Loading interactive filters…
1200KM / detection
T1195 Supply Chain Compromise — Detection Rules
Detection workspace for T1195 Supply Chain Compromise: 1 Sigma sources, 1 Atlas concepts and 1 anomaly models. No live detection validation.
Source-backed rule directory
Atlas deterministic concepts
T1195 Supply Chain Compromise
MATCH(installed_package_hash NOT_IN approved_manifest OR signature_invalid OR publisher NOT_IN approved_publishers) -> ALERT
Anomaly models
Compromised software or update installation — T1195 Supply Chain Compromise
Comparison unit: package, publisher, and installation population.
Expected behavior: approved packages originate from known publishers and produce consistent post-install behavior.
Deviation: novel package-publisher combination or synchronized behavioral shift across many endpoints.
ATT&CK analytic guidance
1) New or updated software is delivered/installed from atypical sources or with signature/hash mismatches; 2) installer/updater writes binaries to unexpected paths or replaces existing signed files; 3) first run causes unsigned/abnormally signed modules to load or child processes to execute, optionally followed by network egress to new destinations.
1) Package manager or curl/wget installs/upgrades from non-approved repos or unsigned packages; 2) new ELF written into PATH directories or replacement of existing binaries/libraries; 3) first run leads to unexpected child processes or outbound connections.
1) pkg/notarization installs from atypical sources or with Gatekeeper/AMFI warnings; 2) new Mach-O written into /Applications or ~/Library paths or substitution of signed components; 3) first run from installer spawns unsigned children or exfil.
Connected ecosystem references
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.