CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Living Off the Pipeline

campaign · campaign:sentinelone-living-off-the-pipeline-2026 single-source

SentinelOne taxonomy of CI/CD subversion ('Living Off the Pipeline') with three case studies: TeamCity, GitLab service accounts, and Contagious Interview.

Coverage
2
1 about it · 1 mention · first 2026-05-16 → last 2026-05-19
Latest activity
2026-05-16
SentinelOne: "Living Off the Pipeline", CI/CD subversion taxonomy with three real intrusion cases (TeamCity…
Peak priority
notable
1 notable
Targets
technology
sectors: technology, public-sector
Sources cited
10
6 hosts
2026-05-162 appearances2026-05-19

Story timeline

Every entry that names Living Off the Pipeline, newest first. Rows tagged mention only name it in passing: they are listed for completeness and add nothing to the action items, pivots or ATT&CK profile on this page.

  1. 2026-05-19Grafana Labs CoinbaseCartel breach; victim confirms source-code-only theft, no customer data, ransom rejected
    mentionactive-threats
  2. 2026-05-16SentinelOne: "Living Off the Pipeline", CI/CD subversion taxonomy with three real intrusion cases (TeamCity, GitLab service-account pivot, Contagious Interview)
    researchSentinelOne: "Living Off the Pipeline", CI/CD subversion taxonomy with three real intrusion cases (TeamCity, GitLab service-account pivot, Contagious
ATT&CK techniques (6 across 6 tactics)

6 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessSupply Chain Compromise · Supply Chain Compromise: Compromise Software Supply Chain
  • ExecutionSoftware Deployment Tools · User Execution
  • PersistenceBoot or Logon Autostart Execution
  • Privilege EscalationBoot or Logon Autostart Execution
  • Credential AccessCredentials from Password Stores
  • Lateral MovementSoftware Deployment Tools

Initial Access TA0001

T1195Supply Chain Compromise×1

Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.

Evidence: 2026-05-16/sentinelone-living-off-the-pipeline-ci-cd-subversion-taxonom · ATT&CK page ↗

T1195.002Supply Chain Compromise: Compromise Software Supply Chain×1

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Evidence: 2026-05-16/sentinelone-living-off-the-pipeline-ci-cd-subversion-taxonom · ATT&CK page ↗

Execution TA0002

T1072Software Deployment Tools×1

Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration management and software deployment applications may be used in an enterprise network or cloud environment for routine administration purposes. These systems may also be integrated into CI/CD pipelines. Examples of such solutions include: SCCM, HBSS, Altiris, AWS Systems Manager, Microsoft Intune, Azure Arc, and GCP Deployment Manager.

Evidence: 2026-05-16/sentinelone-living-off-the-pipeline-ci-cd-subversion-taxonom · ATT&CK page ↗

T1204User Execution×1

An adversary may rely upon specific actions by a user in order to gain execution. Users may be subjected to social engineering to get them to execute malicious code by, for example, opening a malicious document file or link. These user actions will typically be observed as follow-on behavior from forms of Phishing.

Evidence: 2026-05-16/sentinelone-living-off-the-pipeline-ci-cd-subversion-taxonom · ATT&CK page ↗

Persistence TA0003

T1547Boot or Logon Autostart Execution×1

Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges on compromised systems. Operating systems may have mechanisms for automatically running a program on system boot or account logon. These mechanisms may include automatically executing programs that are placed in specially designated directories or are referenced by repositories that store configuration information, such as the Windows Registry. An adversary may achieve the same goal by modifying or extending features of the kernel.

Evidence: 2026-05-16/sentinelone-living-off-the-pipeline-ci-cd-subversion-taxonom · ATT&CK page ↗

Privilege Escalation TA0004

T1547Boot or Logon Autostart Execution×1

Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges on compromised systems. Operating systems may have mechanisms for automatically running a program on system boot or account logon. These mechanisms may include automatically executing programs that are placed in specially designated directories or are referenced by repositories that store configuration information, such as the Windows Registry. An adversary may achieve the same goal by modifying or extending features of the kernel.

Evidence: 2026-05-16/sentinelone-living-off-the-pipeline-ci-cd-subversion-taxonom · ATT&CK page ↗

Credential Access TA0006

T1555Credentials from Password Stores×1

Adversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials. There are also specific applications and services that store passwords to make them easier for users to manage and maintain, such as password managers and cloud secrets vaults. Once credentials are obtained, they can be used to perform lateral movement and access restricted information.

Evidence: 2026-05-16/sentinelone-living-off-the-pipeline-ci-cd-subversion-taxonom · ATT&CK page ↗

Lateral Movement TA0008

T1072Software Deployment Tools×1

Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration management and software deployment applications may be used in an enterprise network or cloud environment for routine administration purposes. These systems may also be integrated into CI/CD pipelines. Examples of such solutions include: SCCM, HBSS, Altiris, AWS Systems Manager, Microsoft Intune, Azure Arc, and GCP Deployment Manager.

Evidence: 2026-05-16/sentinelone-living-off-the-pipeline-ci-cd-subversion-taxonom · ATT&CK page ↗

Entries about Living Off the Pipeline (1)

2026-05-16 · view entry permalink →

NOTABLE

SentinelOne: "Living Off the Pipeline", CI/CD subversion taxonomy with three real intrusion cases (TeamCity, GitLab service-account pivot, Contagious Interview)

SentinelOne published on 2026-05-15 a practitioner-focused taxonomy of CI/CD pipeline subversion techniques, illustrated with three real intrusion case studies that are immediately useful for SOC and DevSecOps teams running JetBrains TeamCity, GitLab, or GitHub Actions (SentinelOne, 2026-05-15). Case 1: an unpatched TeamCity server (CVE-2023-42793) exploited to deploy backdoors via privileged build tasks, remaining undetected for 12+ months. Case 2: a GitLab service-account token compromise enabling creation of malicious Ansible playbooks that were then automatically executed by pipelines, a clean demonstration of how service-account over-privilege translates directly into production code execution. Case 3: the Contagious Interview campaign using fraudulent job offers directing developer victims to fake skill-assessment sites that deploy malware silently to developer workstations. Additional vectors covered include attacker-registered self-hosted runners, workflow triggers from repository discussion comments, dependency poisoning with reconnaissance preinstall scripts, and maintainer-account compromise appending malicious code; the article cross-links a separate SentinelOne analysis of the "Sha1-Hulud" NPM compromise as a related supply-chain case. MITRE ATT&CK: T1195.002, T1547 (rogue runner registration as persistence), T1555 (pipeline secret extraction), T1204 (user execution via fake job-offer social engineering), T1072 (software-deployment-tool abuse via Ansible). Defender monitoring priorities surfaced in the report: GitHub / GitLab audit logs for runner.registered events with unfamiliar names or unexpected source IP ranges; new or modified pipelines authored by service accounts; suspicious child-process spawn from build agents (cmd.exe, powershell.exe, curl, wget outside baseline); credential-access and reverse-tunnel traffic originating from build infrastructure; and secret-injection patterns in workflow-config modifications. Single-source, SentinelOne only.

research16 May 05:00Zsingle-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Research1
  • Threats1

Source distribution

  • attack.mitre.org5 (50%)
  • bleepingcomputer.com1 (10%)
  • securityweek.com1 (10%)
  • sentinelone.com1 (10%)
  • thehackernews.com1 (10%)
  • theregister.com1 (10%)