Case 43C27B · Famous breaches · L4 Advanced
SolarWinds SUNBURST
Practise as: Explain it · Interview · Deep dive
Interview questionExplain the SolarWinds compromise. Why was it so hard to detect?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- SUNSPOT implant in the build server injected SUNBURST into signed Orion updates, 2019.4 through 2020.2.1 HF1
- About 18,000 customers installed it, but the actor (APT29/SVR) hand-picked a small number for follow-on
- Stealth: ~2-week dormancy, C2 via DGA subdomains of avsvmcloud[.]com mimicking Orion traffic, checks for security tools
- Follow-on used TEARDROP/Cobalt Strike and forged SAML tokens (Golden SAML) to reach cloud email
- Found by FireEye in Dec 2020 investigating its own breach; drove SBOM, build integrity and SLSA efforts
If the interviewer pushes back
- Code signing did not help here. What build-pipeline controls would have detected SUNSPOT?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.