Responding to the SolarWinds Software Compromise in Industrial Environments
ID: 2b20a902-faa4-53c1-87b7-c8ff4050455e
STIX ID: report--2b20a902-faa4-53c1-87b7-c8ff4050455e
Feed Name: Dragos Blog
**Executive Summary:** The Dragos advisory details the SolarWinds Orion supply-chain compromise (SUNBURST), where a backdoor in SolarWinds updates potentially granted adversaries long-term, contested access since October 2019 to many enterprise and ICS/OT environments; it highlights that 18,000 customers received the affected software, explains that only a subset show follow-on activity, and provides guidance on identifying compromised instances, host- and network-based hunting, IOCs, incident response steps, and regulatory implications for utilities under NERC CIP.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
