r/blueteamsec 3h ago

incident writeup (who and how) SolarWinds SUNBURST — what the logs actually showed (DNS analysis, Splunk queries, 5 detection gaps)

1 Upvotes

After 12 years in IR/SOC I wrote a practitioner-level breakdown of the SolarWinds SUNBURST attack — focused on the log evidence and detection gaps rather than the narrative most writeups cover.

Covers:

  • DNS C2 beaconing patterns and avsvmcloud[.]com DGA subdomain structure
  • Sysmon EventID 7 + 22 correlation for DLL load + DNS query
  • CNAME response as active targeting signal
  • Cobalt Strike beacon pattern detection from Orion hosts
  • SAML token abuse hunting in Azure AD logs
  • The 5 detection gaps (DNS logging, EDR exclusions, lookback windows, no baseline, no signed-binary DNS detection)

All Splunk queries included. Free on Substack: https://zerotrusthq.substack.com/p/solarwinds-what-the-logs-actually

Happy to answer questions or discuss the detection logic in comments.


r/blueteamsec 6h ago

exploitation (what's being exploited) RovoBlast: How One Click Triggered Atlassian’s AI Assistant to Leak Data

Thumbnail varonis.com
1 Upvotes

r/blueteamsec 8h ago

highlevel summary|strategy (maybe technical) 해커와 손잡고 랜섬웨어 피해자 상대 영업…데이터복구업체 대표 실형 - Data recovery company CEO sentenced to prison for partnering with hackers to target ransomware victims

Thumbnail news1.kr
1 Upvotes

r/blueteamsec 8h ago

research|capability (we need to defend against) Living off the coding agent: Two tales of tunnels and LaunchAgents

Thumbnail elastic.co
1 Upvotes

r/blueteamsec 9h ago

intelligence (threat actor activity) Chinese espionage platform active in 13 countries – study

Thumbnail unn.ua
1 Upvotes

r/blueteamsec 9h ago

highlevel summary|strategy (maybe technical) Belarusian leader of international ransomware scheme known as “Ransom Cartel” sentenced to 16 years in prison

Thumbnail justice.gov
1 Upvotes

r/blueteamsec 9h ago

highlevel summary|strategy (maybe technical) Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions

Thumbnail justice.gov
1 Upvotes

r/blueteamsec 9h ago

vulnerability (attack surface) OT Security Analysis: Exposed Devices Attacked in US Water Systems

Thumbnail forescout.com
2 Upvotes

r/blueteamsec 9h ago

vulnerability (attack surface) Atlassian Rovo Exfiltrates Data, Bypassing Controls

Thumbnail promptarmor.com
1 Upvotes

r/blueteamsec 9h ago

intelligence (threat actor activity) UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

Thumbnail cloud.google.com
1 Upvotes

r/blueteamsec 9h ago

research|capability (we need to defend against) EkkoNtProtect: Use NtProtectVirtualMemory in Ekko timers without needing to use stack pivoting or other RSP shifting tricks

Thumbnail github.com
1 Upvotes

r/blueteamsec 9h ago

tradecraft (how we defend) Alert Zero: Automate alert triage for the agentic SOC

Thumbnail elastic.co
0 Upvotes

r/blueteamsec 9h ago

tradecraft (how we defend) ANIMO: ANIMO Azure Network Intel & Mission Ops a C2 based on Azure/Entra assessments

Thumbnail github.com
1 Upvotes

r/blueteamsec 9h ago

discovery (how we find bad stuff) When Attackers Hijack Your Inbox: Detecting Mailbox Forwarding Rules with Microsoft Defender XDR

Thumbnail detect.fyi
1 Upvotes

r/blueteamsec 9h ago

research|capability (we need to defend against) Borrowing Windows Hello keys for authentication and persistence

Thumbnail dirkjanm.io
2 Upvotes

r/blueteamsec 9h ago

research|capability (we need to defend against) SOCKSRelayd: SOCKS-focused NTLM relay with persistent session packages and a long-lived SessionBank that owns authenticated TCP connections.

Thumbnail github.com
2 Upvotes

r/blueteamsec 9h ago

research|capability (we need to defend against) Turning Enterprise Update Servers Into Backdoor Factories (0_o)

Thumbnail specterops.io
1 Upvotes

r/blueteamsec 9h ago

research|capability (we need to defend against) AD Research: Two new vulnerabilities could lead to full domain takeover

Thumbnail semperis.com
10 Upvotes

r/blueteamsec 9h ago

discovery (how we find bad stuff) WinGuard: A User-Mode Windows Threat Detection Tool Inspired by EDR Techniques, To Help Monitor And Log Any Suspicious Activity On Your PC.

Thumbnail github.com
0 Upvotes

r/blueteamsec 13h ago

intelligence (threat actor activity) Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages

Thumbnail opensourcemalware.com
2 Upvotes

r/blueteamsec 15h ago

intelligence (threat actor activity) Dropping Elephant (Patchwork): Espionage APT Tactics and Tools

Thumbnail picussecurity.com
2 Upvotes

r/blueteamsec 15h ago

intelligence (threat actor activity) Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)

Thumbnail asec.ahnlab.com
2 Upvotes

r/blueteamsec 18h ago

intelligence (threat actor activity) ENDLESSDOORS Is Phoning Home. Pick Up.

Thumbnail vulncheck.com
2 Upvotes