v20260802
hunting-for-supply-chain-compromise
A comprehensive guide for conducting hypothesis-driven threat hunting against supply chain compromises (T1195). This skill focuses on querying SIEM/EDR logs to detect indicators of trojanized software updates, compromised dependencies, unauthorized code modifications, and tampered build artifacts. It is crucial when investigating suspected vendor compromises or scoping a build pipeline breach, requiring advanced knowledge of logging systems and threat intelligence.