Skip to content
← LibraryTechnique entry
T1195Initial Access

Supply Chain Compromise

Compromise software, hardware, or service providers used by the target.

§ Where this technique fits

T1195 is catalogued under the Initial Access tactic of the offensive-security kill-chain. It appears in 4 approved dossiers in the registry, typically at step 3.3 on average.

Authoritative reference: attack.mitre.org/techniques/T1195/.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    AWS sts:AssumeRole Chain
    C-AWS-ASSUMEROLE-CHAIN · Lateral Movement
    seen 1×
  2. 02
    GitHub Action Tag Mutation
    SUP-ACTION-TAG-MUTATION · Persistence
    seen 1×
  3. 03
    User Execution
    T1204 · Execution
    seen 1×
  4. 04
    Valid Accounts
    T1078 · Initial Access
    seen 1×