third-party integrations, and teaches how to technically verify what upstream dependencies actually ship. Students work hands-on with provenance verification, runtime detection, inherited risk analysis, and practical defense implementation — skills that go beyond policy documents and questionnaires.
Supply chain attacks succeed because they exploit trust: in packages, in integrations, and in the assumption that upstream components are safe. Using real case studies including SolarWinds, xz Utils, Log4Shell, and 3CX, the course reconstructs how small trust failures chain into full organizational compromise, and where technical verification would have caught them.
This is not a risk management or governance course. It is built for security practitioners who need to technically verify supply chain components and build detection capabilities in their own environments.
Topics Covered
- Anatomy of supply chain attack chains (SolarWinds, xz Utils, Log4Shell, 3CX)
- Package ecosystem attacks and detection engineering
- Inherited risk analysis — what upstream software actually ships
- Cryptographic configuration weaknesses and hardcoded secrets
- AI component metadata, model provenance, and dataset lineage
- Provenance verification and admission controls
- Runtime behavioral monitoring for supply chain anomalies
- Building a continuous verification defense playbook
Training Curriculum
Module 1 — Anatomy of Supply Chain Attack Chains
Technical reconstruction of major incidents and kill-chain mapping. Students reconstruct attack chains using build logs and artifact signatures, and build a supply chain attack taxonomy referenced throughout the course.
Module 2 — Package Ecosystem Attacks and Detection Engineering
Typosquatting, dependency confusion, namespace hijacking, maintainer account takeover, and hidden capability abuse. Students write detection rules and test them against a curated set of real malicious packages.
Module 3 — Inherited Risk Analysis
Hands-on verification of upstream dependencies and third-party software: undisclosed transitive dependencies, cryptographic weaknesses, AI component metadata, tampering detection, and vulnerability cross-referencing.
Module 4 — Building Supply Chain Defenses That Work
Provenance verification workflows, admission controls gated on attestations, package governance policies, and runtime detection rules assembled into a technical supply chain defense playbook.