Compromise Software Supply Chain
Parent: T1195
Description
Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version. Targeting may be specific to a desired victim set or may be distributed to a broad set of consumers but only move on to additional tactics on specific victims. (Citation: MITRE ATT&CK)
Mapped SPARTA techniques
3 techniques
T1195.002 'Compromise Software Supply Chain' is an exact title-and-scope match to IA-0001.02 — both describe altering source before build, swapping signed binaries at distribution edges, and abusing update mechanisms.
T1195.002 'Compromise Software Supply Chain' covers manipulation of update/distribution mechanisms for software, addressing IA-0002's SDR-pipeline manipulation (toolchains, bitstreams, DSP coefficients, in-service update channels). SPACE-SHIELD has no SDR-specific initial-access technique.
T1195.002 'Compromise Software Supply Chain' explicitly covers manipulation of update/distribution mechanisms — exactly the on-orbit update pipeline IA-0007.01 targets (source repos, build packaging, staging, update metadata, transmission).
Cite as SafeMode Space, space-shield T1195.002.