@Mandiant have produced a great report on responding to the #Solorigate/ #UNC2452 actor.

It has some really useful guidance on detection and response that everyone should read (the guidance is much more broadly applicable than just this TA)

#MSTIC has created #AzureSentinel content that covers the vast majority of detection opportunities detailed in the report, this is a thread of them:
We also have these queries and many other useful queries wrapped into this single Workbook you can import into #AzureSentinel for easy use.

You can follow @MSSPete.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled:

By continuing to use the site, you are consenting to the use of cookies as explained in our Cookie Policy to improve your experience.