Open-source detection rules for identifying SolarWinds SunBurst backdoor activities and related vulnerabilities across multiple security tools.
FireEye SunBurst Countermeasures is a collection of open-source detection rules and indicators of compromise (IoCs) for identifying malicious activities associated with the SolarWinds SunBurst supply chain attack. It provides security teams with ready-to-use signatures across multiple security tool formats to detect backdoored SolarWinds Orion NMS activities and related vulnerabilities in their environments.
Security operations teams, threat hunters, and incident responders who need to detect and investigate SolarWinds SunBurst compromise activities in their networks using existing security tools.
This project offers freely available, professionally developed detection rules from FireEye Mandiant that can be immediately deployed across multiple security platforms, providing organizations with enterprise-grade threat detection capabilities without commercial licensing requirements.
This repository provides a collection of detection rules and indicators of compromise (IoCs) for identifying malicious activities associated with the SolarWinds SunBurst supply chain attack. These rules help security teams detect backdoored SolarWinds Orion NMS activities and related vulnerabilities in their environments.
These rules are provided freely to the community to enhance collective defense against sophisticated supply chain attacks, with clear categorization to help security teams balance detection accuracy and operational efficiency.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.
Rules are available in Snort, Yara, IOC, and ClamAV formats, enabling integration with various security tools as specified in the README.
Divided into production and supplemental rules, helping teams prioritize deployment and manage tuning efforts based on the repository's release states.
The repository is regularly updated with the latest detection capabilities, ensuring ongoing relevance against evolving threats as mentioned.
Focused on UNC2452/SolarWinds compromise with distinctions for COSMICGALE and SUPERNOVA, providing targeted detection without false positives from unrelated activities.
Supplemental rules need environment-specific adjustments, which can be time-consuming and require advanced security knowledge, as admitted in the README.
Rules are specific to SolarWinds SunBurst and related threats, making them ineffective for detecting other types of malware or broader attack vectors.
Provided without warranty, with users bearing all risk for quality and performance, which might deter risk-averse organizations.