SANS Emergency Webcast: What you need to know about the SolarWinds Supply-Chain Attack

Subscribers:
64,099
Published on ● Video Link: https://www.youtube.com/watch?v=qP3LQNsjKWw



Duration: 58:01
169,199 views
3,243


On Dec 13, 2020, Solarwinds, an IT company that creates software for network management, stated they were investigating an incident that appears to be the product of a “highly-sophisticated, targeted and manual supply chain attack by a nation-state.” SolarWinds said they are in contact with the FBI and that a vulnerability which existed until the March-June 2020 timeframe was leveraged to take advantage of their Orion software product.

The attack is a supply-chain based attack in which the adversary can leverage the software’s update mechanism. The Solarwinds attack has been linked to the Treasury Department and FireEye compromises at this time.

Information is being released continuously by those investigating the incidents across the thousands of organizations that use SolarWinds, including governments, militaries, and commercial entities around the world.

As indicators of compromise continue to be released, organizations and their incident response teams should prioritize hunting for adversary behaviors and Tools, Techniques, and Procedures (TTPs) associated with their SolarWinds installs, as that platform could be leveraged as a launching point into their organization.

Participants will learn about:
- The latest information regarding the Solarwind's incident and the mechanics of the supply chain attack.
- Any known detection mechanisms, including IOCs, have been released at this point.
- How the incident could impact organizations that use SolarWinds and where to begin investigations.

Speaker Bio
Jake Williams @malwarejake is a SANS analyst, senior SANS instructor and course author. Jake spent more than a decade in information security roles at several government agencies, developing specialties in offensive forensics, malware development and digital counterespionage. Jake is the founder of Rendition Infosec, which provides penetration testing, digital forensics and incident response, expertise in cloud data exfiltration, and the tools and guidance to secure client data against sophisticated, persistent attacks on-premises and in the cloud.


SANS is the most trusted and by far the largest source for information security training and security certification in the world. It also develops, maintains, and makes available at no cost, the largest collection of research documents about various aspects of information security, and it operates the Internet's early warning system - the Internet Storm Center.




Other Videos By SANS Institute


2021-02-02DNS: What It Is, What It Does, and How to Defend It
2021-02-02Cracking the Mystery: Quantum Cryptography and The Future of Cybersecurity
2021-02-02Cybersecurity is Like Ice Cream. There Are a Whole Lot of Flavors
2021-02-02Can People Hack Nuclear Plants?
2021-01-27Data Protection Day 2021
2021-01-26Data Privacy Day 2021
2021-01-21A Recap from Chris Krebs's Keynote - SANS Cyber Threat Intelligence 2021
2021-01-12SANS Virtual Summits Will Be FREE for the Community in 2021
2020-12-18SANS Security Awareness – Secure the Holidays
2020-12-16Behind The Scenes Of Law Enforcement And Private Industry Cooperation | STAR Webcawst
2020-12-14SANS Emergency Webcast: What you need to know about the SolarWinds Supply-Chain Attack
2020-12-07Making Order out of Chaos: How to Deal with Threat Group Names | STAR Webcast
2020-12-03SANS Foundations - What's James Lyne's favorite part of the new course - Interview with the author
2020-12-03SANS Foundations - How do you balance theory and practical? - An Interview with James Lyne
2020-12-03SANS Foundations - How did you pick the course topics? An interview with the Author, James Lyne
2020-11-23SANS Foundations overview by course author James Lyne
2020-11-18Becoming a CISO: Leading Transformation
2020-11-18SANS Cyber Security Foundations Course
2020-11-12New Five Day Security Culture Course | MGT521 | SANS Institute
2020-11-06Good on Paper: Packaging Your Skills and Experience (Panel)
2020-11-04Authentic at Work: Bringing Your Whole Self to Work in Infosec & Tech | Christina Morillo



Tags:
sans institute
information security
cyber security
cybersecurity
information security training
cybersecurity training
cyber security training
solarwinds
solarigate
#SUNBURST
solarwinds orion
solarwinds incident
solarwinds vulnerability