Techniques › T1195
T1195 Supply Chain Compromise
initial access — Linux, Windows, macOS, SaaS · attack.mitre.org · JSON
1
MITRE detection strategy
3
analytics
1
Sigma rules tagged attack.t1195
1
KEV CVEs mapped here
<p>Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.</p><p>Supply chain compromise can take place at any stage of the supply chain including:</p>
- <li>Manipulation of development tools</li><li>Manipulation of a development environment</li><li>Manipulation of source code repositories (public or private)</li><li>Manipulation of source code in open-source dependencies</li><li>Manipulation of software update/distribution mechanisms</li><li>Compromised/infected system images (removable media infected at the factory) </li><li>Replacement of legitimate software with modified versions</li><li>Sales of modified/counterfeit products to legitimate distributors</li><li>Shipment interdiction</li>
KEV CVEs mapped to this technique · CTID Mappings Explorer
| CVE | Vendor / product | Mapping type | State | Added |
|---|---|---|---|---|
| CVE-2024-49035 | Microsoft Partner Center | primary impact | Mapped | 2025-02-25 |
Detection strategy · ATT&CK Enterprise v19.2
- DET0537 Behavioral detection for Supply Chain Compromise (package/update tamper → install → first-run) v1.0
AN1480 Windows1) New or updated software is delivered/installed from atypical sources or with signature/hash mismatches; 2) installer/updater writes binaries to unexpected paths or replaces existing signed files; 3) first run causes unsigned/abnormally signed modules to load or child processes to execute, optionally followed by network egress to new destinations.WinEventLog:Microsoft-Windows-CodeIntegrity/Operational
CodeIntegrity reports 'Invalid image hash' or 'Unsigned image' for new/updated binaries→ DC0059 File MetadataNSM:FlowFirst-time egress from host after new install to unknown update endpoints→ DC0078 Network Traffic FlowTunable:TimeWindowTrustedPublishersTrustedUpdateHostsRiskScoreThresholdAN1481 Linux1) Package manager or curl/wget installs/upgrades from non-approved repos or unsigned packages; 2) new ELF written into PATH directories or replacement of existing binaries/libraries; 3) first run leads to unexpected child processes or outbound connections.NSM:FlowFirst-time egress to unknown registries/mirrors immediately after install→ DC0078 Network Traffic FlowTunable:ApprovedReposPathScopeMinBinarySizeTimeWindowAN1482 macOS1) pkg/notarization installs from atypical sources or with Gatekeeper/AMFI warnings; 2) new Mach-O written into /Applications or ~/Library paths or substitution of signed components; 3) first run from installer spawns unsigned children or exfil.macos:unifiedloginstaller or system_installd 'PackageKit: install succeeded/failed' with non-notarized or unknown signer→ DC0059 File MetadataNSM:FlowNew egress from app just installed to unknown update endpoints→ DC0078 Network Traffic FlowTunable:AllowedTeamIDsTrustedDMGsTimeWindowRiskScoreThreshold
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1195
Author: NVISO
· 2020-06-09 (modified 2021-11-27) · logsource: product=windows category=file_event · 805c55d9-31e6-4846-9878-c34c75054fe9
Detects Octopus Scanner Malware.