Compliance Node Overview
MITRE ATT&CK T1195.001 (Compromise Software Dependencies and Development Tools) is an Enterprise Initial Access sub-technique of T1195 (Supply Chain Compromise). Adversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise. Applications often depend on external software to function properly. Popular open source projects that are used as dependencies in many applications may be targeted as a means to add malicious code to users of the dependency. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1033 Limit Software Installation, M1016 Vulnerability Scanning, M1051 Update Software, M1013 Application Developer Guidance. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-06, CA-02, CA-07, CM-02, CM-03, CM-05.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1195/001/
SHA-256 integrity: 7c6af850b84ad38d84967b1bdac80fb337c5cb3cfd7425f7a333964266fd1810
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1195.001: Compromise Software Dependencies and Development Tools (https://attack.mitre.org/techniques/T1195/001/)
- MITRE ATT&CK Tactic TA0001: Initial Access (https://attack.mitre.org/tactics/TA0001/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access