T03 · Remote Payload Retrieval and Execution
- Location
sutras.yaml:48- Finding
Mutable Remote Installers Are Downloaded and Executed Without Verification
- Content
View full analysis
- Remediation
View remediation
install.sh" | sha256sum --check - less install.sh bash install.sh ``` 6. Use Authenticode or another appropriate signing mechanism for the PowerShell installer and verify the signature before execution. 7. Prefer installation from the reviewed local package or a trusted package manager that verifies signed, immutable releases. 8. Configure CI to reject distribution metadata containing pipe-to-shell or download-to-`Invoke-Expression` patterns. ]]>
