Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0309 — Compromised software/update chain (installer/write → first-run/child → egress/signature anomaly)
DET0309

Compromised software/update chain (installer/write → first-run/child → egress/signature anomaly)

3 analytic(s) · 1 technique(s) detected

Analytics

3
AN0862 Analytic 0862
Windows

Adversary ships a tampered application or update: an updater/installer (msiexec/setup/update.exe/vendor service) writes or replaces binaries; on first run it spawns scripts/shells or unsigned DLLs and beacons to non-approved update CDNs/hosts. Detection correlates: (1) process creation of installer/updater → (2) file metadata changes in program paths → (3) first-run children and module/signature anomalies → (4) outbound connections to unexpected hosts within a short window.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=6 WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=13, 14 WinEventLog:Sysmon EventCode=3, 22 WinEventLog:Microsoft-Windows-CodeIntegrity/Operational Unsigned or invalid image for newly installed/updated binaries NSM:Flow First-time egress to non-approved update hosts right after install/update
[TimeWindow] Correlate write→first-run→egress (default 90 minutes).
[ApprovedUpdateHosts] Allow-list of vendor update endpoints, enterprise proxy/cache.
[ApprovedSigners] Code-signing publishers allowed for programs/services.
[ProgramPaths] Monitored install locations (e.g., C:\Program Files, C:\ProgramData, %LOCALAPPDATA%).
AN0863 Analytic 0863
Linux

A compromised package/update (deb/rpm/tarball/AppImage/vendor updater) is installed, writing/overwriting files in /usr/local/bin, /usr/bin, /opt, or ~/.local; first run executes unexpected shells/curl/wget and connects to unapproved hosts. Correlate package/updater execution → file writes/replace → first-run child processes → egress.

auditd:SYSCALL execve journald:package dpkg/apt/yum/dnf transaction logs; vendor updaters in systemd journals NSM:Flow New outbound flows to non-approved vendor hosts post install
[PathScope] Monitored install paths (/usr/local, /usr/bin, /opt/*, ~/.local/bin, /var/lib/systemd).
[ApprovedRepos] Allow-listed APT/YUM repos and GPG keys for vendor updates.
[TimeWindow] Default 90 minutes.
AN0864 Analytic 0864
macOS

A tampered app/pkg/notarized update is installed via installer, softwareupdated, Homebrew, or vendor updater; new Mach-O or bundle contents appear in /Applications, /Library, /usr/local or /opt/homebrew; first run spawns sh/zsh/osascript/curl and makes egress to unfamiliar domains; AMFI/Gatekeeper may log signature/notarization problems.

macos:unifiedlog pkginstalld/softwareupdated/Homebrew install transactions macos:endpointsecurity exec NSM:Flow New/rare egress to non-approved update hosts after install
[AllowedTeamIDs] Apple Developer Team IDs allowed for enterprise.
[BrewTapsAllowList] Trusted Homebrew taps.
[TimeWindow] Default 90 minutes.

Detected Techniques

1

Details

MITRE ID
DET0309
STIX ID
x-mitre-detection-strategy--77d3b532-9c4f-4f9f-9581-3009b201435d
Analytics
3
Techniques Detected
1
By Tactic
Initial Access
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.