If you're hitting #AppSecVillage at #DEFCON34 this weekend, take a minute and check out my Arsenal session on Proactive Malicious Package Defense. I'm releasing a free and #opensource tool that can use public intel sources, or commercial ones if you want. Fully pluggable! And has features that make it useful from desktop to enterprise-scale CI, and ships as a static binary