SolarStorm and SUNBURST Hunting and Response Playbook
This playbook does the following: - Collect indicators to aid in your threat hunting process. - Retrieve IOCs of SUNBURST (a trojanized version of the SolarWinds Orion plugin). - Retrieve C2 domains and URLs associated with Sunburst. - Discover IOCs of associated activity related to the infection. - Generate an indicator list to block indicators with SUNBURST tags. - Hunt for the SUNBURST backdoor - Query firewall logs to detect network activity. - Search endpoint logs for Sunburst hashes to detect presence on hosts. If compromised hosts are found: - Notify security team to review and trigger remediation response actions. - Run sub-playbooks to isolate/quarantine infected hosts/endpoints and await further actions from the security team. Sources: https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html https://unit42.paloaltonetworks.com/fireeye-solarstorm-sunburst/3/ https://www.splunk.com/en_us/blog/security/sunburst-backdoor-detections-in-splunk.html
- Pack
- MajorBreachesInvestigationandResponse
- Tasks
- 73
Inputs
- IsolateEndpointAutomatically — Whether to automatically isolate endpoints, or opt for manual user approval. True means isolation will be done automatically.
- BlockIndicatorsAutomatically — Whether to automatically indicators involved with SolarStorm.
- CVEs — CVEs related to SUNBURST and SolarStorm.
- SunBurstSTIX — Hard-coded STIX file of SUNBURST and SolarStorm indicators.
- KnownRelatedIOCs — Add your own custom SUNBURST and SolarStorm IOCs to hunt.
- LogForwarding — PAN-OS Log Forwarding Profile Name
- AutoCommit — This input establishes whether to commit the configuration automatically in PAN-OS. Yes - Commit automatically. No - Commit manually.
- AutoBlockSolarWindsServer — This input establishes whether to block the SolarWinds server automatically in PAN-OS. True - Commit automatically. False - Commit manually.
- DeviceGroup — Target Device Group (Panorama only)
- O365_AdminRolesList — Comma-separated list of Service O365 admin roles.
- Mialboxes_Retrieve_Limit — The maximum number of results to retrieve. Default is 10.
Commands used
- appendIndicatorField
- closeInvestigation
- createNewIndicator
- expanse-get-issues
- extractIndicators