MITRE ATT&CK · Enterprise

T1195.002 — Supply Chain Compromise: Compromise Software Supply Chain

Sub-technique of T1195 Supply Chain Compromise

ID
T1195.002
Platforms
Linux, Windows, macOS
Tactics
Initial Access

Description

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Targeting may be specific to a desired victim set or may be distributed to a broad set of consumers but only move on to additional tactics on specific victims.

Detected by EasySIEM

This project's own SigmaHQ-derived detection pipeline tags every compiled rule with the ATT&CK technique(s) it maps to -- if a rule in your install covers this technique, its alerts show up automatically on your own EasySIEM Console's ATT&CK Reference page, no lookup needed. This page exists so a click from there always lands here on easysiem.com, not on attack.mitre.org.

View this technique on the official MITRE ATT&CK site ↗