Build Pipeline Compromise: When the Artifact Is the Payload
An intrusion that never touched production directly. The attacker modified a build agent, and the organisation shipped the backdoor itself through its own signed release channel.
6 records on file
Every published record, searchable by title, technique, tag or record ID, and filterable by category and severity.
6 matching records
6 records
An intrusion that never touched production directly. The attacker modified a build agent, and the organisation shipped the backdoor itself through its own signed release channel.
Adversary-in-the-middle phishing does not defeat MFA by breaking it. It waits until MFA has already succeeded, then takes what MFA produced.
Public buckets are rarely the result of someone choosing "public". They are the result of inherited permissions, broad principals, and policies that outlive their purpose.
When every tool in the intrusion ships with the operating system, signature-based detection has nothing to match. What remains is relationship, context and frequency.
A class of flaw where the vulnerable code is often correct, the input is often authenticated, and the exposure window is set by patch logistics rather than by exploit difficulty.
Five detections, in deployment order, with the telemetry each one needs, the noise it produces, and the tuning required before it earns a place in a queue.