logo

Introducing SITF: The First Threat Framework Dedicated to SDLC Infrastructure

ID: 93099b53-08eb-51cb-86b9-6393979ddf62

STIX ID: report--93099b53-08eb-51cb-86b9-6393979ddf62

Feed Name: Wiz Blog

Date Published: 2026-01-26

Date Updated: 2026-05-01

...
...

The report presents SITF, an open framework for securing SDLC infrastructure across Endpoint/IDE, VCS, CI/CD, Registry, and Production, featuring an interactive attack flow visualizer, a library of 70+ SDLC-specific techniques, and a risk–technique–control mapping to drive preventive controls. It demonstrates the approach using a high-level breakdown of the Shai-Hulud 2.0 campaign—tracing steps from malicious PRs to secret exfiltration, package poisoning, endpoint compromise, and persistence—and generates a prioritized controls matrix to break attack chains early. The tool is open-source, browser-based, and supports exporting models and community contributions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.