diff --git a/sbom.md b/sbom.md
index daaffe4..3dbd857 100644
--- a/sbom.md
+++ b/sbom.md
@@ -78,3 +78,32 @@ Most used from this list: https://spdx.dev/use/spdx-tools/
| [Snyk](https://snyk.io) | `tbd` | Proprietary | Unknown |
| [SBOM Observer](https://sbom.observer) | `tbd` | Proprietary | 49 EUR/user/month, 69 EUR/user/month, Custom |
| [SOOS](https://soos.io) | `tbd` | Proprietary | $0/month, $90/month, Custom |
+
+
+| Name and Link | Key Features | License | Approx Costs |
+| ------------- | ------------ | ------- | ------------ |
+| [Microsoft's SBOM Tool](https://github.com/microsoft/sbom-tool) |
- **SBOM Generation**: Scans source folders for dependencies and generates SBOMs.
- **CI/CD Integration**: Seamless integration with GitHub Actions and Azure DevOps.
- **Validation**: Validates SBOMs and redacts sensitive data.
| MIT | Open Source |
+| [Syft](https://github.com/anchore/syft) | - **SBOM Creation**: Builds SBOMs for containers, files, and cloud artifacts.
- **Multiple Formats**: Supports SPDX and CycloneDX.
- **Ecosystem Integration**: Compatible with Anchore's other tools for security analysis.
| Apache-2.0 | Open Source |
+| [ScanCode Toolkit](https://github.com/nexB/scancode-toolkit) | - **License Detection**: Scans for open-source licenses and copyrights.
- **Component Identification**: Identifies components, vulnerabilities, and origin data.
- **Customizable**: Extensible with plugins and tailored scanning options. | Apache-2.0 | Open Source |
+| [SCANOSS](https://www.scanoss.com) |
- **Real-Time Scanning**: Detects open-source components during development.
- **Comprehensive Detection**: Uses an extensive database for accurate results.
- **APIs for Integration**: Offers APIs for workflow integration.
| Proprietary | Free, $35K/year, Custom |
+| [Vigilant Ops](https://www.vigilant-ops.com) | - **SBOM Management**: Manages and tracks SBOMs for transparency.
- **Vulnerability Analysis**: Identifies risks in software components.
- **Compliance Tools**: Ensures adherence to industry standards.
| Proprietary | Unknown |
+| [Threatrix](https://threatrix.io) | - **SCA Analysis**: Monitors and analyzes software components.
- **Real-Time Updates**: Detects emerging vulnerabilities.
- **Detailed Reporting**: Helps manage security and compliance risks.
| Proprietary | Unknown |
+| [Black Duck](https://www.blackduck.com) | - **Component Insights**: Tracks open-source licenses and vulnerabilities.
- **Policy Automation**: Creates and enforces usage policies.
- **Continuous Monitoring**: Monitors for new threats and compliance issues.
| Proprietary | Unknown |
+| [OSS Review Toolkit](https://oss-review-toolkit.org) | - **Dependency Scanning**: Automates open-source dependency analysis.
- **Policy Evaluation**: Ensures compliance with organizational policies.
- **CI/CD Integration**: Fits into existing pipelines.
| Apache-2.0 | Open Source |
+| [Manifest](https://www.manifestcyber.com) | - **SBOM Tools**: Manages and generates SBOMs for software.
- **Vulnerability Scans**: Identifies risks in the supply chain.
- **Compliance Support**: Helps meet regulatory standards.
| Proprietary | Unknown |
+| [Lib4SBOM](https://github.com/anthonyharrison/lib4sbom) | - **Library for SBOMs**: Simplifies SBOM creation in various formats.
- **Standard Support**: Compatible with SPDX and CycloneDX.
- **Development Friendly**: Easy integration with workflows.
| Apache-2.0 | Open Source |
+| [GUAC](https://guac.sh) | - **SBOM Aggregation**: Consolidates SBOMs into a unified graph.
- **Provenance Tracking**: Tracks the origin of software components.
- **Querying**: Provides deep insights into dependencies.
| Apache-2.0 | Open Source |
+| [FOSSology](https://www.fossology.org) | - **License Scanning**: Detects and analyzes software licenses.
- **Metadata Extraction**: Extracts copyright and component details.
- **Custom Workflows**: Supports flexible compliance processes.
| GPL-2.0 / LGPL-2.1 | Open Source |
+| [DISTRO2SBOM](https://github.com/anthonyharrison/distro2sbom) | - **Distribution Focused**: Creates SBOMs for Linux distributions.
- **Comprehensive Scans**: Analyzes all installed packages.
- **Standards Compatible**: Supports SPDX and CycloneDX formats.
| Apache-2.0 | Open Source |
+| [CycloneDX](https://github.com/CycloneDX) | - **SBOM Standard**: Defines a standardized SBOM format.
- **Extensive Tooling**: Libraries and tools for CycloneDX SBOMs.
- **Broad Adoption**: Industry-standard for supply chain transparency.
| Apache-2.0 | Open Source |
+| [CAST SBOM Manager](https://www.castsoftware.com/sbommanager) | - **Centralized Management**: Manages SBOMs from various tools.
- **Vulnerability Tracking**: Monitors components for security issues.
- **Compliance Features**: Generates reports for regulatory requirements.
| Proprietary | Free |
+| [Dependency Track](https://dependencytrack.org) | - **Continuous Analysis**: Analyzes SBOMs for vulnerabilities.
- **Ecosystem Integration**: Works with CycloneDX SBOMs.
- **Comprehensive Monitoring**: Tracks components for new risks.
| Apache-2.0 | Open Source |
+| [Trivy](https://trivy.dev) | - **Vulnerability Scanning**: Scans containers, dependencies, and code.
- **SBOM Support**: Generates and analyzes SBOMs.
- **Broad Compatibility**: Works across multiple platforms and CI/CD tools.
| Apache-2.0 | Open Source |
+| [Parlay](https://github.com/snyk/parlay) | - **SBOM Enhancements**: Improves and consolidates SBOM data.
- **Integration Ready**: Supports Snyk tools and others.
- **Scalability**: Handles large-scale SBOMs efficiently.
| Apache-2.0 | Open Source |
+| [Finite State](https://finitestate.io) | - **SBOM Automation**: Automates SBOM creation and management.
- **Vulnerability Analysis**: Identifies and mitigates risks.
- **Compliance Features**: Meets regulatory requirements.
| Proprietary | Unknown |
+| [Checkmarx](https://checkmarx.com/product/sbom/) | - **SBOM Creation**: Generates SBOMs with detailed component analysis.
- **Security Focus**: Prioritizes identifying vulnerabilities.
- **Policy Compliance**: Ensures adherence to internal policies.
| Proprietary | Unknown |
+| [Qwiet](https://qwiet.ai) | - **Real-Time Scans**: Monitors open-source components during CI/CD.
- **AI-Driven Analysis**: Leverages AI for threat detection.
- **Comprehensive Reporting**: Details vulnerabilities and compliance.
| Proprietary | Unknown |
+| [Snyk](https://snyk.io) | - **SBOM Support**: Integrates SBOM generation with its security tools.
- **Vulnerability Scans**: Identifies threats in open-source and proprietary code.
- **Policy Compliance**: Assists in maintaining secure supply chains.
| Proprietary | Unknown |
+| [SBOM Observer](https://sbom.observer) | - **Visualization**: Visualizes SBOM data for better understanding.
- **Collaboration**: Designed for team use with access controls.
- **Multi-Tier Plans**: Offers flexible subscription options
| Proprietary | €49/user/month, €69/user/month, Custom |
+| [SOOS](https://soos.io) | - **Affordable Security**: Provides low-cost vulnerability analysis.
- **SBOM Tools**: Creates and manages SBOMs efficiently.
- **Developer Focus**: Tailored for small to medium teams.
| Proprietary | $0/month, $90/month, Custom |
+