kevmap

TechniquesT1195 › T1195.001

T1195.001 Compromise Software Dependencies and Development Tools

initial access — Linux, macOS, Windows · attack.mitre.org · JSON

1
MITRE detection strategy
3
analytics
2
Sigma rules tagged attack.t1195.001
0
KEV CVEs mapped here
<p>Adversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise. Applications often depend on external software to function properly. Popular open source projects that are used as dependencies in many applications, such as pip and NPM packages, may be targeted as a means to add malicious code to users of the dependency. This may also include abandoned packages, which in some cases could be re-registered by threat actors after being removed by adversaries. Adversaries may also employ "typosquatting" or name-confusion by choosing names similar to existing popular libraries or packages in order to deceive a user.</p><p>Additionally, CI/CD pipeline components, such as GitHub Actions, may be targeted in order to gain access to the building, testing, and deployment cycles of an application. By adding malicious code into a GitHub action, a threat actor may be able to collect runtime credentials (e.g., via Proc Filesystem) or insert further malicious components into the build pipelines for a second-order supply chain compromise. As GitHub Actions are often dependent on other GitHub Actions, threat actors may be able to infect a large number of repositories via the compromise of a single Action.</p><p>Targeting may be specific to a desired victim set or may be distributed to a broad set of consumers but only move on to additional tactics on specific victims.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1195.001

Author: Muhammad Faisal (@faisalusuf) · 2023-01-27 · logsource: product=github service=audit · 34e1c7d4-0cd5-419d-9f1b-1dad3f61018d
Dependabot performs a scan to detect insecure dependencies, and sends Dependabot alerts. This rule detects when an organization owner disables Dependabot alerts private repositories or Dependabot security updates for all repositories.
Techniques: T1195.001
Author: NVISO · 2020-06-09 (modified 2021-11-27) · logsource: product=windows category=file_event · 805c55d9-31e6-4846-9878-c34c75054fe9
Detects Octopus Scanner Malware.
Techniques: T1195T1195.001

Rules tagged at the parent level (attack.t1195) 1

These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.

Author: NVISO · 2020-06-09 (modified 2021-11-27) · logsource: product=windows category=file_event · 805c55d9-31e6-4846-9878-c34c75054fe9
Detects Octopus Scanner Malware.
Techniques: T1195T1195.001