π Overview
Implement a KQL rule to detect anomalous activity originating from third-party supplier accounts, API keys, and integrations. Supply chain compromise is the attack vector behind the M&S 2025 breach and is one of the hardest threats to detect because supplier access is by definition trusted.
π― Acceptance Criteria
π Related
- MITRE Technique: T1195 β Supply Chain Compromise
- Related files:
sentinel/watchlists/retail-ioc-watchlist.csv, docs/threat-model.md
- Dependencies: Azure AD audit logs, third-party API gateway logs in Sentinel
π Resources
π Overview
Implement a KQL rule to detect anomalous activity originating from third-party supplier accounts, API keys, and integrations. Supply chain compromise is the attack vector behind the M&S 2025 breach and is one of the hardest threats to detect because supplier access is by definition trusted.
π― Acceptance Criteria
detection-rules/supply_chain_anomaly.kqlHightests/detection-rules/test_kql_rules.pydocs/mitre-mapping.mddevπ Related
sentinel/watchlists/retail-ioc-watchlist.csv,docs/threat-model.mdπ Resources