{"id":19390597,"url":"https://github.com/mandiant/sunburst_countermeasures","last_synced_at":"2025-07-25T15:15:55.588Z","repository":{"id":45357412,"uuid":"321092899","full_name":"mandiant/sunburst_countermeasures","owner":"mandiant","description":null,"archived":false,"fork":false,"pushed_at":"2023-06-01T13:34:23.000Z","size":84,"stargazers_count":561,"open_issues_count":8,"forks_count":199,"subscribers_count":116,"default_branch":"main","last_synced_at":"2024-05-23T05:20:03.866Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"YARA","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"bsd-2-clause","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/mandiant.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE.txt","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null}},"created_at":"2020-12-13T15:10:47.000Z","updated_at":"2024-05-19T19:26:31.000Z","dependencies_parsed_at":"2024-01-03T04:13:22.908Z","dependency_job_id":"9d0b2a74-38e9-4f50-9349-03954de64380","html_url":"https://github.com/mandiant/sunburst_countermeasures","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/mandiant/sunburst_countermeasures","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mandiant%2Fsunburst_countermeasures","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mandiant%2Fsunburst_countermeasures/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mandiant%2Fsunburst_countermeasures/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mandiant%2Fsunburst_countermeasures/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/mandiant","download_url":"https://codeload.github.com/mandiant/sunburst_countermeasures/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mandiant%2Fsunburst_countermeasures/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":267023278,"owners_count":24022924,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-07-25T02:00:09.625Z","response_time":70,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-10T10:22:06.743Z","updated_at":"2025-07-25T15:15:55.531Z","avatar_url":"https://github.com/mandiant.png","language":"YARA","funding_links":[],"categories":[],"sub_categories":[],"readme":"# FireEye Mandiant SunBurst Countermeasures\n\nThese rules are provided freely to the community without warranty.\n\nIn this GitHub repository you will find rules in multiple languages:\n- Snort\n- Yara\n- IOC\n- ClamAV\n\nThe rules are categorized and labeled into two release states:\n- Production: rules that are expected to perform with minimal tuning.\n- Supplemental: rules that are known to require further environment-specific tuning and tweaking to perform, and are often used for hunting workflows.\n\nPlease check back to this GitHub for updates to these rules.\n\nFireEye customers can refer to the FireEye Community (community.fireeye.com) for information on how FireEye products detect these threats.\n \nThe entire risk as to quality and performance of these rules is with the users.\n\nPlease review the FireEye blog for additional details on this threat. \n\nPlease note: COSMICGALE and SUPERNOVA signatures and indicators are confirmed to detect malicious files and activity, however they have not been directly associated with the current UNC2452 Solarwinds compromise.\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmandiant%2Fsunburst_countermeasures","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmandiant%2Fsunburst_countermeasures","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmandiant%2Fsunburst_countermeasures/lists"}