Supply Chain Compromise T1195

Tactic: Initial Access

Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.

Events covered

19 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 119 rules share fields, values, and exclusions.

Fields filtered most (87 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
action33eq 28, in 5, starts_with 1completed, created, audit_log_streaming.update, edited, protected_branch.destroy
EventType30eq 19, in 11exec, start, modification, ProcessRollup2, connection_attempted
process_name25eq 15, in 7, starts_with 3, wildcard 2node, 3cxdesktopapp.exe, 7z.exe, 7zfm.exe, 7zg.exe
event.type21eq 21start, change
sourcetype18eq 18httpevent, github:cloud:audit
Image17ends_with 13, starts_with 3, contains 2/curl, /private/tmp/, /python3, \cmd.exe, \gup.exe
parent_process_name15eq 7, in 7, wildcard 1bun, bun.exe, node, Runner.Worker, Runner.Listener
CommandLine14contains 12, wildcard 2, ne 1 i , install , *az account get-access-token*, *gcloud config config-helper --format json*, *gh auth token*
TargetFilename14ends_with 4, eq 4, contains 3, in 3, starts_with 2, wildcard 2/*/.vscode/tasks.json, ?:\*\.vscode\tasks.json, */.github/workflows/*.yaml, */.github/workflows/*.yml, */.github/workflows/discussion.yaml
Channel12eq 12
process.args11eq 7, in 3, ends_with 1, wildcard 1--install, --json, -i, ., filesystem
host.os.type10eq 8, in 2
ParentImage7ends_with 5, contains 1, starts_with 1/node, \node.exe, /bun, /python3, /var/lib/dpkg/info/
EventID6eq 3, in 31, 11, 13, 3, 4688
ParentCommandLine6contains 2, ends_with 2, wildcard 2, is_not_null 1.js, .mjs, .ts, init, *extensionHost*

Top indicator values (1671 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
201087
EventTypeeq
exec
13579
EventTypeeq
connection_attempted
375
sourcetypeeq
httpevent
1212
sourcetypeeq
github:cloud:audit
66
EventTypein
exec
9206
EventTypein
start
9168
EventTypein
ProcessRollup2
3118
process_nameeq
node
525
Imageends_with
/curl
422
Imageends_with
\powershell.exe
3181
actioneq
completed
44
actioneq
created
34
data_stream.dataseteq
github.audit
418
CommandLinecontains
curl
317
CommandLinecontains
i
23
CommandLinecontains
install
22
CommandLinecontains
02-echo@0.0.7
22
CommandLinecontains
@accordproject/concerto-analysis@3.24.1
22
CommandLinecontains
@accordproject/concerto-linter-default-ruleset@3.24.1
22
CommandLinecontains
@accordproject/concerto-linter@3.24.1
22
EventIDin
1
34
actionin
edited
33
dc_event_idgt
1
33
parent_process_namein
Runner.Worker
33
process_namein
bash
3202
process_namein
dash
3170
process_namein
fish
3163
process_namein
sh
3197
process_namein
zsh
3196

Exclusions (170 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
dest_ipcidr_match
10.0.0.0/8
3
dest_ipcidr_match
100.64.0.0/10
3
dest_ipcidr_match
127.0.0.0/8
3
dest_ipcidr_match
169.254.0.0/16
3
dest_ipcidr_match
172.16.0.0/12
3
dest_ipcidr_match
192.0.0.0/24
3
dest_ipcidr_match
192.0.2.0/24
3
dest_ipcidr_match
192.168.0.0/16
3
dest_ipcidr_match
192.175.48.0/24
3
dest_ipcidr_match
192.31.196.0/24
3
dest_ipcidr_match
192.52.193.0/24
3
dest_ipcidr_match
192.88.99.0/24
3
dest_ipcidr_match
198.18.0.0/15
3
dest_ipcidr_match
198.51.100.0/24
3
dest_ipcidr_match
203.0.113.0/24
3

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 19 rules

Elastic 35 rules

Splunk 30 rules

Kusto 8 rules

Panther 27 rules