Könyv Supply Chain Reconnaissance Drevan Orlix

Supply Chain Reconnaissance

OSINT Methods for Vendor Risk, Fraud Detection, and Third-Party Assessment

Szerző: Drevan Orlix
Nyelv: Angol
Kötés: Puha kötésű
Elérhetőség: Várható készletfeltöltés
Küldés 01. 09. 2026
15 916 Ft
Your vendors filled out the questionnaires. Your supply chain is still your biggest security gap.Mos...

Információk a könyvről

Szerző
Nyelv
Angol
Kötés
Könyv - Puha kötésű
Kiadva
2026
oldal
248
EAN
9798170350230
Enbook ID
53679461
Súly
585
Méretek
216 x 280 x 13

Teljes leírás

Your vendors filled out the questionnaires. Your supply chain is still your biggest security gap.

Most third-party breaches succeed because organizations ask vendors about their security instead of verifying it independently. Supply Chain Reconnaissance gives security analysts, vendor risk managers, and GRC professionals a structured, tool-backed OSINT methodology to profile any vendor using public data - without relying on what the vendor tells you.

Built around the five-layer Vendor Intelligence Package (VIP) framework, this book teaches you to verify vendor corporate identity, map infrastructure exposure, trace beneficial ownership through shell company structures, detect fraud signals before payments are made, and monitor continuously across your entire vendor portfolio.

By the end of this book, you will be able to:

- Map a vendor's complete corporate ownership structure using OpenCorporates and GLEIF API data
- Identify shell companies, UBO anomalies, and jurisdiction red flags before vendor onboarding
- Profile a vendor's external attack surface using Shodan and Censys without alerting the target
- Detect early fraud indicators via domain registration anomalies, certificate mismatches, and job-post signals
- Trace shipping and trade data using ImportYeti to identify hidden suppliers and flagged trading partners
- Execute an adverse media and ESG risk scan covering multilingual sources and regulatory registers
- Score and rank vendors using a five-dimension risk matrix calibrated to access tier and vendor type
- Construct an ongoing vendor monitoring workflow using SpiderFoot automation and API integrations
- Conduct executive and key-personnel background checks using court filings and sanction databases
- Build a complete Vendor Intelligence Package with auditable evidence chains suitable for regulatory audit

Every chapter includes working Python code, real documented case studies (SolarWinds, Target, Home Depot, CFM/Safran, Intel Israel), and decision filters that tell you exactly what to do when a finding appears. The VIP framework scales from a solo analyst managing 20 vendors to an enterprise program monitoring hundreds, with automation tools that convert what was once three days of manual work into a 20-minute scheduled scan.

For corporate security analysts, vendor risk managers, procurement officers, fraud investigators, and GRC professionals who cannot afford to trust without verifying. If you have a vendor list and a folder of questionnaires, this book shows you what to do next.

Stop asking vendors if they are secure. Start verifying.