Cross-source coverage
T1195.002 / ATT&CK
Supply Chain Compromise: Compromise Software Supply Chain
63 rules across 7 sources.
Showing deprecated rules · back to the default
From MITRE ATT&CK 19.2
Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.
Targeting may be specific to a desired victim set or may be distributed to a broad set of consumers but only move on to additional tactics on specific victims.
- Tactics
- Initial Access
- Platforms
- Linux · Windows · macOS
- Telemetry
-
WinEventLog:SysmonWinEventLog:Microsoft-Windows-CodeIntegrity/OperationalNSM:Flowauditd:SYSCALLjournald:packagemacos:unifiedlogmacos:endpointsecurity
How MITRE says to detect it DET0309
Compromised software/update chain (installer/write → first-run/child → egress/signature anomaly)
Windows Analytic 0862
Adversary ships a tampered application or update: an updater/installer (msiexec/setup/update.exe/vendor service) writes or replaces binaries; on first run it spawns scripts/shells or unsigned DLLs and beacons to non-approved update CDNs/hosts. Detection correlates: (1) process creation of installer/updater → (2) file metadata changes in program paths → (3) first-run children and module/signature anomalies → (4) outbound connections to unexpected hosts within a short window.
WinEventLog:SysmonEventCode=1WinEventLog:SysmonEventCode=6WinEventLog:SysmonEventCode=7WinEventLog:SysmonEventCode=11WinEventLog:SysmonEventCode=13, 14WinEventLog:SysmonEventCode=3, 22WinEventLog:Microsoft-Windows-CodeIntegrity/OperationalUnsigned or invalid image for newly installed/updated binariesNSM:FlowFirst-time egress to non-approved update hosts right after install/update
Linux Analytic 0863
A compromised package/update (deb/rpm/tarball/AppImage/vendor updater) is installed, writing/overwriting files in /usr/local/bin, /usr/bin, /opt, or ~/.local; first run executes unexpected shells/curl/wget and connects to unapproved hosts. Correlate package/updater execution → file writes/replace → first-run child processes → egress.
auditd:SYSCALLexecvejournald:packagedpkg/apt/yum/dnf transaction logs; vendor updaters in systemd journalsNSM:FlowNew outbound flows to non-approved vendor hosts post install
macOS Analytic 0864
A tampered app/pkg/notarized update is installed via installer, softwareupdated, Homebrew, or vendor updater; new Mach-O or bundle contents appear in /Applications, /Library, /usr/local or /opt/homebrew; first run spawns sh/zsh/osascript/curl and makes egress to unfamiliar domains; AMFI/Gatekeeper may log signature/notarization problems.
macos:unifiedlogpkginstalld/softwareupdated/Homebrew install transactionsmacos:endpointsecurityexecNSM:FlowNew/rare egress to non-approved update hosts after install
SigmaHQ/sigma
17 rules| Detection | Severity | Format |
|---|---|---|
| Axios NPM Compromise File Creation Indicators - Linux | High | Sigma |
| Axios NPM Compromise File Creation Indicators - MacOS | High | Sigma |
| Axios NPM Compromise File Creation Indicators - Windows | High | Sigma |
| Axios NPM Compromise Indicators - Linux | High | Sigma |
| Axios NPM Compromise Indicators - macOS | High | Sigma |
| Axios NPM Compromise Indicators - Windows | High | Sigma |
| LiteLLM / TeamPCP Supply Chain Attack Indicators | High | Sigma |
| Shai-Hulud 2.0 Malicious NPM Package Installation | High | Sigma |
| Shai-Hulud 2.0 Malicious NPM Package Installation - Linux | High | Sigma |
| Shai-Hulud Malicious Bun Execution | High | Sigma |
+ 7 more from SigmaHQ/sigma → showing the 10 highest-severity
elastic/detection-rules
16 rules| Detection | Severity | Format |
|---|---|---|
| Elastic Defend Alert from GenAI Utility or Descendant | Critical | Elastic TOML |
| Elastic Defend Alert from Package Manager Install Ancestry | Critical | Elastic TOML |
| Deprecated - SUNBURST Command and Control Activity | High | Elastic TOML |
| Command Execution via SolarWinds Process | Medium | Elastic TOML |
| Execution via GitHub Actions Runner | Medium | Elastic TOML |
| GitHub Actions Workflow Modification Blocked | Medium | Elastic TOML |
| New GitHub Self Hosted Action Runner | Medium | Elastic TOML |
| Remote GitHub Actions Runner Registration | Medium | Elastic TOML |
| SolarWinds Process Disabling Services via Registry | Medium | Elastic TOML |
| Suspicious Execution from VS Code Extension | Medium | Elastic TOML |
+ 6 more from elastic/detection-rules → showing the 10 highest-severity
panther-labs/panther-analysis
15 rules| Detection | Severity | Format |
|---|---|---|
| GitHub Malicious Commit Content | High | Panther Python |
| GitHub Malicious Pull Request Content | High | Panther Python |
| GitHub pull_request_target Workflow on Self-Hosted Runner | High | Panther Python |
| GitHub pull_request_target Workflow Usage | High | Panther Python |
| GitHub Sha1-Hulud Malicious Repository Created | High | Panther Python |
| GitHub Artifact Download from Cross-Fork Workflow | Medium | Panther Python |
| GitHub Commits Skipping Workflows | Medium | Panther Python |
| GitHub Malicious Comment/Review Content | Medium | Panther Python |
| GitHub Malicious Issue/Pages Content | Medium | Panther Python |
| GitHub pull_request_target Workflow with Checkout Action | Medium | Panther Python |
+ 5 more from panther-labs/panther-analysis → showing the 10 highest-severity
splunk/security_content
8 rules| Detection | Severity | Format |
|---|---|---|
| 3CX Supply Chain Attack Network Indicators | Undefined | SPL |
| Hunting 3CXDesktopApp Software | Undefined | SPL |
| Python Network Traffic During Package Build | Undefined | SPL |
| Python PTH File Creation During Package Installation | Undefined | SPL |
| Python PYTHONPATH Modification During Package Installation | Undefined | SPL |
| Python Site Hooks Creation During Package Installation | Undefined | SPL |
| Shai-Hulud 2 Exfiltration Artifact Files | Undefined | SPL |
| Windows Vulnerable 3CX Software | Undefined | SPL |
chronicle/detection-rules
3 rules| Detection | Severity | Format |
|---|---|---|
| potential_solarwinds_mimicking_via_proxy | Undefined | YARA-L |
| unusual_solarwinds_child_process_via_cmdline | Undefined | YARA-L |
| unusual_solarwinds_file_creation_via_filewrite | Undefined | YARA-L |
elastic/protections-artifacts
3 rules| Detection | Severity | Format |
|---|---|---|
| Egress Network Connection from Default DPKG Directory | Undefined | Elastic TOML |
| Egress Network Connection from RPM Package | Undefined | Elastic TOML |
| Suspicious Terraform Provider Execution and Network Connection | Undefined | Elastic TOML |
falcosecurity/rules
1 rule| Detection | Severity | Format |
|---|---|---|
| Network Tool Executed During NPM Package Install | Medium | Falco YAML |