{"id":"T1195","name":"Supply Chain Compromise","url":"https://attack.mitre.org/techniques/T1195","tactics":["initial-access"],"platforms":["Linux","Windows","macOS","SaaS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0537","stix_id":"x-mitre-detection-strategy--18c9199f-d6b6-4efe-ac90-9a1b7b8c6f36","name":"Behavioral detection for Supply Chain Compromise (package/update tamper → install → first-run)","url":"https://attack.mitre.org/detectionstrategies/DET0537","analytics":[{"id":"AN1480","stix_id":"x-mitre-analytic--a6b1e74e-6c05-4d9f-928c-63ddf558798b","name":"Analytic 1480","description":"1) New or updated software is delivered/installed from atypical sources or with signature/hash mismatches; 2) installer/updater writes binaries to unexpected paths or replaces existing signed files; 3) first run causes unsigned/abnormally signed modules to load or child processes to execute, optionally followed by network egress to new destinations.","url":"https://attack.mitre.org/detectionstrategies/DET0537#AN1480","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Microsoft-Windows-CodeIntegrity/Operational","channel":"CodeIntegrity reports 'Invalid image hash' or 'Unsigned image' for new/updated binaries","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"wineventlog-microsoft-windows-codeintegrity-operational"},{"name":"NSM:Flow","channel":"First-time egress from host after new install to unknown update endpoints","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"TimeWindow","description":"Correlation window between install events and first-run activity (default 2h; adjust for staged rollouts)."},{"field":"TrustedPublishers","description":"Publisher/Signer allow-list to suppress expected updates."},{"field":"TrustedUpdateHosts","description":"Known update CDNs/APIs (e.g., download.microsoft.com) to reduce egress false positives."},{"field":"RiskScoreThreshold","description":"Score cut-off for alerting when combining path, signer, and reputation features."}],"live":true,"detection_strategies":["DET0537"],"techniques":["T1195"]},{"id":"AN1481","stix_id":"x-mitre-analytic--86f2dfd5-7073-4178-8c83-8628ecf087d4","name":"Analytic 1481","description":"1) Package manager or curl/wget installs/upgrades from non-approved repos or unsigned packages; 2) new ELF written into PATH directories or replacement of existing binaries/libraries; 3) first run leads to unexpected child processes or outbound connections.","url":"https://attack.mitre.org/detectionstrategies/DET0537#AN1481","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve, unlink","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"open, rename","data_component":"DC0020","data_component_name":"Process Modification","log_source_slug":"auditd-syscall"},{"name":"journald:package","channel":"dpkg/apt install, remove, upgrade events","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"journald-package"},{"name":"NSM:Flow","channel":"First-time egress to unknown registries/mirrors immediately after install","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"ApprovedRepos","description":"Allow-listed APT/YUM repo URLs and GPG key fingerprints."},{"field":"PathScope","description":"Directories to watch for new ELF writes (e.g., /usr/bin, /usr/local/bin, /lib*/, /opt/*/bin)."},{"field":"MinBinarySize","description":"Ignore tiny helper files; default >16KB."},{"field":"TimeWindow","description":"Install→first-run correlation window (default 2h)."}],"live":true,"detection_strategies":["DET0537"],"techniques":["T1195"]},{"id":"AN1482","stix_id":"x-mitre-analytic--779b2e27-9318-46a3-aeec-765f5fb09de3","name":"Analytic 1482","description":"1) pkg/notarization installs from atypical sources or with Gatekeeper/AMFI warnings; 2) new Mach-O written into /Applications or ~/Library paths or substitution of signed components; 3) first run from installer spawns unsigned children or exfil.","url":"https://attack.mitre.org/detectionstrategies/DET0537#AN1482","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"installer or system_installd 'PackageKit: install succeeded/failed' with non-notarized or unknown signer","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"launchd, processes","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"},{"name":"macos:endpointsecurity","channel":"write, rename","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"macos-endpointsecurity"},{"name":"NSM:Flow","channel":"New egress from app just installed to unknown update endpoints","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"AllowedTeamIDs","description":"Apple Developer Team IDs permitted in your fleet."},{"field":"TrustedDMGs","description":"Known DMG/Pkg sources and hashes."},{"field":"TimeWindow","description":"Install→first-run correlation window (default 2h)."},{"field":"RiskScoreThreshold","description":"Adjust alert sensitivity based on org tolerance."}],"live":true,"detection_strategies":["DET0537"],"techniques":["T1195"]}],"live":true,"version":"1.0","techniques":["T1195"]}],"sigma_rules":[{"id":"805c55d9-31e6-4846-9878-c34c75054fe9","title":"Octopus Scanner Malware","author":"NVISO","status":"test","level":"high","date":"2020-06-09","modified":"2021-11-27","description":"Detects Octopus Scanner Malware.","references":["https://securitylab.github.com/research/octopus-scanner-malware-open-source-supply-chain"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.initial-access","attack.t1195","attack.t1195.001"],"path":"rules/windows/file/file_event/file_event_win_mal_octopus_scanner.yml","techniques":["T1195","T1195.001"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2024-49035","state":"mapped","mapping_types":["primary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}