@Mandiant have produced a great report on responding to the #Solorigate/ #UNC2452 actor.

It has some really useful guidance on detection and response that everyone should read (the guidance is much more broadly applicable than just this TA)

https://www.fireeye.com/content/dam/collateral/en/wp-m-unc2452.pdf
#MSTIC has created #AzureSentinel content that covers the vast majority of detection opportunities detailed in the report, this is a thread of them:
We also have these queries and many other useful queries wrapped into this single Workbook you can import into #AzureSentinel for easy use.

https://github.com/Azure/Azure-Sentinel/blob/53fd116195eb5a7a90e6ef6c9726aaa99d7993b2/Workbooks/SolarWindsPostCompromiseHunting.json
You can follow @MSSPete.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled:

By continuing to use the site, you are consenting to the use of cookies as explained in our Cookie Policy to improve your experience.