logo

SolarWinds Backdoor (Sunburst) Incident Response Playbook

ID: f096fc96-a29d-535a-a413-30e3c6e0c5d5

STIX ID: report--f096fc96-a29d-535a-a413-30e3c6e0c5d5

Feed Name: TrustedSec blog

Threat Score
95/100

Date Published: 2023-09-20

Date Updated: 2026-05-01

...
...

This TrustedSec playbook provides step-by-step investigation, containment, eradication, and recovery guidance for organizations impacted by the SolarWinds Orion (Sunburst) backdoor. It recommends forensic preservation (live RAM capture, disk imaging, exporting logs), lists investigative questions across user, network, endpoint, and post‑exploitation activity, and prescribes containment actions (isolate/quarantine Orion servers, disable accounts, block known C2/Ioc domains and IPs). The guide also covers eradication (change or recreate compromised credentials, remove servers) and recovery options (rebuild from golden images or apply hotfixes and verify DLL hashes), emphasizing that organizations should assume full breach due to an advanced, likely state‑sponsored actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.