Search/T1195: Supply Chain Compromise
Technique

T1195: Supply Chain Compromise

Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise can take place at any stage of the supply chain including: Manipulation of development tools Manipulation of a development environment Manipulation of source code repositories (public or private) Manipulation of source code in open-source dependencies Manipulation of software update/distribution mechanisms Compromised/infected system images (removable media infected at the factory) Replacement of legitimate software with modified versions Sales of modified/counterfeit products to legitimate distributors Shipment interdiction While supply chain compromise can impact any component of hardware or software, adversaries…

Connections
5 relationships