Cross-source coverage

T1195.002 / ATT&CK

Supply Chain Compromise: Compromise Software Supply Chain

59 rules across 6 sources.

4 deprecated hidden · include

From MITRE ATT&CK 19.2

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Targeting may be specific to a desired victim set or may be distributed to a broad set of consumers but only move on to additional tactics on specific victims.

Tactics
Initial Access
Platforms
Linux · Windows · macOS
Telemetry
WinEventLog:SysmonWinEventLog:Microsoft-Windows-CodeIntegrity/OperationalNSM:Flowauditd:SYSCALLjournald:packagemacos:unifiedlogmacos:endpointsecurity

How MITRE says to detect it DET0309

Compromised software/update chain (installer/write → first-run/child → egress/signature anomaly)

Windows Analytic 0862

Adversary ships a tampered application or update: an updater/installer (msiexec/setup/update.exe/vendor service) writes or replaces binaries; on first run it spawns scripts/shells or unsigned DLLs and beacons to non-approved update CDNs/hosts. Detection correlates: (1) process creation of installer/updater → (2) file metadata changes in program paths → (3) first-run children and module/signature anomalies → (4) outbound connections to unexpected hosts within a short window.

  • WinEventLog:Sysmon EventCode=1
  • WinEventLog:Sysmon EventCode=6
  • WinEventLog:Sysmon EventCode=7
  • WinEventLog:Sysmon EventCode=11
  • WinEventLog:Sysmon EventCode=13, 14
  • WinEventLog:Sysmon EventCode=3, 22
  • WinEventLog:Microsoft-Windows-CodeIntegrity/Operational Unsigned or invalid image for newly installed/updated binaries
  • NSM:Flow First-time egress to non-approved update hosts right after install/update

Linux Analytic 0863

A compromised package/update (deb/rpm/tarball/AppImage/vendor updater) is installed, writing/overwriting files in /usr/local/bin, /usr/bin, /opt, or ~/.local; first run executes unexpected shells/curl/wget and connects to unapproved hosts. Correlate package/updater execution → file writes/replace → first-run child processes → egress.

  • auditd:SYSCALL execve
  • journald:package dpkg/apt/yum/dnf transaction logs; vendor updaters in systemd journals
  • NSM:Flow New outbound flows to non-approved vendor hosts post install

macOS Analytic 0864

A tampered app/pkg/notarized update is installed via installer, softwareupdated, Homebrew, or vendor updater; new Mach-O or bundle contents appear in /Applications, /Library, /usr/local or /opt/homebrew; first run spawns sh/zsh/osascript/curl and makes egress to unfamiliar domains; AMFI/Gatekeeper may log signature/notarization problems.

  • macos:unifiedlog pkginstalld/softwareupdated/Homebrew install transactions
  • macos:endpointsecurity exec
  • NSM:Flow New/rare egress to non-approved update hosts after install

SigmaHQ/sigma

17 rules
Detection Severity Format
Axios NPM Compromise File Creation Indicators - Linux High Sigma
Axios NPM Compromise File Creation Indicators - MacOS High Sigma
Axios NPM Compromise File Creation Indicators - Windows High Sigma
Axios NPM Compromise Indicators - Linux High Sigma
Axios NPM Compromise Indicators - macOS High Sigma
Axios NPM Compromise Indicators - Windows High Sigma
LiteLLM / TeamPCP Supply Chain Attack Indicators High Sigma
Shai-Hulud 2.0 Malicious NPM Package Installation High Sigma
Shai-Hulud 2.0 Malicious NPM Package Installation - Linux High Sigma
Shai-Hulud Malicious Bun Execution High Sigma

+ 7 more from SigmaHQ/sigma → showing the 10 highest-severity

elastic/detection-rules

15 rules
Detection Severity Format
Elastic Defend Alert from GenAI Utility or Descendant Critical Elastic TOML
Elastic Defend Alert from Package Manager Install Ancestry Critical Elastic TOML
Command Execution via SolarWinds Process Medium Elastic TOML
Execution via GitHub Actions Runner Medium Elastic TOML
GitHub Actions Workflow Modification Blocked Medium Elastic TOML
New GitHub Self Hosted Action Runner Medium Elastic TOML
Remote GitHub Actions Runner Registration Medium Elastic TOML
SolarWinds Process Disabling Services via Registry Medium Elastic TOML
Suspicious Execution from VS Code Extension Medium Elastic TOML
Suspicious SolarWinds Child Process Medium Elastic TOML

+ 5 more from elastic/detection-rules → showing the 10 highest-severity

panther-labs/panther-analysis

15 rules
Detection Severity Format
GitHub Malicious Commit Content High Panther Python
GitHub Malicious Pull Request Content High Panther Python
GitHub pull_request_target Workflow on Self-Hosted Runner High Panther Python
GitHub pull_request_target Workflow Usage High Panther Python
GitHub Sha1-Hulud Malicious Repository Created High Panther Python
GitHub Artifact Download from Cross-Fork Workflow Medium Panther Python
GitHub Commits Skipping Workflows Medium Panther Python
GitHub Malicious Comment/Review Content Medium Panther Python
GitHub Malicious Issue/Pages Content Medium Panther Python
GitHub pull_request_target Workflow with Checkout Action Medium Panther Python

+ 5 more from panther-labs/panther-analysis → showing the 10 highest-severity

splunk/security_content

8 rules
Detection Severity Format
3CX Supply Chain Attack Network Indicators Undefined SPL
Hunting 3CXDesktopApp Software Undefined SPL
Python Network Traffic During Package Build Undefined SPL
Python PTH File Creation During Package Installation Undefined SPL
Python PYTHONPATH Modification During Package Installation Undefined SPL
Python Site Hooks Creation During Package Installation Undefined SPL
Shai-Hulud 2 Exfiltration Artifact Files Undefined SPL
Windows Vulnerable 3CX Software Undefined SPL

elastic/protections-artifacts

3 rules
Detection Severity Format
Egress Network Connection from Default DPKG Directory Undefined Elastic TOML
Egress Network Connection from RPM Package Undefined Elastic TOML
Suspicious Terraform Provider Execution and Network Connection Undefined Elastic TOML

falcosecurity/rules

1 rule
Detection Severity Format
Network Tool Executed During NPM Package Install Medium Falco YAML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.