Solar Winds Supply Chain Attack
ArchivedSolar Winds Supply Chain Attack consists of alerts that detect domains, IP addresses and file checksums(hash) confirmed to be a part of an attack on the SolarWinds Orion products.
Release Details
Package Details
- Alert Packages
- LP_SolarWinds Orion API Authentication Bypass CVE-2020-10148 Attempt
- LP_SolarWinds Supply Chain Compromise IoC Domain Match
- LP_SolarWinds Supply Chain Compromise IoC Hash Match
- LP_SolarWinds Supply Chain Compromise IoC IP Match
- LP_SolarWinds Supply Chain Compromise Suspicious File Drop
- LP_SolarWinds Supply Chain Compromise Malicious Image Load
- LP_SolarWinds Supply Chain Compromise IoC Snort Rule Match
- LP_SolarWinds Supply Chain Compromise Suspicious Process Creations
- KB List
- SOLARWINDS_DOMAINS
- SOLARWINDS_URLS
- SOLARWINDS_IPS
- SOLARWINDS_HASHES
Enhancement
Added a new alert rule LP_SolarWinds Orion API Authentication Bypass CVE-2020-10148 Attempt .
Installation
To install Solar Winds Supply Chain Attack:
- Download the .pak file from the Download link above.
- Go to Settings >> System Settings from the navigation bar and click Applications .
- Click Import .
- Browse to the downloaded .pak file.
- Click Upload.
Past Release
Changes in Solar Winds Supply Chain Attack v5.0.1 ▾
KB List Usage
- SOLARWINDS_DOMAINS: It contains a list of all domain IoC like deftsecurity.com and databasegalore.com.
- SOLARWINDS_URLS: It contains a list of URLs. It is an extension of a domain. If the domain is deftsecurity.com, the entry in this list will be *deftsecurity.com*.
- SOLARWINDS_IPS: It contains a list of all IPs.
- SOLARWINDS_HASHES: It contains a list of all available hashes like MD5, SHA1, or SHA256.
Required Log Source
- Windows
- Sysmon
- Firewall
- Web Proxy
- Antivirus
- Email Security
-
Snort
-
Suricata
- DNS Server
Support
If you have any questions or require assistance, create a support ticket..
Comments
Article is closed for comments.