{"id":22852919,"url":"https://github.com/subfission/sunburst-data-aggregation","last_synced_at":"2026-02-28T13:33:03.136Z","repository":{"id":92113306,"uuid":"322140129","full_name":"subfission/SUNBURST-Data-Aggregation","owner":"subfission","description":"Aggregation of threat intel sources for the SolarWinds Orion(SUNBURST) attack.","archived":false,"fork":false,"pushed_at":"2020-12-28T17:22:32.000Z","size":92,"stargazers_count":5,"open_issues_count":0,"forks_count":1,"subscribers_count":3,"default_branch":"main","last_synced_at":"2025-11-10T01:02:00.397Z","etag":null,"topics":["solarwinds","solorigate","sunburst","threat-intelligence","unc2452"],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/subfission.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2020-12-17T00:52:50.000Z","updated_at":"2021-10-18T13:36:32.000Z","dependencies_parsed_at":null,"dependency_job_id":"83e0ef9f-2701-481a-a09b-78b009635adc","html_url":"https://github.com/subfission/SUNBURST-Data-Aggregation","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/subfission/SUNBURST-Data-Aggregation","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/subfission%2FSUNBURST-Data-Aggregation","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/subfission%2FSUNBURST-Data-Aggregation/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/subfission%2FSUNBURST-Data-Aggregation/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/subfission%2FSUNBURST-Data-Aggregation/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/subfission","download_url":"https://codeload.github.com/subfission/SUNBURST-Data-Aggregation/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/subfission%2FSUNBURST-Data-Aggregation/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29935368,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-28T13:16:57.922Z","status":"ssl_error","status_checked_at":"2026-02-28T13:11:15.149Z","response_time":90,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["solarwinds","solorigate","sunburst","threat-intelligence","unc2452"],"created_at":"2024-12-13T06:09:55.430Z","updated_at":"2026-02-28T13:33:03.107Z","avatar_url":"https://github.com/subfission.png","language":null,"funding_links":[],"categories":[],"sub_categories":[],"readme":"# SUNBURST Data Aggregation\nThe following is an aggregation of threat intel sources for the **SolarWinds Orion** (**SUNBURST**) attack.\n\n*Note: I do not own, maintain, or make no claim as to the validity or safety of these resources.*\n\n## Open Source Resources\n 1. [Mandiant SunBurst Countermeasures by FireEye](https://github.com/fireeye/sunburst_countermeasures)\n 2. [Suburst DGA Domains Decoded](https://github.com/5u3e10px/Suburst-DGA-Domains-Decoded)\n 3. [Decompile of the Solorwinds \"SUNBURST\" Trojan associated with Campaign UNC2452 by Shadow0ps](https://github.com/Shadow0ps/solorigate_sample_source)\n 4. [Sunburst IOCs for Splunk Ingest by davisshannon](https://github.com/davisshannon/Splunk-Sunburst)\n 5. [Various indicator lists and/or free research tools provided by Bambenek Labs](https://github.com/bambenek/research)\n 6. [SunBurst DGA Decode Script by RedDrip7](https://github.com/RedDrip7/SunBurst_DGA_Decode)\n 7. [SunBurst sample detonation review by ept-team](https://github.com/ept-team/sunburst)\n 8. [Quick lookup files for SUNBURST Backdoor by rkovar](https://github.com/rkovar/sunburstlookups)\n 9. [Alienvault OTX Threat Intel](https://otx.alienvault.com/pulse/5fd6df943558e0b56eaf3da8)\n10. [Azure-Sentinel-Notebooks Guided Hunting - Solarwinds Post Compromise](https://github.com/Azure/Azure-Sentinel-Notebooks/blob/fdcc923d15d9aeb9f99bf78ed66d9fb0de29b3d6/Guided%20Investigation%20-%20Solarwinds%20Post%20Compromise%20Activity.ipynb)\n11. [Credential Dumping Tool for SolarWinds Orion by mubix](https://github.com/mubix/solarflare)\n12. [Powershell script to decode the DGA algorithm used in the SUNBURST backdoor by Truesec](https://github.com/Truesec/sunburst-decoder)\n\n## News Media\n- [FireEye Threat Research - Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor](https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html)\n- [FireEye Shares Details of Recent Cyber Attack, Actions to Protect Community](https://www.fireeye.com/blog/products-and-services/2020/12/fireeye-shares-details-of-recent-cyber-attack-actions-to-protect-community.html)\n- [FireEye Identifies Killswitch for SolarWinds Malware as Victims Scramble to Respond](https://www.darkreading.com/attacks-breaches/fireeye-identifies-killswitch-for-solarwinds-malware-as-victims-scramble-to-respond/d/d-id/1339746)\n- [DomainTools - Unraveling Network Infrastructure Linked to the SolarWinds Hack](https://www.domaintools.com/resources/blog/unraveling-network-infrastructure-linked-to-the-solarwinds-hack)\n- [Hackers used SolarWinds' dominance against it in sprawling spy campaign](https://www.reuters.com/article/us-global-cyber-solarwinds/hackers-at-center-of-sprawling-spy-campaign-turned-solarwinds-dominance-against-it-idUSKBN28P2N8)\n- [Microsoft - Ensuring customers are protected from Solorigate](https://www.microsoft.com/security/blog/2020/12/15/ensuring-customers-are-protected-from-solorigate/)\n- [Solorigate: SolarWinds Orion Platform Contained a Backdoor Since March 2020 (SUNBURST)](https://www.tenable.com/blog/solorigate-solarwinds-orion-platform-contained-a-backdoor-since-march-2020-sunburst)\n- [The SolarWinds Perfect Storm: Default Password, Access Sales and More](https://threatpost.com/solarwinds-default-password-access-sales/162327/)\n- [Rapid7 - SolarWinds SUNBURST Backdoor Supply Chain Attack: What You Need to Know](https://blog.rapid7.com/2020/12/14/solarwinds-sunburst-backdoor-supply-chain-attack-what-you-need-to-know/)\n- [Unit42 - Threat Brief: SolarStorm and SUNBURST Customer Coverage](https://unit42.paloaltonetworks.com/fireeye-solarstorm-sunburst/)\n- [Dark Halo Leverages SolarWinds Compromise to Breach Organizations](https://www.volexity.com/blog/2020/12/14/dark-halo-leverages-solarwinds-compromise-to-breach-organizations/)\n- [Talos - Threat Advisory: SolarWinds supply chain attack](https://blog.talosintelligence.com/2020/12/solarwinds-supplychain-coverage.html)\n- [Cnet - SolarWinds hack hits major tech companies and hospital system: What you need to know](https://www.cnet.com/news/solarwinds-hack-hits-major-tech-companies-and-hospital-system-what-you-need-to-know/)\n- [ZDNet - A second hacking group has targeted SolarWinds systems](https://www.zdnet.com/article/a-second-hacking-group-has-targeted-solarwinds-systems/)\n- [Cisco targeted in SolarWinds attack as Microsoft uncovers a second hacking group](https://siliconangle.com/2020/12/20/cisco-targeted-solarwinds-attack-microsoft-uncovers-second-hacking-group/)\n- [Bloomberg - SolarWinds Adviser Warned of Lax Security Years Before Hack](https://www.bloomberg.com/news/articles/2020-12-21/solarwinds-adviser-warned-of-lax-security-years-before-hack)\n- [TRUESEC - The SolarWinds Orion SUNBURST supply-chain Attack](https://blog.truesec.com/2020/12/17/the-solarwinds-orion-sunburst-supply-chain-attack/)\n\n## Social Media\n- [Twitter #UNC2452](https://twitter.com/hashtag/UNC2452)\n- [Twitter #SUNBURST](https://twitter.com/hashtag/SUNBURST)\n- [Twitter #SolarWindsOrion](https://twitter.com/hashtag/SolarWindsOrion)\n- [Twitter #solarwinds123](https://twitter.com/hashtag/solarwinds123)\n- [Twitter #solorigate](https://twitter.com/hashtag/solorigate)\n- [Twitter #SolarWindsHack](https://twitter.com/hashtag/SolarWindsHack)\n\n## Cybersecurity and Infrastructure Security Agency (CISA)\n- [Emergency Directive 21-01](https://cyber.dhs.gov/ed/21-01/)\n- [Security Advisory - Active Exploitation of SolarWinds Software](https://us-cert.cisa.gov/ncas/current-activity/2020/12/13/active-exploitation-solarwinds-software)\n- [Alert (AA20-352A) Advanced Persistent Threat Compromise of Government Agencies, Critical Infrastructure, and Private Sector Organizations](https://us-cert.cisa.gov/ncas/alerts/aa20-352a)\n\n## Vendor Security Resources\n- [Elastic Security provides free and open protections for SUNBURST](https://www.elastic.co/blog/elastic-security-provides-free-and-open-protections-for-sunburst)\n- [Finding SUNBURST backdoor with Zeek logs \u0026 Corelight](https://corelight.blog/2020/12/15/finding-sunburst-backdoor-with-zeek-logs-and-corelight/)\n- [Using Splunk to Detect Sunburst Backdoor](https://www.splunk.com/en_us/blog/security/sunburst-backdoor-detections-in-splunk.html)\n- [Microsoft - Important steps for customers to protect themselves from recent nation-state cyberattacks](https://blogs.microsoft.com/on-the-issues/2020/12/13/customers-protect-nation-state-cyberattacks/)\n- [SANS Emergency Webcast: What you need to know about the SolarWinds Supply-Chain Attack](https://www.youtube.com/watch?v=qP3LQNsjKWw)\n- [Corelight: Finding SolarWinds / SUNBURST backdoors with Zeek \u0026 Corelight](https://www.youtube.com/watch?v=zGlxC-nGEzE)\n\n## Hotfix\n- [SolarWinds Hotfix 2](https://support.solarwinds.com/SuccessCenter/s/article/Orion-Platform-2020-2-1-Hotfix-2?language=en_US)\n\n\nPlease use this to protect yourself and your assets.  Feel free to add pull requests for additional resources.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsubfission%2Fsunburst-data-aggregation","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fsubfission%2Fsunburst-data-aggregation","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsubfission%2Fsunburst-data-aggregation/lists"}