ESA SPACE-SHIELD
T1195.002
enhancement

Compromise Software Supply Chain

Parent: T1195

Description

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version. Targeting may be specific to a desired victim set or may be distributed to a broad set of consumers but only move on to additional tactics on specific victims. (Citation: MITRE ATT&CK)

Mapped SPARTA techniques

3 techniques

  • T1195.002 'Compromise Software Supply Chain' is an exact title-and-scope match to IA-0001.02 — both describe altering source before build, swapping signed binaries at distribution edges, and abusing update mechanisms.

  • T1195.002 'Compromise Software Supply Chain' covers manipulation of update/distribution mechanisms for software, addressing IA-0002's SDR-pipeline manipulation (toolchains, bitstreams, DSP coefficients, in-service update channels). SPACE-SHIELD has no SDR-specific initial-access technique.

  • T1195.002 'Compromise Software Supply Chain' explicitly covers manipulation of update/distribution mechanisms — exactly the on-orbit update pipeline IA-0007.01 targets (source repos, build packaging, staging, update metadata, transmission).

Cite as SafeMode Space, space-shield T1195.002.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.