MITRE ATT&CK playbook · synthetic replay evidence
Every reviewed technique. Every observable defense.
A fixture-derived index of the ATT&CK instructional leads used by Compromised build trust chain. Tools are defensive instruments; indicators are prerecorded observations, never live telemetry.
- Techniques
- 11
- Telemetry
- 22
- Defensive tools
- 07
- Analytics
- 09
- Evidence
- 16
- Blind spots
- 05
11 OF 11 TECHNIQUES · AL-BUILD-TRUST-1.1.0
T1070.004
Reviewed ATT&CK technique
Instructional lead
Explode viewCollapse3
Indicators
1
Tools
1
Defenses
Defensive tools
File-integrity monitor
Transient workspace detection
Output · Create, write and restore events inside the build workspace
File integrity · Compile inputs
Telemetry & indicators
- 13:00E14File integrity
Workspace restored to the committed state
The fixture is removed and the workspace again matches the commit. Post-build inspection of the workspace now shows nothing — the window has closed.
Build interposition · BLD-WIN-03
- 15:00E16File integrity
Short-lived file mutation recorded, not alerted
File-integrity monitoring recorded create and delete inside the workspace but the workspace path is excluded from alerting. The evidence existed; the rule did not.
Build interposition · BLD-WIN-03
- 24:30E28File integrity
Transient workspace mutation recovered from raw records
The create/delete pair is still in the raw file-integrity stream even though no alert fired. Retention, not alerting, saved this investigation.
Investigation · BLD-WIN-03
Detection coverage
D-FIM-TRANSIENT · Transient file mutation in build workspace
Create/delete pair inside an active job workspace during the compile step.
blind spot · validated in fixture
Replay evidence
EV-BASE
Baseline trust chain
CI orchestrator · verified fixture
Unlocked at E01
EV-CI-JOB
CI job 88421 record
CI orchestrator · verified fixture
Unlocked at E08
EV-GIT
Source-control verification
Source control · verified fixture
Unlocked at E09
EV-FILEDIFF
Transient workspace file (inert)
File integrity · verified fixture
Unlocked at E12
EV-FIM
File-integrity stream (raw, unalerted)
File integrity · correlated
Unlocked at E12
EV-BUILDLOG
Build and test log
CI orchestrator · verified fixture
Unlocked at E13
EV-HASH
Reproducibility comparison
CI orchestrator · verified fixture
Unlocked at E15
EV-PROVENANCE
Release provenance record
Release system · unverified
Unlocked at E15
EV-CASE
Investigator case note
Release system · correlated
Unlocked at E29
Documented adversary profiles · 7
Exact ATT&CK technique overlap only · public behavior is not replay attribution.
G0096APT41ATT&CK reports deletion of files from systems during documented operations.G0035DragonflyATT&CK reports deletion of applications, screenshots, and other operational files during cleanup.G0034Sandworm TeamATT&CK reports backdoors capable of deleting files used during an operation.G1023APT5ATT&CK reports deletion of scripts and web shells to evade detection.G0016APT29ATT&CK reports removal of operational artifacts from victim networks.G0007APT28ATT&CK reports intentional deletion of computer files to cover operational tracks.G0032Lazarus GroupATT&CK reports deletion of files and operational artifacts during documented activity.T1071.001
Reviewed ATT&CK technique
Instructional lead
Explode viewCollapse1
Indicators
1
Tools
1
Defenses
Defensive tools
Egress proxy telemetry
Network correlation
Output · Source host, reserved destination and baseline deviation
Egress proxy · Build-tier egress
Telemetry & indicators
- 22:00E23Egress proxy
Egress proxy records a first-seen destination from the build tier
One request to updates.example.net (TEST-NET-2 198.51.100.24) from a host whose baseline destination list contains four entries. First-seen egress from build infrastructure is unusually cheap to detect.
Downstream signal · BLD-WIN-03
Detection coverage
D-EGRESS-ALLOWLIST · First-seen egress from build infrastructure
New outbound destination from a host with a small, stable baseline.
blind spot · not validated
Replay evidence
EV-RECON
Public technology inventory (fixture)
Egress proxy · verified fixture
Unlocked at E02
EV-DNS
Resolver log excerpt
DNS resolver · verified fixture
Unlocked at E04
EV-PROCTREE
Process ancestry on BLD-WIN-03
Endpoint telemetry · verified fixture
Unlocked at E07
EV-CI-JOB
CI job 88421 record
CI orchestrator · verified fixture
Unlocked at E08
EV-FILEDIFF
Transient workspace file (inert)
File integrity · verified fixture
Unlocked at E12
EV-HASH
Reproducibility comparison
CI orchestrator · verified fixture
Unlocked at E15
EV-NET
Egress proxy record
Egress proxy · correlated
Unlocked at E23
Documented adversary profiles · 4
Exact ATT&CK technique overlap only · public behavior is not replay attribution.
G0096APT41ATT&CK reports HTTP use to retrieve payloads during documented exploitation activity.G0034Sandworm TeamATT&CK reports an identified tool connecting to designated command infrastructure over HTTP.G0007APT28ATT&CK reports implants using HTTP and HTTPS among configured command channels.G0032Lazarus GroupATT&CK reports command-and-control communications over HTTP and HTTPS.T1071.004
Reviewed ATT&CK technique
Instructional lead
Explode viewCollapse1
Indicators
1
Tools
1
Defenses
Defensive tools
DNS resolver telemetry
Destination correlation
Output · First-seen name, source host and observation time
DNS resolver · Build-tier egress
Telemetry & indicators
- 03:00E04DNS resolver
Resolver log — reserved example domain queried
A single lookup for updates.example.net appears in the range resolver log. In this fixture it is benign-looking and unremarkable in isolation.
Reconnaissance · DEV-JUMP-07
Detection coverage
D-DNS-NOVEL · Novel domain resolution from build tier
First resolution of a domain not in the build tier's baseline.
blind spot · not validated
Replay evidence
EV-BASE
Baseline trust chain
CI orchestrator · verified fixture
Unlocked at E01
EV-DNS
Resolver log excerpt
DNS resolver · verified fixture
Unlocked at E04
EV-PROCTREE
Process ancestry on BLD-WIN-03
Endpoint telemetry · verified fixture
Unlocked at E07
EV-CI-JOB
CI job 88421 record
CI orchestrator · verified fixture
Unlocked at E08
EV-GIT
Source-control verification
Source control · verified fixture
Unlocked at E09
EV-FILEDIFF
Transient workspace file (inert)
File integrity · verified fixture
Unlocked at E12
EV-BUILDLOG
Build and test log
CI orchestrator · verified fixture
Unlocked at E13
EV-HASH
Reproducibility comparison
CI orchestrator · verified fixture
Unlocked at E15
EV-PROVENANCE
Release provenance record
Release system · unverified
Unlocked at E15
EV-CASE
Investigator case note
Release system · correlated
Unlocked at E29
Documented adversary profiles · 2
Exact ATT&CK technique overlap only · public behavior is not replay attribution.
T1078.004
Reviewed ATT&CK technique
Instructional lead
Explode viewCollapse2
Indicators
1
Tools
1
Defenses
Defensive tools
Identity audit trail
Service-account analysis
Output · Identity, schedule window, source and session time
Identity · Build-tier identity
Telemetry & indicators
- 04:00E05Identity
Build access — an existing automation session is reused
The scenario grants the emulation a pre-existing automation session on the build tier. How that session was obtained is deliberately out of scope: this exercise studies what happens after trust is already held.
Build access · CI-ORCH-01
- 05:00E06Identity
Automation identity used outside its schedule
The automation identity authenticates 43 minutes outside its recorded schedule window. Schedule deviation for non-human identities is a high-value, low-noise signal.
Build access · CI-ORCH-01
Detection coverage
D-IAM-SESSION · Non-human identity outside schedule
Automation identity authenticates outside its recorded schedule window.
expected · validated in fixture
Replay evidence
EV-BASE
Baseline trust chain
CI orchestrator · verified fixture
Unlocked at E01
EV-IAM
Identity events — automation session
Identity · correlated
Unlocked at E05
EV-CI-JOB
CI job 88421 record
CI orchestrator · verified fixture
Unlocked at E08
EV-GIT
Source-control verification
Source control · verified fixture
Unlocked at E09
EV-BUILDLOG
Build and test log
CI orchestrator · verified fixture
Unlocked at E13
EV-HASH
Reproducibility comparison
CI orchestrator · verified fixture
Unlocked at E15
EV-PROVENANCE
Release provenance record
Release system · unverified
Unlocked at E15
EV-CASE
Investigator case note
Release system · correlated
Unlocked at E29
Documented adversary profiles · 3
Exact ATT&CK technique overlap only · public behavior is not replay attribution.
T1195.002
Compromise Software Supply Chain
Initial Access
Explode viewCollapse8
Indicators
3
Tools
3
Defenses
Defensive tools
CI job ledger
Build correlation
Output · Job, commit, worker, workspace and build result
CI orchestrator · Checkout-to-compile integrity
Endpoint process telemetry
Process-tree analysis
Output · Parent-child ancestry and process lifetime
Endpoint telemetry · Build-worker execution
SLSA provenance verifier
Release-admission verification
Output · Commit, job, compile-input attestation and release relationship
Release system · Producer authority and release approval
Telemetry & indicators
- 07:00E08CI orchestrator
The adversary waits for a legitimate build
Nothing is forced. The emulation waits for the scheduled build so that every downstream record looks ordinary.
Build access
- 10:00E11Endpoint telemetry
The helper observes the compiler invocation
The resident helper watches for the expected compiler invocation. Only observation is modelled; no injection, hooking or evasion technique is described or provided.
Build interposition · BLD-WIN-03
- 10:30E11ACI orchestrator
Selectivity check — correct product and expected source version
Before touching anything, the emulated helper confirms the job is the intended product (Aurora Gateway Agent) at the expected source version (ns-48f2). This selectivity is why such activity is rare, quiet and hard to find by sampling: unmatched builds are left completely alone, so most build records look perfectly normal.
Build interposition · BLD-WIN-03
- 14:00E15CI orchestrator
Produced binary hash differs from the reproducible reference
Output digest sha256:9f41…c7d2 does not match the reference rebuild digest sha256:2a08…41be for commit ns-48f2. This single comparison is the strongest available integrity signal.
Build interposition · BLD-WIN-03
- 16:00E17CI orchestrator
Trusted release — the ordinary workflow accepts the artifact
Tests, approval, signing and publication all proceed normally. Nothing in the pipeline is bypassed, which is exactly why the pipeline offers no warning.
Trusted release
- 19:00E20Release system
Provenance record lacks the compile-input attestation
The release record links commit → job → signature, but no attestation binds the compile inputs actually present on the worker. That gap is the failed trust boundary.
Trusted release
- 22:30E24Endpoint telemetry
Marker string observed in the released artifact inventory
Artifact inventory scanning reports the inert marker ATTACK_LAB_MARKER_NS_482 inside the signed release. In the real world this is the moment the theory becomes a finding.
Downstream signal
- 25:00E29Release system
Provenance gap documented as the failed boundary
Case note records the conclusion: the failed trust boundary is the build environment, between checkout and compile. Signature and repository integrity remained intact throughout.
Investigation
Detection coverage
D-REPRO · Reproducible-build digest comparison
Independent rebuild digest differs from the released artifact digest.
expected · validated in fixture
D-PROVENANCE · Provenance completeness check
Release lacks an attestation binding compile inputs to the signed artifact.
expected · validated in fixture
D-ARTIFACT-SCAN · Released-artifact inventory scan
Unexpected string or component present in a signed release.
expected · validated in fixture
Replay evidence
EV-BASE
Baseline trust chain
CI orchestrator · verified fixture
Unlocked at E01
EV-PROCTREE
Process ancestry on BLD-WIN-03
Endpoint telemetry · verified fixture
Unlocked at E07
EV-CI-JOB
CI job 88421 record
CI orchestrator · verified fixture
Unlocked at E08
EV-GIT
Source-control verification
Source control · verified fixture
Unlocked at E09
EV-FILEDIFF
Transient workspace file (inert)
File integrity · verified fixture
Unlocked at E12
EV-FIM
File-integrity stream (raw, unalerted)
File integrity · correlated
Unlocked at E12
EV-BUILDLOG
Build and test log
CI orchestrator · verified fixture
Unlocked at E13
EV-HASH
Reproducibility comparison
CI orchestrator · verified fixture
Unlocked at E15
EV-SIGN
Signing service record
Signing service · verified fixture
Unlocked at E19
EV-PROVENANCE
Release provenance record
Release system · unverified
Unlocked at E15
EV-RELEASE
Canary release record (metadata only)
Release system · verified fixture
Unlocked at E22
EV-CASE
Investigator case note
Release system · correlated
Unlocked at E29
Documented adversary profiles · 4
Exact ATT&CK technique overlap only · public behavior is not replay attribution.
G0096APT41ATT&CK reports access to production environments where code was inserted into legitimate signed files for distribution.G0035DragonflyATT&CK reports trojanized control-system software installers placed on legitimate vendor distribution sites.G0046FIN7ATT&CK reports initial access through compromise of a victim's software supply chain.G0034Sandworm TeamATT&CK reports replacement of a legitimate M.E.Doc software update with a malicious update.T1543
Reviewed ATT&CK technique
Instructional lead
Explode viewCollapse2
Indicators
1
Tools
1
Defenses
Defensive tools
Endpoint process telemetry
Process-tree analysis
Output · Parent-child ancestry and process lifetime
Endpoint telemetry · Build-worker execution
Telemetry & indicators
- 06:00E07Endpoint telemetry
Unexpected child process under the build agent
Process ancestry shows a monitoring helper started by the build agent rather than by the host service manager. Ancestry, not name, is what makes this visible.
Build access · BLD-WIN-03
- 24:00E27Endpoint telemetry
Process ancestry correlates to the build window
The helper's lifetime brackets the compile step of job 88421 exactly. Correlating ancestry to job timing converts two weak signals into one strong one.
Investigation · BLD-WIN-03
Detection coverage
D-EDR-ANCESTRY · Build-agent process ancestry deviation
Long-lived helper process started by the build agent rather than the service manager.
expected · validated in fixture
Replay evidence
EV-BASE
Baseline trust chain
CI orchestrator · verified fixture
Unlocked at E01
EV-PROCTREE
Process ancestry on BLD-WIN-03
Endpoint telemetry · verified fixture
Unlocked at E07
EV-CI-JOB
CI job 88421 record
CI orchestrator · verified fixture
Unlocked at E08
EV-GIT
Source-control verification
Source control · verified fixture
Unlocked at E09
EV-FILEDIFF
Transient workspace file (inert)
File integrity · verified fixture
Unlocked at E12
EV-BUILDLOG
Build and test log
CI orchestrator · verified fixture
Unlocked at E13
EV-HASH
Reproducibility comparison
CI orchestrator · verified fixture
Unlocked at E15
EV-PROVENANCE
Release provenance record
Release system · unverified
Unlocked at E15
EV-CASE
Investigator case note
Release system · correlated
Unlocked at E29
Documented adversary profiles · 0
Exact ATT&CK technique overlap only · public behavior is not replay attribution.
No exact overlap exists among the eight reviewed profiles. No actor association is inferred.T1554
Reviewed ATT&CK technique
Instructional lead
Explode viewCollapse1
Indicators
1
Tools
0
Defenses
Defensive tools
Endpoint process telemetry
Process-tree analysis
Output · Parent-child ancestry and process lifetime
Endpoint telemetry · Build-worker execution
Telemetry & indicators
- 10:00E11Endpoint telemetry
The helper observes the compiler invocation
The resident helper watches for the expected compiler invocation. Only observation is modelled; no injection, hooking or evasion technique is described or provided.
Build interposition · BLD-WIN-03
Detection coverage
No reviewed analytic is mapped. This remains a defensive coverage gap.
Replay evidence
EV-BASE
Baseline trust chain
CI orchestrator · verified fixture
Unlocked at E01
EV-PROCTREE
Process ancestry on BLD-WIN-03
Endpoint telemetry · verified fixture
Unlocked at E07
EV-CI-JOB
CI job 88421 record
CI orchestrator · verified fixture
Unlocked at E08
EV-GIT
Source-control verification
Source control · verified fixture
Unlocked at E09
EV-FILEDIFF
Transient workspace file (inert)
File integrity · verified fixture
Unlocked at E12
EV-FIM
File-integrity stream (raw, unalerted)
File integrity · correlated
Unlocked at E12
EV-BUILDLOG
Build and test log
CI orchestrator · verified fixture
Unlocked at E13
EV-HASH
Reproducibility comparison
CI orchestrator · verified fixture
Unlocked at E15
EV-PROVENANCE
Release provenance record
Release system · unverified
Unlocked at E15
EV-CASE
Investigator case note
Release system · correlated
Unlocked at E29
Documented adversary profiles · 1
Exact ATT&CK technique overlap only · public behavior is not replay attribution.
T1565.001
Reviewed ATT&CK technique
Instructional lead
Explode viewCollapse1
Indicators
1
Tools
1
Defenses
Defensive tools
File-integrity monitor
Transient workspace detection
Output · Create, write and restore events inside the build workspace
File integrity · Compile inputs
Telemetry & indicators
- 11:00E12File integrity
Harmless source fixture staged into the temporary workspace
A harmless fixture file is written into the temporary workspace. Its only content is the inert marker ATTACK_LAB_MARKER_NS_482. It exists for 41 seconds.
Build interposition · BLD-WIN-03
Detection coverage
D-FIM-TRANSIENT · Transient file mutation in build workspace
Create/delete pair inside an active job workspace during the compile step.
blind spot · validated in fixture
Replay evidence
EV-BASE
Baseline trust chain
CI orchestrator · verified fixture
Unlocked at E01
EV-CI-JOB
CI job 88421 record
CI orchestrator · verified fixture
Unlocked at E08
EV-GIT
Source-control verification
Source control · verified fixture
Unlocked at E09
EV-FILEDIFF
Transient workspace file (inert)
File integrity · verified fixture
Unlocked at E12
EV-FIM
File-integrity stream (raw, unalerted)
File integrity · correlated
Unlocked at E12
EV-BUILDLOG
Build and test log
CI orchestrator · verified fixture
Unlocked at E13
EV-HASH
Reproducibility comparison
CI orchestrator · verified fixture
Unlocked at E15
EV-PROVENANCE
Release provenance record
Release system · unverified
Unlocked at E15
EV-CASE
Investigator case note
Release system · correlated
Unlocked at E29
Documented adversary profiles · 0
Exact ATT&CK technique overlap only · public behavior is not replay attribution.
No exact overlap exists among the eight reviewed profiles. No actor association is inferred.T1591
Reviewed ATT&CK technique
Instructional lead
Explode viewCollapse1
Indicators
1
Tools
0
Defenses
Defensive tools
Egress proxy telemetry
Network correlation
Output · Source host, reserved destination and baseline deviation
Egress proxy · Build-tier egress
Telemetry & indicators
- 01:00E02Egress proxy
Reconnaissance — reasoning about the environment, no intrusion
The emulated adversary reads the vendor's public technology inventory. No intrusion step is modelled or described.
Reconnaissance
Detection coverage
No reviewed analytic is mapped. This remains a defensive coverage gap.
Replay evidence
EV-RECON
Public technology inventory (fixture)
Egress proxy · verified fixture
Unlocked at E02
Documented adversary profiles · 3
Exact ATT&CK technique overlap only · public behavior is not replay attribution.
G0046FIN7ATT&CK reports compiling prospective-victim lists using public business information and revenue criteria.G0007APT28ATT&CK reports gathering public information about an organization's capabilities.G0032Lazarus GroupATT&CK reports studying public organizational information to tailor targeting activity.T1591.002
Reviewed ATT&CK technique
Instructional lead
Explode viewCollapse1
Indicators
1
Tools
1
Defenses
Defensive tools
Egress proxy telemetry
Network correlation
Output · Source host, reserved destination and baseline deviation
Egress proxy · Build-tier egress
Telemetry & indicators
- 02:00E03Egress proxy
Release cadence is public
Published release notes disclose a predictable weekly gateway-agent release and the name of the build toolchain. Public information alone narrows where trust is concentrated.
Reconnaissance
Detection coverage
D-BLIND-RECON · Public disclosure of toolchain and cadence
Release notes disclose predictable timing and build technology.
blind spot · not validated
Replay evidence
EV-RECON
Public technology inventory (fixture)
Egress proxy · verified fixture
Unlocked at E02
EV-DNS
Resolver log excerpt
DNS resolver · verified fixture
Unlocked at E04
EV-NET
Egress proxy record
Egress proxy · correlated
Unlocked at E23
Documented adversary profiles · 2
Exact ATT&CK technique overlap only · public behavior is not replay attribution.
T1596
Reviewed ATT&CK technique
Instructional lead
Explode viewCollapse1
Indicators
1
Tools
0
Defenses
Defensive tools
Egress proxy telemetry
Network correlation
Output · Source host, reserved destination and baseline deviation
Egress proxy · Build-tier egress
Telemetry & indicators
- 01:00E02Egress proxy
Reconnaissance — reasoning about the environment, no intrusion
The emulated adversary reads the vendor's public technology inventory. No intrusion step is modelled or described.
Reconnaissance
Detection coverage
No reviewed analytic is mapped. This remains a defensive coverage gap.
Replay evidence
EV-RECON
Public technology inventory (fixture)
Egress proxy · verified fixture
Unlocked at E02
Documented adversary profiles · 1
Exact ATT&CK technique overlap only · public behavior is not replay attribution.