Open cardosec

Case 43C27B · Famous breaches · L4 Advanced

SolarWinds SUNBURST

Practise as: Explain it · Interview · Deep dive

Interview questionExplain the SolarWinds compromise. Why was it so hard to detect?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. SUNSPOT implant in the build server injected SUNBURST into signed Orion updates, 2019.4 through 2020.2.1 HF1
  2. About 18,000 customers installed it, but the actor (APT29/SVR) hand-picked a small number for follow-on
  3. Stealth: ~2-week dormancy, C2 via DGA subdomains of avsvmcloud[.]com mimicking Orion traffic, checks for security tools
  4. Follow-on used TEARDROP/Cobalt Strike and forged SAML tokens (Golden SAML) to reach cloud email
  5. Found by FireEye in Dec 2020 investigating its own breach; drove SBOM, build integrity and SLSA efforts

If the interviewer pushes back

  • Code signing did not help here. What build-pipeline controls would have detected SUNSPOT?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.