The SolarWinds Orion breach: 6 ideas on what to do next and why
ID: 74eadbc2-b9df-5d75-afa5-5a2a5b0e7d75
STIX ID: report--74eadbc2-b9df-5d75-afa5-5a2a5b0e7d75
Feed Name: Expel Blog
Date Published: 2020-12-16
Date Updated: 2026-04-27
Author: Jon Hencinski; Anthony Randazzo; Bruce Potter; Mary Singh
This note analyzes the SolarWinds Orion (SUNBURST) supply-chain compromise and provides operational guidance: organizations must rewind telemetry to search for historical compromise, account for data retention shortcomings, leverage vendor detections and EDR for remote forensics, and hunt for post-compromise TTPs (Azure AD PowerShell behavior, federation trust modifications, forged SAML tokens, anomalous logins, lateral movement and privilege escalation). The authors report widespread potential impact, praise rapid vendor detection development, and note no observed recent SUNBURST C2 in their limited telemetry.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
