kevmap

Techniques › T1195

T1195 Supply Chain Compromise

initial access — Linux, Windows, macOS, SaaS · attack.mitre.org · JSON

1
MITRE detection strategy
3
analytics
1
Sigma rules tagged attack.t1195
1
KEV CVEs mapped here
<p>Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.</p><p>Supply chain compromise can take place at any stage of the supply chain including:</p>
    <li>Manipulation of development tools</li><li>Manipulation of a development environment</li><li>Manipulation of source code repositories (public or private)</li><li>Manipulation of source code in open-source dependencies</li><li>Manipulation of software update/distribution mechanisms</li><li>Compromised/infected system images (removable media infected at the factory) </li><li>Replacement of legitimate software with modified versions</li><li>Sales of modified/counterfeit products to legitimate distributors</li><li>Shipment interdiction</li>
<p>While supply chain compromise can impact any component of hardware or software, adversaries looking to gain execution have often focused on malicious additions to legitimate software in software distribution or update channels. Adversaries may limit targeting to a desired victim set or distribute malicious software to a broad set of consumers but only follow up with specific victims. Popular open-source projects that are used as dependencies in many applications may also be targeted as a means to add malicious code to users of the dependency.</p><p>In some cases, adversaries may conduct “second-order” supply chain compromises by leveraging the access gained from an initial supply chain compromise to further compromise a software component. This may allow the threat actor to spread to even more victims.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

CVEVendor / productMapping typeStateAdded
CVE-2024-49035Microsoft Partner Center primary impact Mapped2025-02-25

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1195

Author: NVISO · 2020-06-09 (modified 2021-11-27) · logsource: product=windows category=file_event · 805c55d9-31e6-4846-9878-c34c75054fe9
Detects Octopus Scanner Malware.
Techniques: T1195T1195.001

Sub-techniques

IDNameSigma rulesKEV CVEs
T1195.001Compromise Software Dependencies and Development Tools20
T1195.002Compromise Software Supply Chain172
T1195.003Compromise Hardware Supply Chain00