Why is there no sbom for windows?
-
Why is there no sbom for windows?
Why is there no page on a microsoft domain where i can enter the name or hash of a windows executable or dll and get a detailed description of what it is, what it does, and maybe the revision history?I am tired of sifting through sketchy seo slop websites and reddit (i am repeating myself) for this information.
And yes, please flame me and point me at the page that everyone knows about but i somehow missed. Thank you.
-
Why is there no sbom for windows?
Why is there no page on a microsoft domain where i can enter the name or hash of a windows executable or dll and get a detailed description of what it is, what it does, and maybe the revision history?I am tired of sifting through sketchy seo slop websites and reddit (i am repeating myself) for this information.
And yes, please flame me and point me at the page that everyone knows about but i somehow missed. Thank you.
@h2onolan There is. NIST provide their own, or you can request the CycloneDX ECMA-424 SBoM directly from them and they will provide it for every OS version SKU and KB hotfix.
I love to dunk on MS, but this is one thing they’re good at.
-