December 21st, 2020 – Solorigate Resource Center
2020-12-22 11:23:42 Author: msrc-blog.microsoft.com(查看原文) 阅读量:265 收藏

Alongside our industry partners and the security community, Microsoft continues to investigate the extent of the recent nation-state attack on SolarWinds. Our goal is to provide the latest threat intelligence, Indicators of Compromise (IOC)s, and guidance across our products and solutions to help the community respond, harden infrastructure, and begin to recover from this unprecedented attack. As new information becomes available, we will make updates to this article at https://aka.ms/solorigate  

Executive Summary and Background Information 

Microsoft is aware of a sophisticated supply chain attack that has targeted a variety of victims. The attack utilized malicious SolarWinds files that potentially gave nation-state actors access to some victims’ networks. Microsoft cybersecurity experts are investigating the attack to help ensure that customers are as secure as possible.  

Information for Security Operations and Hunters 

We encourage customers to implement new detections and protections to identify possible prior campaigns or prevent future campaigns against their systems. We have published the IOC’s in this post. This list is not exhaustive and may expand as investigations continue.  

We also recommend you review the IOCs provided by FireEye at Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor | FireEye Inc

Information for Security Admins  

Specific guidance for Microsoft Security products and solutions 

Overviews of the different Microsoft security products:  

Coming soon: Solorigate product specific guidance 

Where can I get help and assistance? 

  • Customers with any product support related needs should file a Microsoft Support case at https://support.microsoft.com/contactus  
  • Get help in the Microsoft 365 security center, Office 365 Security & Compliance center, and Microsoft Defender Security Center by clicking on the “?” Icon in the top navigation bar.  
  • For deployment assistance please contact https://fasttrack.microsoft.com  

Other Advisories & Additional Resources 


文章来源: https://msrc-blog.microsoft.com/2020/12/21/december-21st-2020-solorigate-resource-center/
如有侵权请联系:admin#unsafe.sh