Supply Chain Compromise T1195

Tactic: Initial Access

Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.

Events covered

19 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 114 rules share fields, values, and exclusions.

Fields filtered most (86 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
action30eq 25, in 5, starts_with 1completed, audit_log_streaming.update, created, edited, protected_branch.destroy
EventType28eq 19, in 9exec, modification, start, ProcessRollup2, connection_attempted
process_name24eq 14, in 7, starts_with 3, wildcard 2node, 3cxdesktopapp.exe, 7z.exe, 7zfm.exe, 7zg.exe
event.type20eq 20start, change, protocol
sourcetype18eq 18httpevent, github:cloud:audit
Image17ends_with 13, starts_with 3, contains 2/curl, /private/tmp/, /python3, \cmd.exe, \gup.exe
TargetFilename13ends_with 4, eq 4, contains 2, in 2, starts_with 2, wildcard 2/*/.vscode/tasks.json, ?:\*\.vscode\tasks.json, */.github/workflows/*.yaml, */.github/workflows/*.yml, */.github/workflows/discussion.yaml
parent_process_name13in 7, eq 5, wildcard 1node, Runner.Worker, Runner.Listener, bash, bun
Channel12eq 12
host.os.type11eq 9, in 2
process.args11eq 7, in 3, ends_with 1, wildcard 1--install, --json, -i, ., filesystem
CommandLine9contains 9 i , 02-echo@0.0.7, @accordproject/concerto-analysis@3.24.1, "c:\programdata\wt.exe" -w hidden -ep bypass -file, && echo
ParentImage7ends_with 5, contains 1, starts_with 1/node, \node.exe, /bun, /python3, /var/lib/dpkg/info/
data_stream.dataset6eq 6github.audit, endpoint.alerts
vendor_action6eq 6org.disable_two_factor_requirement, protected_branch.destroy, repo.archived, repo.destroy, repository_ruleset.destroy

Top indicator values (1661 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
181078
EventTypeeq
exec
13576
EventTypeeq
connection_attempted
373
sourcetypeeq
httpevent
1212
sourcetypeeq
github:cloud:audit
66
EventTypein
exec
7201
EventTypein
start
7163
EventTypein
ProcessRollup2
3117
process_nameeq
node
525
Imageends_with
/curl
422
Imageends_with
\powershell.exe
3179
actioneq
completed
44
data_stream.dataseteq
github.audit
418
CommandLinecontains
curl
317
CommandLinecontains
i
23
CommandLinecontains
02-echo@0.0.7
22
CommandLinecontains
@accordproject/concerto-analysis@3.24.1
22
CommandLinecontains
@accordproject/concerto-linter-default-ruleset@3.24.1
22
CommandLinecontains
@accordproject/concerto-linter@3.24.1
22
CommandLinecontains
@accordproject/concerto-metamodel@3.12.5
22
CommandLinecontains
@accordproject/concerto-types@3.24.1
22
CommandLinecontains
@accordproject/markdown-it-cicero@0.16.26
22
CommandLinecontains
@accordproject/template-engine@2.7.2
22
actionin
edited
33
parent_process_namein
Runner.Worker
33
process_namein
bash
3202
process_namein
dash
3170
process_namein
fish
3163
process_namein
sh
3197
process_namein
zsh
3196

Exclusions (168 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
dest_ipcidr_match
10.0.0.0/8
3
dest_ipcidr_match
100.64.0.0/10
3
dest_ipcidr_match
127.0.0.0/8
3
dest_ipcidr_match
169.254.0.0/16
3
dest_ipcidr_match
172.16.0.0/12
3
dest_ipcidr_match
192.0.0.0/24
3
dest_ipcidr_match
192.0.2.0/24
3
dest_ipcidr_match
192.168.0.0/16
3
dest_ipcidr_match
192.175.48.0/24
3
dest_ipcidr_match
192.31.196.0/24
3
dest_ipcidr_match
192.52.193.0/24
3
dest_ipcidr_match
192.88.99.0/24
3
dest_ipcidr_match
198.18.0.0/15
3
dest_ipcidr_match
198.51.100.0/24
3
dest_ipcidr_match
203.0.113.0/24
3

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 19 rules

Elastic 34 rules

Splunk 26 rules

Kusto 8 rules

Panther 27 rules