Course

Software Supply Chain Detection Reasoning

About this learning content: Courses, lessons, assessments, explanations and illustrations may be created with the help of artificial intelligence. We review and check the material and do our best to avoid incorrect or outdated information, but mistakes, omissions or ambiguous questions may remain. Please verify information before relying on it for professional, security, legal or operational decisions. Read the full notice or report an issue.
Difficulty Advanced
Modules 3
Lessons 3
Time 2 hr 30 min
Language en
Created by Threat Intelligence Lab
Updated 16 September 2026
Software Supply Chain Detection ReasoningEVIDENCE connects to UNDERSTANDING. The course carries one line of reasoning from observation to a bounded claim.Software Supply Chain Detection ReasoningEVIDENCEUNDERSTANDINGThe course carries one line of reasoning from observation to a bounded claim.

About this course

Follow trust and identity from developer to source, workflow, runner, artifact, registry, deployment, Kubernetes control plane, and runtime. The course is written for one reader and develops its ideas through continuous explanation, realistic thought experiments, and explicit distinctions between fact, assessment, and uncertainty.

What you'll learn

  • Reason from a security concern to evidence and a bounded analytical claim.
  • Explain assumptions, tradeoffs, and limitations in plain language.

Before you begin

You will get more from this course if these foundations are already familiar.

  • Detection Engineering: From Telemetry to Tuned Detections — You should understand the basic detection lifecycle and common telemetry sources.

Course content

Module 1: Trust Travels from Source to Runtime

Map developers, repositories, workflows, runners, registries, deployers, and workloads as one chain of authority.

Module 2: Authorized Features Can Carry Unauthorized Change

Detect consequential state changes even when attackers use valid accounts and normal platform capabilities.

Module 3: Provenance Strengthens a Claim Without Making It Absolute

Use artifact identity, builder claims, verification policy, and deployment evidence without treating a signature as proof of benign intent.

Keep building