// MITRE ATT&CK
T1195.003 · Compromise Hardware Supply Chain
Sub-technique of T1195 · Supply Chain Compromise.
Adversaries may manipulate hardware components in products prior to receipt by a final consumer for the purpose of data or system compromise. By modifying hardware or firmware in the supply chain, adversaries can insert a backdoor into consumer networks that may be difficult to detect and give the a...
How to detect & mitigate it
Detecting Compromise Hardware Supply Chain starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Related techniques
T1195.001
Compromise Software Dependencies and Development Tools T1566.002
Spearphishing Link T1566.001
Spearphishing Attachment T1195
Supply Chain Compromise T1190
Exploit Public-Facing Application T1659
Content Injection T1199
Trusted Relationship T1566
Phishing
Compromise Software Dependencies and Development Tools T1566.002
Spearphishing Link T1566.001
Spearphishing Attachment T1195
Supply Chain Compromise T1190
Exploit Public-Facing Application T1659
Content Injection T1199
Trusted Relationship T1566
Phishing
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.