Tracing Ghost Suppliers: What DNS, TLS and JavaScript Reveal About Your Real Supply Chain
A few months ago we mapped the externally visible digital supply chains of critical infrastructure organizations in a Balkan country without credentials, agents or internal access. Starting with a root domain, we followed DNS delegations, certificate relationships, script inclusions, hosting infrastructure, ASNs and third-party services to see how far the dependency graph would take us. Quite far. One energy organisation alone produced 941 findings. Among them were still-active technical dependencies on Russian-origin infrastructure inherited through suppliers and web infrastructure; connections that persisted despite a geopolitical environment very different from the one in which the original procurement decisions were made. But the interesting part wasn't Russia. It was the gap between the supply chain organisations believed they had and the one their infrastructure exposed. In this talk I'll show how to reconstruct a supplier graph from externally observable signals, distinguish incidental vendor references from dependencies that can actually influence the attack surface, and rank relationships based on technical proximity rather than treating every third party as equal. I'll walk through the signals that proved useful, the ones that produced misleading relationships, and patterns we've subsequently observed across critical infrastructure in the Western Balkans and Central Asia. Attendees will leave with a practical methodology for using passive reconnaissance to identify hidden supplier dependencies and to ask a deceptively simple question of their own environments: Who can touch your attack surface that isn't on your supplier list? No exploitation, no internal access. Just what the infrastructure says about itself when you know where to look.
Speaker

Robin de Vries
CEO at ThingsRecon - Supply Chain Intelligence
Robin de Vries spent 22 years founding and leading PQR, a Dutch IT infrastructure company, before turning his attention to a question that kept surfacing in enterprise environments: what does an organization's digital supply chain look like from the outside, and how much of it is invisible to the organization itself. He now leads ThingsRecon, where he builds infrastructure for passive discovery and continuous monitoring of digital supplier relationships and attack paths across government, critic... read more