Skip to main content

Supply Chain Intel

This guide is focused on orienting platform users on how to use Supply Chain Intel.


Workspace

Adding a Vendor

Just like other platform workspaces, a Vendor is an asset that must be added to monitoring before data collection begins.

To add a vendor, go to Settings → Monitoring settings → Asset management, open the Digital Risk tab, and click Add asset. From the asset type list, choose Vendor ("Gain visibility into your vendor ecosystem").

Following this flow, you will reach the screen below:

one.axur.com_monitoringConfig_assets-management_add-asset_category=CUSTOMER_VENDOR.png

Type the name of the vendor you want to monitor and select one from the dropdown list that appears.

image.png

You can select multiple vendors at once for bulk addition.

image.png

If the desired vendor does not appear in the dropdown, it may not yet be in Axur's vendor catalog. In this case, click "Suggest a Vendor" and provide the vendor's name and domain. The SLA for new vendor inclusion is 24 hours.

image.png

Under Monitoring setup, keep the Supply Chain Intel → Vendor toggle enabled to monitor credential leaks, exposed infrastructure, and threat intelligence bulletins. Optionally, set the Critical bulletin categories that should be treated as critical for these vendors (e.g., Malware, Data Breach, Vulnerability, Ransomware, Zero Day, Supply Chain Attacks, Remote Code Execution, Denial of Service). This selection drives the Critical flag and the "Only critical" filter in the vendor's Threat Landscape. Finally, click "Save Asset" to add the vendors to your monitored list.

22one.axur.com_monitoringConfig_assets-management_add-asset_category=CUSTOMER_VENDOR (1).png

Vendor List

The vendor list consolidates all vendors added to monitoring. It displays global monitoring indicators and summarized data per vendor, with columns for Corporate Creds, Customer Creds, Dark Web, Bulletins (with a badge for critical bulletins), Vulnerabilities, Expired Certs, and Tags, plus filtering, sorting, and tag assignment capabilities.

In the Bulletins column, a badge next to the total shows the number of critical bulletins for each vendor, bulletins that match the Critical bulletin categories defined for it, so you can spot at-risk vendors at a glance directly from the list.

333one.axur.com_supply-chain-intel.png

Summary Indicators

At the top of the list, you can view high-level indicators that aggregate data across all monitored vendors:

  • Total monitored vendors;

  • Total exposed credentials (Employee and Customer);

  • Total security bulletins published for your vendors;

  • Total vulnerabilities found.

These values are affected by the active vendor filter.


Filter

To quickly find a specific vendor, use the search filter at the top-left of the screen. Type the vendor name and the list filters automatically.

Vendor filter

Vendor filter

The vendor filter also affects the values shown in the summary indicators above the list.

Sorting

The vendor list can be sorted in ascending or descending order by any column. Click a column header to sort; click it again to reverse the order. This is useful for identifying the most critical vendors or those with the highest volume of findings in your portfolio.


Tag Management

Tags allow you to categorize and organize your monitored vendors. They are client-specific; one client's tags are not visible to other clients.

  • Creating tags: Users with Manager or Expert profiles can create custom tags directly from the vendor list by interacting with the tag cell on any vendor row.

  • Assigning tags: Click on a vendor's tag cell to add or remove tags. Multiple tags can be assigned to the same vendor.

  • Filtering by tag: Use the tag filter at the top of the vendor list to show only vendors associated with a specific tag. This helps group vendors by risk tier, business unit, contract status, or any custom category you define.

image.png

Vendor Details

Clicking on a vendor in the list opens the Vendor Details page, which presents the full intelligence report organized in tabs: Overview, Threat Landscape, Attack Surface, Employee Credentials, Customer Credentials, and Dark Web. Use Export (top-right) to download the full report as a PDF. Across all sections, trend indicators show each key metric's variation, week-over-week (WoW) for Dark Web mentions, expired certificates and vulnerable assets, and month-over-month (MoM) for employee and customer credentials.

About the Vendor

The top of the Vendor Details page displays general information about the vendor, including a brief description, website, market segment, and trust center contact (when available). This information is pre-loaded by Axur and maintained in the vendor catalog.

Overview

The Overview tab summarizes the vendor's current posture at a glance:

  • Metric cards with trend indicators: data breach bulletins, ransomware bulletins, expired certificates, vulnerable asset variations, Dark Web mentions, employee credentials, and customer credentials.

  • AI Summary (Vendor Overview): an AI-generated narrative of the vendor's security posture — Threat Posture Characterization, Current Exposure, and Conclusion & Recommendations — updated daily.

How to use it: Use the Overview as your first-stop triage, your command center for the vendor. Before onboarding a new vendor, start here for an instant read before going deep. When an alert fires, open this page first to understand the full picture before jumping to a specific tab. It answers the question, "Is this a vendor I should be worried about right now?"


Vendor Threat Landscape

This section provides a threat intelligence overview of the vendor based on Axur's CTI monitoring sources.

  • AI Summary: An AI-generated narrative summarizing the vendor's current security posture based on the most recent intelligence data.

  • Security Bulletins: Ransomware, data breach, and vulnerability events involving the vendor or its products and services, each showing IoC, CVE, and TTP counts. Bulletins matching the Critical bulletin categories you selected for the vendor are flagged Critical and counted in a badge on the Threat Landscape tab title; use the "Only critical" toggle to show only those. Updated up to 4 times per day.

  • Navigate to CTI: A direct link to Axur's full CTI area for deeper investigation of specific bulletins or events.

How to use it: When a ransomware group announces they've hit a supplier, it often shows up here before mainstream news. If a critical vendor appears with a data breach bulletin, assess your exposure: check what data or access that vendor holds, review your connections and integrations, and open an internal ticket for remediation or escalation. The signal is already vendor-contextualized; no need to filter irrelevant global noise.


External Attack Surface (EASM)

This section maps the vendor's publicly exposed infrastructure and identifies exploitable weaknesses.

  • Discovered Hosts & Subdomains: Public hosts and subdomains associated with the vendor's main domain.

  • Vulnerabilities: The most critical findings across discovered hosts, listing Host, IP Address, Open Port, CVE, and Severity.

  • Certificates Expiration: TLS/SSL certificates associated with the vendor's hosts, listing Host, IP, Expiration Date, and Status. Expired or soon-to-expire certificates may indicate neglected infrastructure.

EASM data is refreshed weekly.

How to use it: Risk-based prioritization. Everything here is derived from passive fingerprinting — we never touch the vendor's systems; this is exactly what an attacker can see from the outside. If a vendor runs a critical integration with your environment and shows a high-severity CVE in an exposed service, treat it as active risk, not a compliance flag: bring the CVE and affected service to the vendor with a remediation timeline. It also informs your compensating controls, tightening internal network segmentation for that connection while you wait for them to patch.


Employee Credentials Leaked

This section shows corporate credentials belonging to vendor employees that have been found exposed in malware logs (infostealers) or third-party data breaches.

  • Credential samples: Partial display of the exposed email/username, a redacted password, and the date of exposure. Full credentials are never displayed in plain text.

  • Top Sources: A Chart showing the distribution of credential leaks by source (e.g., Forums and Dark Markets, Telegram, and Mega.io).

Employee credential leaks indicate a risk of unauthorized access to the vendor's own systems. This data is refreshed weekly.

How to use it: Treat a spike in employee credential exposure as a third-party compromise indicator. A significant volume of recent exposures, especially from infostealers, which means active malware rather than old breaches, warrants increased monitoring of traffic from that vendor's systems and a review of the access tokens or API keys shared between you. In incident response, one beta customer used this tab to check whether credentials from an Atlassian incident were recent or historical, which directly informed how they communicated the risk to their crisis team.


Customer Credentials Leaked

This section shows credentials of end-users captured by malware while they were accessing the vendor's applications or services.

  • Credential samples: Partial display of the exposed email/username, a redacted password, the affected Access URL (the vendor application where the credential was captured), and the date of exposure.

Customer credential leaks indicate that users of the vendor's platform may have compromised devices. This represents a downstream risk that can affect your organization if it uses the same vendor applications. This data is refreshed weekly.

How to use it: Threat hunting and incident-response scoping. If you're investigating a potential compromise and a vendor's platform appears here with a high count of affected users, immediately check whether any of those credentials map to your organization's domain, the pivotal question is "were my people affected through this vendor?" Once you confirm exposure, initiate password resets, revoke active sessions, and audit what those users accessed on the vendor's side around the exposure date.


Dark Web & Brand Mentions

This section monitors the vendor's presence in cybercrime communities across the Dark Web, Telegram channels, and underground forums.

  • AI Summary: An AI-generated narrative summarizing the most relevant Dark Web activity related to the vendor.

  • Top Profiles and Channels Mentioning the Vendor's Brand: The most active profiles and channels mentioning the vendor, including their platform and total mention count.

  • Mentions by Channel: Breakdown of where the vendor is being discussed (e.g., Telegram, Twitter, WhatsApp, websites, and forums).

  • Navigate to Threat Hunting: A direct link to Axur's Threat Hunting with pre-filled filters for messaging and forum platforms, enabling deeper manual investigation without having to reconfigure the search.

Dark Web data is refreshed up to 4 times per day.

How to use it: Your early-warning radar. By the time an attack makes the news, the planning has often been happening in these channels for days or weeks. The AI summary isn't just noise counting; it identifies what the conversation is about: someone selling access, an actor claiming a compromise, or coordinated discussion of exploiting a specific service. If a known ransomware group mentions your vendor in the context of unauthorized access or data exfiltration, respond immediately: escalate internally, alert the vendor, and, if your environment is connected to theirs, move to active threat hunting. This is the window where you can still contain the blast radius.


Integrations: API & Webhooks

You can consume vendor intelligence in your own systems (SIEM, ticketing, SOAR). Integrations are managed under Settings → API & Integrations.

  • REST API: Query Dark Web, Threat Landscape (standard and critical bulletins), corporate and customer credentials, Attack Surface, trend indicators, and the AI overview. See the developer documentation linked on the API & Integrations page.

  • Feeds & Webhooks 2.0: Under API & Integrations → Feeds, click Add feed to receive continuous updates on vendor events. Choose a delivery mode:

    • Pull — you make GET requests to retrieve events when needed (add ?dry-run=true to test without consuming events).

    • Push — events are sent automatically to your configured endpoint (Webhook 2.0).

    • Slack — events are delivered to a channel in your connected Slack workspace.

  • Event types include: new bulletins, new critical bulletins, expired certificates, top threat actors, new corporate credentials, and new customer credentials. Feeds can be filtered by assets, customers, and sections (deep-dark-web, attack-surface, bulletins, critical-bulletins, corporate-credentials, and customer-credentials).

image.png

Alerts & Notifications

Configure automated alerts triggered by relevant changes in your monitored vendors. Alerts can be scoped per vendor and per event type (for example, new critical bulletins, expired certificates, new credentials, or Dark Web activity) so you focus on what matters and avoid alert fatigue. The Critical bulletin categories you set when adding a vendor determine which bulletins are treated as critical for alerting.


If you have any questions, feel free to contact us at [email protected] 😊

Did this answer your question?