T1677 Poisoned Pipeline Execution
Adversaries may manipulate continuous integration / continuous development (CI/CD) processes by injecting malicious code into the build process. There are several mechanisms for poisoning pipelines: * In a Direct Pipeline Execution scenario, the threat actor directly modifies the CI configuration file (e.g., `gitlab-ci.yml` in GitLab). They may include a command to exfiltrate credentials…
Who uses it · with stories on Jábega
Sigma rules to hunt it
SigmaHQ has no rules for this technique.
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.