Esc
Compromise Software Dependencies and Development Tools - T1195.001
(ATT&CK® Technique)
Definition
Adversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise. Applications often depend on external software to function properly. Popular open source projects that are used as dependencies in many applications may be targeted as a means to add malicious code to users of the dependency.
D3FEND Inferred Relationships
Browse the D3FEND knowledge graph by clicking on the nodes below.