Skip to content
Moat or Bloat

dSBOM-engine

Dynamic SBOM tool using kernel tracing to track live memory maps and export to CycloneDX

Library Rated 7 Oct 2026Dormant

Built by
Tetstack

Bloat

123/500

Where it landed on the scale

Bloat
0
Float
300
Moat
400

Summary

dSBOM-engine is a working proof of concept with real tracing output and a tagged release, built in one day with no activity since. The problem (static SBOMs missing runtime-loaded code) is real, but there's no path to payment, no docs or support, and the core idea is replicable by someone with ptrace experience.

Bloat · Not much here works or looks likely to last, yet.

Breakdown

Five measures, 100 points each. Open the receipts under any of them to see the posts and pages behind the points.

Viability

Is there a real problem, someone who would pay, and a market this builder can actually reach?

The runtime-versus-static SBOM gap is a real security problem, but there's no pricing, no sign of anyone using it, and no clear buyer within this builder's reach.

33/100

Rubric 21–40A real problem, but no plausible path to anyone paying, or a market well out of this builder's reach.

Receipts (2)
  1. Describes a real blind spot in static SBOM tools, such as dlopen() payloads and packed ELF files.

    “I present dSBOM-engine https://github.com/PicasoTheDeal/dSBOM-engine Static SBOM tools miss a massive execution blind spot: what's on disk isn't always what runs in memory. Malware easily bypasses them by packing payloads inside clean ELF envelopes and dynamic libraries via dlopen(). dSBOM-engine uses low-level kernel tracing (ptrace) to track live memory maps and export footprints into Cyclone”

    Post · @Tetstack · 3 Jul 2026 · open on Telegram (opens in a new tab)

  2. No license, homepage or pricing, so there's no visible way to charge or even define who may use it.

    Checked 7 Oct 2026 · github.com/PicasoTheDeal/dSBOM-engine (opens in a new tab)

Moat

What stops someone copying it?

The edge is mostly execution and security know-how with ptrace and CycloneDX. Nothing compounding like data, integrations or distribution is visible, and a skilled developer could rebuild a basic version.

24/100

Rubric 21–40The only edge is execution, or being first.

Receipts (2)
  1. Claims ptrace-based memory map tracking and CycloneDX export, which is technical but a known approach.

    “I present dSBOM-engine https://github.com/PicasoTheDeal/dSBOM-engine Static SBOM tools miss a massive execution blind spot: what's on disk isn't always what runs in memory. Malware easily bypasses them by packing payloads inside clean ELF envelopes and dynamic libraries via dlopen(). dSBOM-engine uses low-level kernel tracing (ptrace) to track live memory maps and export footprints into Cyclone”

    Post · @Tetstack · 3 Jul 2026 · open on Telegram (opens in a new tab)

  2. Single day of commits and no ecosystem, data or community around it.

    Checked 7 Oct 2026 · github.com/PicasoTheDeal/dSBOM-engine (opens in a new tab)

Momentum

Did the updates keep coming?

All work happened on a single day (2026-07-03) and nothing has shipped in the 96 days since, so there's no sustained track record yet.

0/100

  • Sustained shipping0/60

    Worked on across 1 days.

  • Consistency0/40

    Updates in 1 of 1 month.

  • Quiet

    No update for 96 days, so scaled to 49%.

Receipts (2)
  1. Earliest post about it.

    “[*] Initiating: basic_link [*] dSBOM Engine: Tracking initialization on PID 5775 [dSBOM Found] -> /usr/lib/ld-linux-x86-64.so.2 [dSBOM Found] -> /usr/lib/libgcc_s.so.1 [dSBOM Found] -> /usr/lib/libstdc++.so.6.0.35 [dSBOM Found] -> /usr/lib/libm.so.6 [dSBOM Found] -> /usr/lib/libc.so.6 [dSBOM Found] -> /home/picasothedealer/Documents/Projects/dSBOM-engine/build/dSBOM [dSBOM Found] -> /home/picasoth”

    Post · @Tetstack · 3 Jul 2026 · open on Telegram (opens in a new tab)

  2. Most recent post about it.

    “I present dSBOM-engine https://github.com/PicasoTheDeal/dSBOM-engine Static SBOM tools miss a massive execution blind spot: what's on disk isn't always what runs in memory. Malware easily bypasses them by packing payloads inside clean ELF envelopes and dynamic libraries via dlopen(). dSBOM-engine uses low-level kernel tracing (ptrace) to track live memory maps and export footprints into Cyclone”

    Post · @Tetstack · 3 Jul 2026 · open on Telegram (opens in a new tab)

Infrastructure

Does a real, working product exist?

A working tracer exists with sample output and a tagged release, but it's only shown on small test programs and lacks docs, an API or visible CycloneDX output.

54/100

  • It's live20/20

    https://github.com/PicasoTheDeal/dSBOM-engine responded when checked.

  • HTTPS5/5

    Hosted on a platform (store, GitHub or Telegram), so HTTPS is the platform's.

  • Real product25/35

    The post shows the engine tracing real processes, listing loaded libraries and finishing cleanly, and a release exists. It's still thin: one test run on toy programs, and the CycloneDX output isn't shown.

  • Own home0/10

    No home found.

  • Maintained0/15

    Last sign of shipping 2026-07-03.

  • Operations4/15

    The post mentions CodeQL, Trivy scanning and signed SHA256 binaries, which is some engineering hygiene. There's no API, docs site, status page or multi-platform support (Linux only).

Receipts (5)
  1. https://github.com/PicasoTheDeal/dSBOM-engine responded when checked.

    Checked 7 Oct 2026 · github.com/PicasoTheDeal/dSBOM-engine (opens in a new tab)

  2. Log output of tracking PIDs and listing loaded shared libraries for test programs.

    “[*] Initiating: basic_link [*] dSBOM Engine: Tracking initialization on PID 5775 [dSBOM Found] -> /usr/lib/ld-linux-x86-64.so.2 [dSBOM Found] -> /usr/lib/libgcc_s.so.1 [dSBOM Found] -> /usr/lib/libstdc++.so.6.0.35 [dSBOM Found] -> /usr/lib/libm.so.6 [dSBOM Found] -> /usr/lib/libc.so.6 [dSBOM Found] -> /home/picasothedealer/Documents/Projects/dSBOM-engine/build/dSBOM [dSBOM Found] -> /home/picasoth”

    Post · @Tetstack · 3 Jul 2026 · open on Telegram (opens in a new tab)

  3. One GitHub release with a description of the CycloneDX generator.

    Checked 7 Oct 2026 · github.com/PicasoTheDeal/dSBOM-engine (opens in a new tab)

  4. Mentions CodeQL memory safety checks, continuous Trivy scanning and SHA256 signatures.

    “I present dSBOM-engine https://github.com/PicasoTheDeal/dSBOM-engine Static SBOM tools miss a massive execution blind spot: what's on disk isn't always what runs in memory. Malware easily bypasses them by packing payloads inside clean ELF envelopes and dynamic libraries via dlopen(). dSBOM-engine uses low-level kernel tracing (ptrace) to track live memory maps and export footprints into Cyclone”

    Post · @Tetstack · 3 Jul 2026 · open on Telegram (opens in a new tab)

  5. Only a repo and one release; no homepage.

    Checked 7 Oct 2026 · github.com/PicasoTheDeal/dSBOM-engine (opens in a new tab)

Sustainability

Is it being set up to last?

There's one GitHub release for distribution, no license, pricing, revenue, support or team, and no sign the project is being carried forward.

12/100

  • Distribution10/30

    Versioned downloadable releases (1 on GitHub).

  • Payments0/15

    No payment provider found.

  • Pricing0/10

    No pricing found on the site.

  • Revenue0/5

    No paying customers or revenue are mentioned anywhere.

  • Privacy policy0/7

    No privacy policy found.

  • Terms0/5

    No terms of service found.

  • Support0/8

    No support contact found.

  • Commitment2/20

    All activity falls on one day and nothing has happened in over three months. There's no roadmap, team, dedicated community or funding.

Receipts (4)
  1. Versioned downloadable releases (1 on GitHub).

    Checked 7 Oct 2026 · github.com/PicasoTheDeal/dSBOM-engine (opens in a new tab)

  2. The announcement says nothing about customers or sales.

    “I present dSBOM-engine https://github.com/PicasoTheDeal/dSBOM-engine Static SBOM tools miss a massive execution blind spot: what's on disk isn't always what runs in memory. Malware easily bypasses them by packing payloads inside clean ELF envelopes and dynamic libraries via dlopen(). dSBOM-engine uses low-level kernel tracing (ptrace) to track live memory maps and export footprints into Cyclone”

    Post · @Tetstack · 3 Jul 2026 · open on Telegram (opens in a new tab)

  3. Created, committed and released all on 2026-07-03, with no pushes since.

    Checked 7 Oct 2026 · github.com/PicasoTheDeal/dSBOM-engine (opens in a new tab)

  4. Single launch post with no roadmap or follow-up plans.

    “I present dSBOM-engine https://github.com/PicasoTheDeal/dSBOM-engine Static SBOM tools miss a massive execution blind spot: what's on disk isn't always what runs in memory. Malware easily bypasses them by packing payloads inside clean ELF envelopes and dynamic libraries via dlopen(). dSBOM-engine uses low-level kernel tracing (ptrace) to track live memory maps and export footprints into Cyclone”

    Post · @Tetstack · 3 Jul 2026 · open on Telegram (opens in a new tab)