/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Microsoft details the Solorigate DLL file that was used to install a backdoor in SolarWinds Orion and reveals it discovered additional malware affecting Orion

- Microsoft 365 Defender Research Team  — Microsoft Threat Intelligence Center (MSTIC)  —  We, along with the security industry …

Microsoft Security

Discussion

  • @luispatino92 Lucho Patio on x
    Do you want to read about the code part of the SolarWind security attack? This is the best post I found about the code that avoided being detected for months and reached some government systems in the USA. #100DaysOfCode https://www.microsoft.com/...
  • @brento Brent Ozar on x
    “In an interesting turn of events, the investigation of the whole SolarWinds compromise led to the discovery of an additional malware that also affects the SolarWinds Orion product” Wow, keeps getting worse. See the “additional malware” section. https://www.microsoft.com/...
  • @file411 @file411 on x
    Good LORD: “whole SolarWinds compromise led to the discovery of an additional malware that also affects the SolarWinds Orion product but has been determined to be likely unrelated to this compromise and used by a different threat actor...” https://www.microsoft.com/... https://tw…
  • @gossithedog Kevin Beaumont on x
    In depth technical look at SolarWinds nation state activity from MS peeps, including more hunting details etc. Really proud of the teams here, everything been thrown at protecting everyone. https://www.microsoft.com/...
  • @file411 @file411 on x
    I have to say this breach is probably one of the most flawless reverse engineering Ops I've ever read “The envelopes” passed through numerous built-in security checks. This takes meticulous planning, discipline & serious coding chops It's impressive https://www.microsoft.com/... …
  • @file411 @file411 on x
    If I'm reading this correctly because the envelope passed the built-in security protocols the C2 Server was like: secret handshake valid, come on in Also take note of the domains too (see next tweet) https://www.microsoft.com/... https://twitter.com/...
  • @file411 @file411 on x
    Hey remember when someone was like: Oh GOD they can accurately & quickly map out a target network. Thus they know where to hide because they can see you coming HERE. WE. ARE. Big props to @Microsoft for their transparency because this helps understand https://www.microsoft.com/..…
  • @msftsecintel @msftsecintel on x
    Here's our analysis of the compromised DLL that led to the Solorigate attack. While the extent of the compromise is being investigated, we want to continue providing the defender community with intel, remediation guidance, and protections we have built: https://www.microsoft.com/…