Skip to content

Aggregation of threat intel sources for the SolarWinds Orion(SUNBURST) attack.

License

Notifications You must be signed in to change notification settings

subfission/SUNBURST-Data-Aggregation

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

28 Commits
 
 
 
 

Repository files navigation

SUNBURST Data Aggregation

The following is an aggregation of threat intel sources for the SolarWinds Orion (SUNBURST) attack.

Note: I do not own, maintain, or make no claim as to the validity or safety of these resources.

Open Source Resources

  1. Mandiant SunBurst Countermeasures by FireEye
  2. Suburst DGA Domains Decoded
  3. Decompile of the Solorwinds "SUNBURST" Trojan associated with Campaign UNC2452 by Shadow0ps
  4. Sunburst IOCs for Splunk Ingest by davisshannon
  5. Various indicator lists and/or free research tools provided by Bambenek Labs
  6. SunBurst DGA Decode Script by RedDrip7
  7. SunBurst sample detonation review by ept-team
  8. Quick lookup files for SUNBURST Backdoor by rkovar
  9. Alienvault OTX Threat Intel
  10. Azure-Sentinel-Notebooks Guided Hunting - Solarwinds Post Compromise
  11. Credential Dumping Tool for SolarWinds Orion by mubix
  12. Powershell script to decode the DGA algorithm used in the SUNBURST backdoor by Truesec

News Media

Social Media

Cybersecurity and Infrastructure Security Agency (CISA)

Vendor Security Resources

Hotfix

Please use this to protect yourself and your assets. Feel free to add pull requests for additional resources.

About

Aggregation of threat intel sources for the SolarWinds Orion(SUNBURST) attack.

Topics

Resources

License

Stars

Watchers

Forks

Releases

No releases published