T1195.002 Compromise Software Supply Chain
Sub-technique of T1195 Supply Chain Compromise
Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version. Targeting may…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Axios NPM Compromise File Creation Indicators - Linuxhighexperimental · linux
- Axios NPM Compromise File Creation Indicators - MacOShighexperimental · macos
- Axios NPM Compromise File Creation Indicators - Windowshighexperimental · windows
- Axios NPM Compromise Indicators - Linuxhighexperimental · linux
- Axios NPM Compromise Indicators - Windowshighexperimental · windows
- Axios NPM Compromise Indicators - macOShighexperimental · macos
- LiteLLM / TeamPCP Supply Chain Attack Indicatorshighexperimental · linux
- Shai-Hulud 2.0 Malicious NPM Package Installationhighexperimental · windows
- Shai-Hulud 2.0 Malicious NPM Package Installation - Linuxhighexperimental · linux
- Shai-Hulud Malicious Bun Executionhighexperimental · windows
- Shai-Hulud Malicious Bun Execution - Linuxhighexperimental · linux
- Suspicious Child Process of Notepad++ Updater - GUP.Exehighexperimental · windows
- TeamPCP LiteLLM Supply Chain Attack Persistence Indicatorshighexperimental · linux
- Uncommon File Created by Notepad++ Updater Gup.EXEhighexperimental · windows
- TanStack Supply-Chain Attack File Creation Indicators - Linuxmediumexperimental · linux
- TanStack Supply-Chain Attack File Creation Indicators - Windowsmediumexperimental · windows
- Notepad++ Updater DNS Query to Uncommon Domainsmedium # can be upgraded to high after tuning with known legitimate dns queriesexperimental · windows
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.