1200KM / detection
T1195.002 Compromise Software Supply Chain — Detection Rules
Detection workspace for T1195.002 Compromise Software Supply Chain: 3 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Notepad++ Updater DNS Query to Uncommon Domains · experimental · medium · {"category":"dns_query","product":"windows"}
- Uncommon File Created by Notepad++ Updater Gup.EXE · experimental · high · {"category":"file_event","product":"windows"}
- Suspicious Child Process of Notepad++ Updater - GUP.Exe · experimental · high · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0309 Compromised software/update chain (installer/write → first-run/child → egress/signature anomaly)
AN0862 Analytic 0862
Adversary ships a tampered application or update: an updater/installer (msiexec/setup/update.exe/vendor service) writes or replaces binaries; on first run it spawns scripts/shells or unsigned DLLs and beacons to non-approved update CDNs/hosts. Detection correlates: (1) process creation of installer/updater → (2) file metadata changes in program paths → (3) first-run children and module/signature anomalies → (4) outbound connections to unexpected hosts within a short window.
AN0863 Analytic 0863
A compromised package/update (deb/rpm/tarball/AppImage/vendor updater) is installed, writing/overwriting files in /usr/local/bin, /usr/bin, /opt, or ~/.local; first run executes unexpected shells/curl/wget and connects to unapproved hosts. Correlate package/updater execution → file writes/replace → first-run child processes → egress.
AN0864 Analytic 0864
A tampered app/pkg/notarized update is installed via installer, softwareupdated, Homebrew, or vendor updater; new Mach-O or bundle contents appear in /Applications, /Library, /usr/local or /opt/homebrew; first run spawns sh/zsh/osascript/curl and makes egress to unfamiliar domains; AMFI/Gatekeeper may log signature/notarization problems.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1195.002 simulation workspace
- Driver Load · DC0079
- File Creation · DC0039
- File Metadata · DC0059
- Module Load · DC0016
- Network Connection Creation · DC0082
- Network Traffic Flow · DC0078
- Process Creation · DC0032
- Windows Registry Key Modification · DC0063
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.