SUNBURST and SUPERNOVA backdoor hashes (Normalized File Events)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Identifies SolarWinds SUNBURST and SUPERNOVA backdoor file hash IOCs in File Events To use this analytics rule, make sure you have deployed the ASIM normalization parsers References: - https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html - https://gist.github.com/olafhartong/71ffdd4cab4b6acd5cbcd1a0691ff82f

Attribute Value
Type Analytic Rule
Solution Standalone Content
ID bc5ffe2a-84d6-48fe-bc7b-1055100469bc
Severity High
Kind Scheduled
Tactics Execution, Persistence, InitialAccess
Techniques T1195, T1059, T1546
Source View on GitHub

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules