Skip to content

Latest commit

 

History

History
407 lines (203 loc) · 12.1 KB

SOLORIGATE_SUNBURST.md

File metadata and controls

407 lines (203 loc) · 12.1 KB

SOLORIGATE

Attribution

KAZUAR / TURLA

Support

Victims

FireEye

Microsoft

Unnamed Think Tank

Solarwinds

Malwarebytes

FidelisSecurity

Qualys & Palo Alto Networks

Mimecast

Google

Failed attempts

  • CrowdStrike

    • Cf. CrowdStrike Reporting Tool for Azure blog post

List from Stage2 pDNS

Hunting / Detection

Hunting w/ Sentinel

Detection & IR w/ Microsoft 365 Defender

Microsoft Defender for Identity

Azure AD Monitor

Hunting w/ Splunk

Yara

ATT&CK

Zeek

CrowdStrike Reporting Tool for Azure

CISA - Sparrow

Host - C2 match

Generic Playbook

Microsoft IOC

Security Advisory

Cf. Victims / Microsoft / Advisory

Implants

SUNBURST

TEARDROP

SUNSPOT

RAINDROP

CobaltStrike

  • Microsoft

GoldMax / SUNSHUTTLE

Goldfinger, Sibot

EnvyScout, BoomBox, NativeZone

FoggyWeb