Next best move:Next: Review customer evidence Next: Trusted trojan proof Atlas

MITRE ATT&CK playbook · synthetic replay evidence

Every reviewed technique. Every observable defense.

A fixture-derived index of the ATT&CK instructional leads used by Compromised build trust chain. Tools are defensive instruments; indicators are prerecorded observations, never live telemetry.

SIMULATION — NO LIVE ACTIONS
Techniques
11
Telemetry
22
Defensive tools
07
Analytics
09
Evidence
16
Blind spots
05

11 OF 11 TECHNIQUES · AL-BUILD-TRUST-1.1.0

  1. T1070.004

    Reviewed ATT&CK technique

    Instructional lead

    3

    Indicators

    1

    Tools

    1

    Defenses

    Explode view

    Defensive tools

    • File-integrity monitor

      Transient workspace detection

      Output · Create, write and restore events inside the build workspace

      File integrity · Compile inputs

    Telemetry & indicators

    • 13:00E14File integrity

      Workspace restored to the committed state

      The fixture is removed and the workspace again matches the commit. Post-build inspection of the workspace now shows nothing — the window has closed.

      Build interposition · BLD-WIN-03

    • 15:00E16File integrity

      Short-lived file mutation recorded, not alerted

      File-integrity monitoring recorded create and delete inside the workspace but the workspace path is excluded from alerting. The evidence existed; the rule did not.

      Build interposition · BLD-WIN-03

    • 24:30E28File integrity

      Transient workspace mutation recovered from raw records

      The create/delete pair is still in the raw file-integrity stream even though no alert fired. Retention, not alerting, saved this investigation.

      Investigation · BLD-WIN-03

    Detection coverage

    • D-FIM-TRANSIENT · Transient file mutation in build workspace

      Create/delete pair inside an active job workspace during the compile step.

      blind spot · validated in fixture

    Replay evidence

    • EV-BASE

      Baseline trust chain

      CI orchestrator · verified fixture

      Unlocked at E01

    • EV-CI-JOB

      CI job 88421 record

      CI orchestrator · verified fixture

      Unlocked at E08

    • EV-GIT

      Source-control verification

      Source control · verified fixture

      Unlocked at E09

    • EV-FILEDIFF

      Transient workspace file (inert)

      File integrity · verified fixture

      Unlocked at E12

    • EV-FIM

      File-integrity stream (raw, unalerted)

      File integrity · correlated

      Unlocked at E12

    • EV-BUILDLOG

      Build and test log

      CI orchestrator · verified fixture

      Unlocked at E13

    • EV-HASH

      Reproducibility comparison

      CI orchestrator · verified fixture

      Unlocked at E15

    • EV-PROVENANCE

      Release provenance record

      Release system · unverified

      Unlocked at E15

    • EV-CASE

      Investigator case note

      Release system · correlated

      Unlocked at E29

    Documented adversary profiles · 7

    Exact ATT&CK technique overlap only · public behavior is not replay attribution.

  2. T1071.001

    Reviewed ATT&CK technique

    Instructional lead

    1

    Indicators

    1

    Tools

    1

    Defenses

    Explode view

    Defensive tools

    • Egress proxy telemetry

      Network correlation

      Output · Source host, reserved destination and baseline deviation

      Egress proxy · Build-tier egress

    Telemetry & indicators

    • 22:00E23Egress proxy

      Egress proxy records a first-seen destination from the build tier

      One request to updates.example.net (TEST-NET-2 198.51.100.24) from a host whose baseline destination list contains four entries. First-seen egress from build infrastructure is unusually cheap to detect.

      Downstream signal · BLD-WIN-03

    Detection coverage

    • D-EGRESS-ALLOWLIST · First-seen egress from build infrastructure

      New outbound destination from a host with a small, stable baseline.

      blind spot · not validated

    Replay evidence

    • EV-RECON

      Public technology inventory (fixture)

      Egress proxy · verified fixture

      Unlocked at E02

    • EV-DNS

      Resolver log excerpt

      DNS resolver · verified fixture

      Unlocked at E04

    • EV-PROCTREE

      Process ancestry on BLD-WIN-03

      Endpoint telemetry · verified fixture

      Unlocked at E07

    • EV-CI-JOB

      CI job 88421 record

      CI orchestrator · verified fixture

      Unlocked at E08

    • EV-FILEDIFF

      Transient workspace file (inert)

      File integrity · verified fixture

      Unlocked at E12

    • EV-HASH

      Reproducibility comparison

      CI orchestrator · verified fixture

      Unlocked at E15

    • EV-NET

      Egress proxy record

      Egress proxy · correlated

      Unlocked at E23

    Documented adversary profiles · 4

    Exact ATT&CK technique overlap only · public behavior is not replay attribution.

  3. T1071.004

    Reviewed ATT&CK technique

    Instructional lead

    1

    Indicators

    1

    Tools

    1

    Defenses

    Explode view

    Defensive tools

    • DNS resolver telemetry

      Destination correlation

      Output · First-seen name, source host and observation time

      DNS resolver · Build-tier egress

    Telemetry & indicators

    • 03:00E04DNS resolver

      Resolver log — reserved example domain queried

      A single lookup for updates.example.net appears in the range resolver log. In this fixture it is benign-looking and unremarkable in isolation.

      Reconnaissance · DEV-JUMP-07

    Detection coverage

    • D-DNS-NOVEL · Novel domain resolution from build tier

      First resolution of a domain not in the build tier's baseline.

      blind spot · not validated

    Replay evidence

    • EV-BASE

      Baseline trust chain

      CI orchestrator · verified fixture

      Unlocked at E01

    • EV-DNS

      Resolver log excerpt

      DNS resolver · verified fixture

      Unlocked at E04

    • EV-PROCTREE

      Process ancestry on BLD-WIN-03

      Endpoint telemetry · verified fixture

      Unlocked at E07

    • EV-CI-JOB

      CI job 88421 record

      CI orchestrator · verified fixture

      Unlocked at E08

    • EV-GIT

      Source-control verification

      Source control · verified fixture

      Unlocked at E09

    • EV-FILEDIFF

      Transient workspace file (inert)

      File integrity · verified fixture

      Unlocked at E12

    • EV-BUILDLOG

      Build and test log

      CI orchestrator · verified fixture

      Unlocked at E13

    • EV-HASH

      Reproducibility comparison

      CI orchestrator · verified fixture

      Unlocked at E15

    • EV-PROVENANCE

      Release provenance record

      Release system · unverified

      Unlocked at E15

    • EV-CASE

      Investigator case note

      Release system · correlated

      Unlocked at E29

    Documented adversary profiles · 2

    Exact ATT&CK technique overlap only · public behavior is not replay attribution.

  4. T1078.004

    Reviewed ATT&CK technique

    Instructional lead

    2

    Indicators

    1

    Tools

    1

    Defenses

    Explode view

    Defensive tools

    • Identity audit trail

      Service-account analysis

      Output · Identity, schedule window, source and session time

      Identity · Build-tier identity

    Telemetry & indicators

    • 04:00E05Identity

      Build access — an existing automation session is reused

      The scenario grants the emulation a pre-existing automation session on the build tier. How that session was obtained is deliberately out of scope: this exercise studies what happens after trust is already held.

      Build access · CI-ORCH-01

    • 05:00E06Identity

      Automation identity used outside its schedule

      The automation identity authenticates 43 minutes outside its recorded schedule window. Schedule deviation for non-human identities is a high-value, low-noise signal.

      Build access · CI-ORCH-01

    Detection coverage

    • D-IAM-SESSION · Non-human identity outside schedule

      Automation identity authenticates outside its recorded schedule window.

      expected · validated in fixture

    Replay evidence

    • EV-BASE

      Baseline trust chain

      CI orchestrator · verified fixture

      Unlocked at E01

    • EV-IAM

      Identity events — automation session

      Identity · correlated

      Unlocked at E05

    • EV-CI-JOB

      CI job 88421 record

      CI orchestrator · verified fixture

      Unlocked at E08

    • EV-GIT

      Source-control verification

      Source control · verified fixture

      Unlocked at E09

    • EV-BUILDLOG

      Build and test log

      CI orchestrator · verified fixture

      Unlocked at E13

    • EV-HASH

      Reproducibility comparison

      CI orchestrator · verified fixture

      Unlocked at E15

    • EV-PROVENANCE

      Release provenance record

      Release system · unverified

      Unlocked at E15

    • EV-CASE

      Investigator case note

      Release system · correlated

      Unlocked at E29

    Documented adversary profiles · 3

    Exact ATT&CK technique overlap only · public behavior is not replay attribution.

  5. T1195.002

    Compromise Software Supply Chain

    Initial Access

    8

    Indicators

    3

    Tools

    3

    Defenses

    Explode view

    Defensive tools

    • CI job ledger

      Build correlation

      Output · Job, commit, worker, workspace and build result

      CI orchestrator · Checkout-to-compile integrity

    • Endpoint process telemetry

      Process-tree analysis

      Output · Parent-child ancestry and process lifetime

      Endpoint telemetry · Build-worker execution

    • SLSA provenance verifier

      Release-admission verification

      Output · Commit, job, compile-input attestation and release relationship

      Release system · Producer authority and release approval

    Telemetry & indicators

    • 07:00E08CI orchestrator

      The adversary waits for a legitimate build

      Nothing is forced. The emulation waits for the scheduled build so that every downstream record looks ordinary.

      Build access

    • 10:00E11Endpoint telemetry

      The helper observes the compiler invocation

      The resident helper watches for the expected compiler invocation. Only observation is modelled; no injection, hooking or evasion technique is described or provided.

      Build interposition · BLD-WIN-03

    • 10:30E11ACI orchestrator

      Selectivity check — correct product and expected source version

      Before touching anything, the emulated helper confirms the job is the intended product (Aurora Gateway Agent) at the expected source version (ns-48f2). This selectivity is why such activity is rare, quiet and hard to find by sampling: unmatched builds are left completely alone, so most build records look perfectly normal.

      Build interposition · BLD-WIN-03

    • 14:00E15CI orchestrator

      Produced binary hash differs from the reproducible reference

      Output digest sha256:9f41…c7d2 does not match the reference rebuild digest sha256:2a08…41be for commit ns-48f2. This single comparison is the strongest available integrity signal.

      Build interposition · BLD-WIN-03

    • 16:00E17CI orchestrator

      Trusted release — the ordinary workflow accepts the artifact

      Tests, approval, signing and publication all proceed normally. Nothing in the pipeline is bypassed, which is exactly why the pipeline offers no warning.

      Trusted release

    • 19:00E20Release system

      Provenance record lacks the compile-input attestation

      The release record links commit → job → signature, but no attestation binds the compile inputs actually present on the worker. That gap is the failed trust boundary.

      Trusted release

    • 22:30E24Endpoint telemetry

      Marker string observed in the released artifact inventory

      Artifact inventory scanning reports the inert marker ATTACK_LAB_MARKER_NS_482 inside the signed release. In the real world this is the moment the theory becomes a finding.

      Downstream signal

    • 25:00E29Release system

      Provenance gap documented as the failed boundary

      Case note records the conclusion: the failed trust boundary is the build environment, between checkout and compile. Signature and repository integrity remained intact throughout.

      Investigation

    Detection coverage

    • D-REPRO · Reproducible-build digest comparison

      Independent rebuild digest differs from the released artifact digest.

      expected · validated in fixture

    • D-PROVENANCE · Provenance completeness check

      Release lacks an attestation binding compile inputs to the signed artifact.

      expected · validated in fixture

    • D-ARTIFACT-SCAN · Released-artifact inventory scan

      Unexpected string or component present in a signed release.

      expected · validated in fixture

    Replay evidence

    • EV-BASE

      Baseline trust chain

      CI orchestrator · verified fixture

      Unlocked at E01

    • EV-PROCTREE

      Process ancestry on BLD-WIN-03

      Endpoint telemetry · verified fixture

      Unlocked at E07

    • EV-CI-JOB

      CI job 88421 record

      CI orchestrator · verified fixture

      Unlocked at E08

    • EV-GIT

      Source-control verification

      Source control · verified fixture

      Unlocked at E09

    • EV-FILEDIFF

      Transient workspace file (inert)

      File integrity · verified fixture

      Unlocked at E12

    • EV-FIM

      File-integrity stream (raw, unalerted)

      File integrity · correlated

      Unlocked at E12

    • EV-BUILDLOG

      Build and test log

      CI orchestrator · verified fixture

      Unlocked at E13

    • EV-HASH

      Reproducibility comparison

      CI orchestrator · verified fixture

      Unlocked at E15

    • EV-SIGN

      Signing service record

      Signing service · verified fixture

      Unlocked at E19

    • EV-PROVENANCE

      Release provenance record

      Release system · unverified

      Unlocked at E15

    • EV-RELEASE

      Canary release record (metadata only)

      Release system · verified fixture

      Unlocked at E22

    • EV-CASE

      Investigator case note

      Release system · correlated

      Unlocked at E29

    Documented adversary profiles · 4

    Exact ATT&CK technique overlap only · public behavior is not replay attribution.

  6. T1543

    Reviewed ATT&CK technique

    Instructional lead

    2

    Indicators

    1

    Tools

    1

    Defenses

    Explode view

    Defensive tools

    • Endpoint process telemetry

      Process-tree analysis

      Output · Parent-child ancestry and process lifetime

      Endpoint telemetry · Build-worker execution

    Telemetry & indicators

    • 06:00E07Endpoint telemetry

      Unexpected child process under the build agent

      Process ancestry shows a monitoring helper started by the build agent rather than by the host service manager. Ancestry, not name, is what makes this visible.

      Build access · BLD-WIN-03

    • 24:00E27Endpoint telemetry

      Process ancestry correlates to the build window

      The helper's lifetime brackets the compile step of job 88421 exactly. Correlating ancestry to job timing converts two weak signals into one strong one.

      Investigation · BLD-WIN-03

    Detection coverage

    • D-EDR-ANCESTRY · Build-agent process ancestry deviation

      Long-lived helper process started by the build agent rather than the service manager.

      expected · validated in fixture

    Replay evidence

    • EV-BASE

      Baseline trust chain

      CI orchestrator · verified fixture

      Unlocked at E01

    • EV-PROCTREE

      Process ancestry on BLD-WIN-03

      Endpoint telemetry · verified fixture

      Unlocked at E07

    • EV-CI-JOB

      CI job 88421 record

      CI orchestrator · verified fixture

      Unlocked at E08

    • EV-GIT

      Source-control verification

      Source control · verified fixture

      Unlocked at E09

    • EV-FILEDIFF

      Transient workspace file (inert)

      File integrity · verified fixture

      Unlocked at E12

    • EV-BUILDLOG

      Build and test log

      CI orchestrator · verified fixture

      Unlocked at E13

    • EV-HASH

      Reproducibility comparison

      CI orchestrator · verified fixture

      Unlocked at E15

    • EV-PROVENANCE

      Release provenance record

      Release system · unverified

      Unlocked at E15

    • EV-CASE

      Investigator case note

      Release system · correlated

      Unlocked at E29

    Documented adversary profiles · 0

    Exact ATT&CK technique overlap only · public behavior is not replay attribution.

    No exact overlap exists among the eight reviewed profiles. No actor association is inferred.
  7. T1554

    Reviewed ATT&CK technique

    Instructional lead

    1

    Indicators

    1

    Tools

    0

    Defenses

    Explode view

    Defensive tools

    • Endpoint process telemetry

      Process-tree analysis

      Output · Parent-child ancestry and process lifetime

      Endpoint telemetry · Build-worker execution

    Telemetry & indicators

    • 10:00E11Endpoint telemetry

      The helper observes the compiler invocation

      The resident helper watches for the expected compiler invocation. Only observation is modelled; no injection, hooking or evasion technique is described or provided.

      Build interposition · BLD-WIN-03

    Detection coverage

    No reviewed analytic is mapped. This remains a defensive coverage gap.

    Replay evidence

    • EV-BASE

      Baseline trust chain

      CI orchestrator · verified fixture

      Unlocked at E01

    • EV-PROCTREE

      Process ancestry on BLD-WIN-03

      Endpoint telemetry · verified fixture

      Unlocked at E07

    • EV-CI-JOB

      CI job 88421 record

      CI orchestrator · verified fixture

      Unlocked at E08

    • EV-GIT

      Source-control verification

      Source control · verified fixture

      Unlocked at E09

    • EV-FILEDIFF

      Transient workspace file (inert)

      File integrity · verified fixture

      Unlocked at E12

    • EV-FIM

      File-integrity stream (raw, unalerted)

      File integrity · correlated

      Unlocked at E12

    • EV-BUILDLOG

      Build and test log

      CI orchestrator · verified fixture

      Unlocked at E13

    • EV-HASH

      Reproducibility comparison

      CI orchestrator · verified fixture

      Unlocked at E15

    • EV-PROVENANCE

      Release provenance record

      Release system · unverified

      Unlocked at E15

    • EV-CASE

      Investigator case note

      Release system · correlated

      Unlocked at E29

    Documented adversary profiles · 1

    Exact ATT&CK technique overlap only · public behavior is not replay attribution.

  8. T1565.001

    Reviewed ATT&CK technique

    Instructional lead

    1

    Indicators

    1

    Tools

    1

    Defenses

    Explode view

    Defensive tools

    • File-integrity monitor

      Transient workspace detection

      Output · Create, write and restore events inside the build workspace

      File integrity · Compile inputs

    Telemetry & indicators

    • 11:00E12File integrity

      Harmless source fixture staged into the temporary workspace

      A harmless fixture file is written into the temporary workspace. Its only content is the inert marker ATTACK_LAB_MARKER_NS_482. It exists for 41 seconds.

      Build interposition · BLD-WIN-03

    Detection coverage

    • D-FIM-TRANSIENT · Transient file mutation in build workspace

      Create/delete pair inside an active job workspace during the compile step.

      blind spot · validated in fixture

    Replay evidence

    • EV-BASE

      Baseline trust chain

      CI orchestrator · verified fixture

      Unlocked at E01

    • EV-CI-JOB

      CI job 88421 record

      CI orchestrator · verified fixture

      Unlocked at E08

    • EV-GIT

      Source-control verification

      Source control · verified fixture

      Unlocked at E09

    • EV-FILEDIFF

      Transient workspace file (inert)

      File integrity · verified fixture

      Unlocked at E12

    • EV-FIM

      File-integrity stream (raw, unalerted)

      File integrity · correlated

      Unlocked at E12

    • EV-BUILDLOG

      Build and test log

      CI orchestrator · verified fixture

      Unlocked at E13

    • EV-HASH

      Reproducibility comparison

      CI orchestrator · verified fixture

      Unlocked at E15

    • EV-PROVENANCE

      Release provenance record

      Release system · unverified

      Unlocked at E15

    • EV-CASE

      Investigator case note

      Release system · correlated

      Unlocked at E29

    Documented adversary profiles · 0

    Exact ATT&CK technique overlap only · public behavior is not replay attribution.

    No exact overlap exists among the eight reviewed profiles. No actor association is inferred.
  9. T1591

    Reviewed ATT&CK technique

    Instructional lead

    1

    Indicators

    1

    Tools

    0

    Defenses

    Explode view

    Defensive tools

    • Egress proxy telemetry

      Network correlation

      Output · Source host, reserved destination and baseline deviation

      Egress proxy · Build-tier egress

    Telemetry & indicators

    • 01:00E02Egress proxy

      Reconnaissance — reasoning about the environment, no intrusion

      The emulated adversary reads the vendor's public technology inventory. No intrusion step is modelled or described.

      Reconnaissance

    Detection coverage

    No reviewed analytic is mapped. This remains a defensive coverage gap.

    Replay evidence

    • EV-RECON

      Public technology inventory (fixture)

      Egress proxy · verified fixture

      Unlocked at E02

    Documented adversary profiles · 3

    Exact ATT&CK technique overlap only · public behavior is not replay attribution.

  10. T1591.002

    Reviewed ATT&CK technique

    Instructional lead

    1

    Indicators

    1

    Tools

    1

    Defenses

    Explode view

    Defensive tools

    • Egress proxy telemetry

      Network correlation

      Output · Source host, reserved destination and baseline deviation

      Egress proxy · Build-tier egress

    Telemetry & indicators

    • 02:00E03Egress proxy

      Release cadence is public

      Published release notes disclose a predictable weekly gateway-agent release and the name of the build toolchain. Public information alone narrows where trust is concentrated.

      Reconnaissance

    Detection coverage

    • D-BLIND-RECON · Public disclosure of toolchain and cadence

      Release notes disclose predictable timing and build technology.

      blind spot · not validated

    Replay evidence

    • EV-RECON

      Public technology inventory (fixture)

      Egress proxy · verified fixture

      Unlocked at E02

    • EV-DNS

      Resolver log excerpt

      DNS resolver · verified fixture

      Unlocked at E04

    • EV-NET

      Egress proxy record

      Egress proxy · correlated

      Unlocked at E23

    Documented adversary profiles · 2

    Exact ATT&CK technique overlap only · public behavior is not replay attribution.

  11. T1596

    Reviewed ATT&CK technique

    Instructional lead

    1

    Indicators

    1

    Tools

    0

    Defenses

    Explode view

    Defensive tools

    • Egress proxy telemetry

      Network correlation

      Output · Source host, reserved destination and baseline deviation

      Egress proxy · Build-tier egress

    Telemetry & indicators

    • 01:00E02Egress proxy

      Reconnaissance — reasoning about the environment, no intrusion

      The emulated adversary reads the vendor's public technology inventory. No intrusion step is modelled or described.

      Reconnaissance

    Detection coverage

    No reviewed analytic is mapped. This remains a defensive coverage gap.

    Replay evidence

    • EV-RECON

      Public technology inventory (fixture)

      Egress proxy · verified fixture

      Unlocked at E02

    Documented adversary profiles · 1

    Exact ATT&CK technique overlap only · public behavior is not replay attribution.