| name | hunting-for-supply-chain-compromise |
| description | Hunt for supply chain compromise indicators including trojanized software updates, compromised dependencies, unauthorized code modifications, and tampered build artifacts. Use when hunting for supply chain compromise indicators including trojanized software updates,. |
| domain | cybersecurity |
| tags | ["threat-hunting","mitre-attack","supply-chain","initial-access","t1195","proactive-detection"] |
| subdomain | threat-hunting |
| version | 1.0 |
| author | oyi77 |
| license | Apache-2.0 |
| d3fend_techniques | ["Platform Hardening","Restore Object","Restore Software","Software Update","Asset Inventory"] |
| nist_csf | ["DE.CM-01","DE.AE-02","DE.AE-07","ID.RA-05"] |
Hunting For Supply Chain Compromise
Overview
Cybersecurity skill for hunting for supply chain compromise. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"hunting for supply chain compromise"
-
"When proactively hunting for indicators of hunting for supply chain compromise i"
-
"After threat intelligence indicates active campaigns using these techniques"
-
"During incident response to scope compromise related to these techniques"
-
When proactively hunting for indicators of hunting for supply chain compromise in the environment
-
After threat intelligence indicates active campaigns using these techniques
-
During incident response to scope compromise related to these techniques
-
When EDR or SIEM alerts trigger on related indicators
-
During periodic security assessments and purple team exercises
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- EDR platform with process and network telemetry (CrowdStrike, MDE, SentinelOne)
- SIEM with relevant log data ingested (Splunk, Elastic, Sentinel)
- Sysmon deployed with comprehensive configuration
- Windows Security Event Log forwarding enabled
- Threat intelligence feeds for IOC correlation
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) k, v IOC_PATTERNS.items()}