// MITRE ATT&CK
T1195 · Supply Chain Compromise
Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise can take place at any stage of the supply chain including: * Manipulation of development tools * Manipulation of a developme...
How to detect & mitigate it
Detecting Supply Chain Compromise starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Sub-techniques (3)
T1195.001
Compromise Software Dependencies and Development Tools T1195.002
Compromise Software Supply Chain T1195.003
Compromise Hardware Supply Chain
Compromise Software Dependencies and Development Tools T1195.002
Compromise Software Supply Chain T1195.003
Compromise Hardware Supply Chain
Related techniques
T1195.001
Compromise Software Dependencies and Development Tools T1566.002
Spearphishing Link T1566.001
Spearphishing Attachment T1195.003
Compromise Hardware Supply Chain T1190
Exploit Public-Facing Application T1659
Content Injection T1199
Trusted Relationship T1566
Phishing
Compromise Software Dependencies and Development Tools T1566.002
Spearphishing Link T1566.001
Spearphishing Attachment T1195.003
Compromise Hardware Supply Chain T1190
Exploit Public-Facing Application T1659
Content Injection T1199
Trusted Relationship T1566
Phishing
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.