| name | detecting-supply-chain-attacks-in-ci-cd |
| description | Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets exposure. Uses PyGithub and YAML parsing for automated audit. Use when hardening CI/CD pipelines or investigating compromised build systems.
|
| domain | cybersecurity |
| tags | ["detecting","supply","chain","attacks"] |
| subdomain | security-operations |
| version | 1.0 |
| author | oyi77 |
| license | Apache-2.0 |
| atlas_techniques | ["AML.T0010","AML.T0104"] |
| nist_ai_rmf | ["GOVERN-5.2","MAP-1.6","MANAGE-2.2"] |
| nist_csf | ["DE.CM-01","RS.MA-01","GV.OV-01","DE.AE-02"] |
Detecting Supply Chain Attacks In Ci Cd
Overview
Cybersecurity skill for detecting supply chain attacks in ci cd. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"detecting supply chain attacks in ci cd"
-
"When investigating security incidents that require detecting supply chain attack"
-
"When building detection rules or threat hunting queries for this domain"
-
"When SOC analysts need structured procedures for this analysis type"
-
When investigating security incidents that require detecting supply chain attacks in ci cd
-
When building detection rules or threat hunting queries for this domain
-
When SOC analysts need structured procedures for this analysis type
-
When validating security monitoring coverage for related attack techniques
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Familiarity with security operations concepts and tools
- Access to a test or lab environment for safe execution
- Python 3.8+ with required dependencies installed
- Appropriate authorization for any testing activities
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}