Cybersecurity from Málaga · Networks, lures and threats

← Threats
MITRE ATT&CK technique · Initial Access

T1195.001 Compromise Software Dependencies and Development Tools

Sub-technique of T1195 Supply Chain Compromise

Adversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise. Applications often depend on external software to function properly. Popular open source projects that are used as dependencies in many applications, such as pip and NPM packages, may be targeted as a means to add malicious code to users of the…

MITRE ATT&CK page ↗

Who uses it · with stories on Jábega

Sigma rules to hunt it

Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.