logo

The SolarWinds Orion breach: 6 ideas on what to do next and why

ID: 74eadbc2-b9df-5d75-afa5-5a2a5b0e7d75

STIX ID: report--74eadbc2-b9df-5d75-afa5-5a2a5b0e7d75

Feed Name: Expel Blog

Threat Score
90/100

Date Published: 2020-12-16

Date Updated: 2026-04-27

Author: Jon Hencinski; Anthony Randazzo; Bruce Potter; Mary Singh

...
...

This note analyzes the SolarWinds Orion (SUNBURST) supply-chain compromise and provides operational guidance: organizations must rewind telemetry to search for historical compromise, account for data retention shortcomings, leverage vendor detections and EDR for remote forensics, and hunt for post-compromise TTPs (Azure AD PowerShell behavior, federation trust modifications, forged SAML tokens, anomalous logins, lateral movement and privilege escalation). The authors report widespread potential impact, praise rapid vendor detection development, and note no observed recent SUNBURST C2 in their limited telemetry.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.