// MITRE ATT&CK

T1195.001 · Compromise Software Dependencies and Development Tools

🎯 Initial Access LinuxmacOSWindows Sub-technique

Sub-technique of T1195 · Supply Chain Compromise.

Adversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise. Applications often depend on external software to function properly. Popular open source projects that are used as dependencies in many applicatio...

How to detect & mitigate it

Detecting Compromise Software Dependencies and Development Tools starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.