Compliance Node Overview
MITRE ATT&CK T1195 (Supply Chain Compromise) is an Enterprise Initial Access technique. Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise can take place at any stage of the supply chain including: * Manipulation of development tools * Manipulation of a development environment * Manipulation of source code repositories (public or private) * Manipulation of source code in open-source dependencies * Manipulation of software update/distribution mechanisms * Compromised/infected. ATT&CK documents 3 sub-techniques: T1195.001 Compromise Software Dependencies and Development Tools; T1195.002 Compromise Software Supply Chain; T1195.003 Compromise Hardware Supply Chain. Affected platforms: Linux, Windows, macOS. MITRE-documented mitigations include M1046 Boot Integrity, M1013 Application Developer Guidance, M1051 Update Software, M1018 User Account Management, M1016 Vulnerability Scanning, M1033 Limit Software Installation. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-06, CA-02, CA-07, CM-02, CM-03, CM-05.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1195/
SHA-256 integrity: 2c4aad2124e91136c36e95f0bec14e2ae8fa66fbfc0a79fe5894e6ff10e5e21b
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1195: Supply Chain Compromise (https://attack.mitre.org/techniques/T1195/) with 3 sub-techniques
- MITRE ATT&CK Tactic TA0001: Initial Access (https://attack.mitre.org/tactics/TA0001/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access