SolarWinds Backdoor (Sunburst) Incident Response Playbook
ID: f096fc96-a29d-535a-a413-30e3c6e0c5d5
STIX ID: report--f096fc96-a29d-535a-a413-30e3c6e0c5d5
Feed Name: TrustedSec blog
This TrustedSec playbook provides step-by-step investigation, containment, eradication, and recovery guidance for organizations impacted by the SolarWinds Orion (Sunburst) backdoor. It recommends forensic preservation (live RAM capture, disk imaging, exporting logs), lists investigative questions across user, network, endpoint, and post‑exploitation activity, and prescribes containment actions (isolate/quarantine Orion servers, disable accounts, block known C2/Ioc domains and IPs). The guide also covers eradication (change or recreate compromised credentials, remove servers) and recovery options (rebuild from golden images or apply hotfixes and verify DLL hashes), emphasizing that organizations should assume full breach due to an advanced, likely state‑sponsored actor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
