logo

Responding to the SolarWinds Breach: Detect, Prevent, and Remediate the Dark Halo Supply Chain Attack

ID: 014a07ab-f5ce-5bf7-971c-4d2aef9f83f0

STIX ID: report--014a07ab-f5ce-5bf7-971c-4d2aef9f83f0

Feed Name: Volexity Blog

Threat Score
90/100

Date Published: 2020-12-16

Date Updated: 2026-05-01

...
...

This Volexity guide outlines how to determine if an organization was affected by the SolarWinds Orion supply-chain compromise attributed to the Dark Halo APT, identifying affected Orion versions and DNS CNAME activity to avsvmcloud.com as primary indicators, and provides detection, prevention, and remediation recommendations including IOC hunting, network/DNS log review, rebuilding impacted servers, and resetting credentials and API keys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.