/SUNBURST-Data-Aggregation

Aggregation of threat intel sources for the SolarWinds Orion(SUNBURST) attack.

GNU General Public License v3.0GPL-3.0

SUNBURST Data Aggregation

The following is an aggregation of threat intel sources for the SolarWinds Orion (SUNBURST) attack.

Note: I do not own, maintain, or make no claim as to the validity or safety of these resources.

Open Source Resources

  1. Mandiant SunBurst Countermeasures by FireEye
  2. Suburst DGA Domains Decoded
  3. Decompile of the Solorwinds "SUNBURST" Trojan associated with Campaign UNC2452 by Shadow0ps
  4. Sunburst IOCs for Splunk Ingest by davisshannon
  5. Various indicator lists and/or free research tools provided by Bambenek Labs
  6. SunBurst DGA Decode Script by RedDrip7
  7. SunBurst sample detonation review by ept-team
  8. Quick lookup files for SUNBURST Backdoor by rkovar
  9. Alienvault OTX Threat Intel
  10. Azure-Sentinel-Notebooks Guided Hunting - Solarwinds Post Compromise
  11. Credential Dumping Tool for SolarWinds Orion by mubix
  12. Powershell script to decode the DGA algorithm used in the SUNBURST backdoor by Truesec

News Media

Social Media

Cybersecurity and Infrastructure Security Agency (CISA)

Vendor Security Resources

Hotfix

Please use this to protect yourself and your assets. Feel free to add pull requests for additional resources.