// MITRE ATT&CK

T1195.002 · Compromise Software Supply Chain

🎯 Initial Access LinuxWindowsmacOS Sub-technique

Sub-technique of T1195 · Supply Chain Compromise.

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution me...

How to detect & mitigate it

Detecting Compromise Software Supply Chain starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.