{"id":"T1677","name":"Poisoned Pipeline Execution","url":"https://attack.mitre.org/techniques/T1677","tactics":["execution"],"platforms":["SaaS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0533","stix_id":"x-mitre-detection-strategy--cad3cfb6-1838-4fa3-abfc-aa590f613436","name":"Detection Strategy for Poisoned Pipeline Execution via SaaS CI/CD Workflows","url":"https://attack.mitre.org/detectionstrategies/DET0533","analytics":[{"id":"AN1473","stix_id":"x-mitre-analytic--0391c880-fcb3-457f-b625-18f9453659b8","name":"Analytic 1473","description":"Detects anomalous CI/CD workflow execution originating from forked repositories, with pull request (PR) metadata or commit messages containing suspicious patterns (e.g., encoded payloads), coupled with the use of insecure pipeline triggers like `pull_request_target` or excessive API usage of CI/CD secrets. Correlation with unusual artifact generation or secret exfiltration via encoded or external network destination URLs confirms suspicious behavior.","url":"https://attack.mitre.org/detectionstrategies/DET0533#AN1473","platforms":["SaaS"],"log_source_references":[{"name":"saas:github","channel":"Workflow triggered via pull_request_target from forked repo","data_component":"DC0069","data_component_name":"Cloud Service Modification","log_source_slug":"saas-github"},{"name":"saas:github","channel":"CI/CD secret accessed or exported","data_component":"DC0070","data_component_name":"Cloud Service Metadata","log_source_slug":"saas-github"},{"name":"saas:github","channel":"Artifact generated includes base64/encoded exfil payload or URL","data_component":"DC0025","data_component_name":"Cloud Storage Access","log_source_slug":"saas-github"},{"name":"saas:RepoEvents","channel":"New file added or modified in PR targeting CI/CD or build config (e.g., `gitlab-ci.yml`, `build.gradle`, `pom.xml`, `.github/workflows/*.yml`)","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"saas-repoevents"},{"name":"saas:PRMetadata","channel":"Commit message or branch name contains encoded strings or payload indicators","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"saas-prmetadata"}],"mutable_elements":[{"field":"TimeWindow","description":"Time delta between PR creation and workflow execution to flag rapid attempts"},{"field":"UserContext","description":"Forked or external user accounts triggering workflows; may differ across orgs"},{"field":"TriggerTypeAllowlist","description":"CI trigger types (e.g., `pull_request_target`) that should or shouldn't be used for forks"},{"field":"ArtifactEntropyThreshold","description":"Entropy threshold for detecting encoded payloads in artifacts"},{"field":"SecretAccessRateThreshold","description":"Rate of secret access in a single workflow run that might indicate abuse"}],"live":true,"detection_strategies":["DET0533"],"techniques":["T1677"]}],"live":true,"version":"1.0","techniques":["T1677"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}