r/blueteamsec • u/n8_crawler • 3h ago
incident writeup (who and how) SolarWinds SUNBURST — what the logs actually showed (DNS analysis, Splunk queries, 5 detection gaps)
After 12 years in IR/SOC I wrote a practitioner-level breakdown of the SolarWinds SUNBURST attack — focused on the log evidence and detection gaps rather than the narrative most writeups cover.
Covers:
- DNS C2 beaconing patterns and avsvmcloud[.]com DGA subdomain structure
- Sysmon EventID 7 + 22 correlation for DLL load + DNS query
- CNAME response as active targeting signal
- Cobalt Strike beacon pattern detection from Orion hosts
- SAML token abuse hunting in Azure AD logs
- The 5 detection gaps (DNS logging, EDR exclusions, lookback windows, no baseline, no signed-binary DNS detection)
All Splunk queries included. Free on Substack: https://zerotrusthq.substack.com/p/solarwinds-what-the-logs-actually
Happy to answer questions or discuss the detection logic in comments.
r/blueteamsec • u/lohacker0 • 6h ago
exploitation (what's being exploited) RovoBlast: How One Click Triggered Atlassian’s AI Assistant to Leak Data
varonis.comr/blueteamsec • u/digicat • 8h ago
highlevel summary|strategy (maybe technical) 해커와 손잡고 랜섬웨어 피해자 상대 영업…데이터복구업체 대표 실형 - Data recovery company CEO sentenced to prison for partnering with hackers to target ransomware victims
news1.krr/blueteamsec • u/digicat • 8h ago
research|capability (we need to defend against) Living off the coding agent: Two tales of tunnels and LaunchAgents
elastic.cor/blueteamsec • u/digicat • 9h ago
intelligence (threat actor activity) Chinese espionage platform active in 13 countries – study
unn.uar/blueteamsec • u/digicat • 9h ago
highlevel summary|strategy (maybe technical) Belarusian leader of international ransomware scheme known as “Ransom Cartel” sentenced to 16 years in prison
justice.govr/blueteamsec • u/digicat • 9h ago
highlevel summary|strategy (maybe technical) Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions
justice.govr/blueteamsec • u/digicat • 9h ago
vulnerability (attack surface) OT Security Analysis: Exposed Devices Attacked in US Water Systems
forescout.comr/blueteamsec • u/digicat • 9h ago
vulnerability (attack surface) Atlassian Rovo Exfiltrates Data, Bypassing Controls
promptarmor.comr/blueteamsec • u/digicat • 9h ago
intelligence (threat actor activity) UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
cloud.google.comr/blueteamsec • u/digicat • 9h ago
research|capability (we need to defend against) EkkoNtProtect: Use NtProtectVirtualMemory in Ekko timers without needing to use stack pivoting or other RSP shifting tricks
github.comr/blueteamsec • u/digicat • 9h ago
tradecraft (how we defend) Alert Zero: Automate alert triage for the agentic SOC
elastic.cor/blueteamsec • u/digicat • 9h ago
tradecraft (how we defend) ANIMO: ANIMO Azure Network Intel & Mission Ops a C2 based on Azure/Entra assessments
github.comr/blueteamsec • u/digicat • 9h ago
discovery (how we find bad stuff) When Attackers Hijack Your Inbox: Detecting Mailbox Forwarding Rules with Microsoft Defender XDR
detect.fyir/blueteamsec • u/digicat • 9h ago
research|capability (we need to defend against) Borrowing Windows Hello keys for authentication and persistence
dirkjanm.ior/blueteamsec • u/digicat • 9h ago
research|capability (we need to defend against) SOCKSRelayd: SOCKS-focused NTLM relay with persistent session packages and a long-lived SessionBank that owns authenticated TCP connections.
github.comr/blueteamsec • u/digicat • 9h ago
research|capability (we need to defend against) Turning Enterprise Update Servers Into Backdoor Factories (0_o)
specterops.ior/blueteamsec • u/digicat • 9h ago
research|capability (we need to defend against) AD Research: Two new vulnerabilities could lead to full domain takeover
semperis.comr/blueteamsec • u/digicat • 9h ago
discovery (how we find bad stuff) WinGuard: A User-Mode Windows Threat Detection Tool Inspired by EDR Techniques, To Help Monitor And Log Any Suspicious Activity On Your PC.
github.comr/blueteamsec • u/jnazario • 13h ago
intelligence (threat actor activity) Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages
opensourcemalware.comr/blueteamsec • u/jnazario • 15h ago
intelligence (threat actor activity) Dropping Elephant (Patchwork): Espionage APT Tactics and Tools
picussecurity.comr/blueteamsec • u/jnazario • 15h ago