Skip to main content
Supply Chain and AI Threat Intelligence Platform app icon

Supply Chain and AI Threat Intelligence Platform

A Splunk app that detects AI-threat patterns (MITRE ATLAS) and runs software composition analysis (SCA) on your SBOMs to identify known-vulnerable components (NVD, OSV) — surfacing the applications where both appear at once. Compliance evidence across nine frameworks and FedRAMP/RMF audit exports, with no separate platform to stand up.Built by GIC Engineering Consultants, Inc., an official Splunk Partner
splunk product badge

Default Version 1.2.17

September 22, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

SCIP is a Splunk app that detects adversarial AI/ML threats (MITRE ATLAS) and runs software composition analysis (SCA) on your SBOMs to identify known-vulnerable components (NVD, OSV) — then, through Compound Risk, surfaces the applications where an AI-threat detection and a known vulnerability appear at once, the exposure neither signal shows alone. It prioritizes with CISA KEV and EPSS and assesses compliance posture across nine frameworks — detection logic written as transparent SPL you can open and read, and no separate platform to stand up. AI THREAT DETECTION - MITRE ATLAS Detection — 81 AI/agentic threat detection rules (72 mapped to 57 MITRE ATLAS techniques) - Compound Risk — correlates MITRE ATLAS AI-threat detections with KEV-listed or critical-severity vulnerabilities on the same application - Silent-Source Detection — alerts when an enrolled AI/LLM telemetry source goes quiet, so a dead pipe is never mistaken for a clean one - AI/ML Bill of Materials — catalogs AI/ML model components from your SBOMs with insecure-serialization-format flagging and risk classification SOFTWARE SUPPLY CHAIN - SBOM ingestion — file-drop or HEC, supporting CycloneDX (JSON/XML) and SPDX (JSON) - Vulnerability correlation — bundled OSV dataset (250,000+ records across 11 ecosystems) with PURL-based correlation, refreshed daily from the live OSV feed across 8 configurable ecosystems; NVD CPE-based correlation; CISA KEV matching; EPSS scoring - Supply Chain Risk Score — 0–100 global and per-application scoring weighted by severity, KEV status, and EPSS - Vendor Risk — per-vendor risk aggregation and letter-grading - SBOM Drift Detection — baseline-vs-current component change tracking - Long-Unpatched Critical Exposure — flags critical/high-severity vulnerabilities unpatched 180+ days - License Compliance — GPL/AGPL/copyleft detection and license-risk classification COMPLIANCE, FEDERAL & AIR-GAPPED DEPLOYMENT - Air-gapped operation — AI-threat detection runs on your own Splunk data, SBOM correlation on the bundled OSV dataset, and intelligence feeds refresh by file transfer rather than live calls; deployed disconnected, SCIP makes no outbound connections - Compliance Gap Assessment — nine frameworks: PCI DSS 4.0.1, NIST CSF 2.0, SOC 2 Type II, HIPAA Security Rule, EU Cyber Resilience Act, FedRAMP / RMF / CISA, DORA, FDA 524B Premarket Cybersecurity, SEBI CSCRF - POA&M & FedRAMP Workflow — POA&M dashboard, monthly ConMon package builder, BOD 26-04 risk-tier classification, deviation request workflow. Dashboards always available; automated POA&M generation is opt-in from Setup - Coverage-Evidence Manifest — AU-12-aligned attestation of unbroken AI-monitoring coverage - Audit-ready exports — FedRAMP POA&M Workbook, SSP Appendix M Integrated Inventory, Deviation Request Form