Poisoned Pipeline

Poisoned Pipeline is a blue team lab that falls under the Threat Hunting, Endpoint Forensics categories and will cover the following subjects: Process Explorer, Event Log Explorer, Timeline Explorer, GitHub, Python3, PowerShell, Resource Development, Initial Access, Execution, Persistence, Privilege Escalation, Defense Impairment, Credential Access, Discovery, Lateral Movement, Collection, Exfiltration.

Learning Objectives

Investigate a multi-stage supply-chain intrusion that landed via a poisoned npm dependency and pivoted through CI/CD into production and AWS by pivoting across Splunk, disk images, and git history.

Categories: Threat Hunting, Endpoint Forensics.

MITRE ATT&CK Tactics: Resource Development, Initial Access, Execution, Persistence, Privilege Escalation, Defense Impairment, Credential Access, Discovery, Lateral Movement, Collection, Exfiltration.

Tools: Process Explorer, Event Log Explorer, Timeline Explorer, GitHub, Python3, PowerShell.

Difficulty: hard.