1 minute(s) to read
THCON 2025 — Software Bill of Materials
THCON 2025 — Vulnerability tracking of offline systems using SBOM
A Look Back at THCON 2025: Tracking Offline Vulnerabilities Using SBOMs
In April 2025, I had the pleasure of taking the stage at THCON alongside Benoît Guillon (Viveris) to present a talk on securing the software supply chain in constrained environments.
Our presentation, titled “Software Bill of Materials: Vulnerability tracking of offline systems using SBOM,” highlighted a major challenge for critical industries: how to maintain an accurate map of software vulnerabilities when systems are completely isolated from the Internet (offline)?
💡 Context and Challenge
In the space sector and critical infrastructure industries, many projects run on disconnected systems for obvious security reasons. Tracking vulnerabilities (CVEs) for these products quickly becomes a major headache.
Before industrializing our approach, we relied on an internal Proof of Concept (PoC) solution. While useful, it had significant limitations:
- It did not integrate all sources of software components.
- It required numerous tedious manual tasks.
- It relied on online connectivity to function.
🛠️ Our Solution: Automation via SBOM
The goal of our presentation was to demonstrate how adopting SBOMs (Software Bill of Materials), combined with a suitable vulnerability management tool, can completely flip this paradigm.
We shared insights from implementing a workflow that enables us to:
- Generate a comprehensive SBOM (the “list of ingredients” for our software), including all dependencies and component sources.
- Automate end-to-end analysis, eliminating error-prone manual interventions.
- Operate entirely offline, ensuring the sovereignty and security of our project data.
The result? A dynamic, visual, and instant map of a project’s security status at any given moment, without ever opening an external data connection.
📺 Resources & Links
- Event: Toulouse Hacking Convention (THCON 2025)
- Co-presenter: Benoît Guillon (Viveris)