logo

Netskope BEAM: Open Source Detector for Supply Chain Compromise

ID: 2d922359-405e-5d96-83a2-d4e3bbdc49b1

STIX ID: report--2d922359-405e-5d96-83a2-d4e3bbdc49b1

Feed Name: Netskope Threat Labs

Date Published: 2025-08-07

Date Updated: 2026-04-28

Author: Colin Estep

...
...

Netskope Threat Labs introduces BEAM, an open-source tool to detect software supply chain compromises by analyzing existing HTTP/HTTPS traffic (e.g., PCAP/HAR) without endpoint agents. BEAM identifies applications via user-agent parsing and LLM assistance, enriches traffic with app context, and scores behavior using pre-trained models (XGBoost) while enabling bespoke models via unsupervised methods (TensorFlow, Isolation Forest, One-Class SVM). A demo shows BEAM flagging anomalous Box client behavior (communication to an unusual domain) with high confidence, and the project is available on GitHub for immediate use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.