The SolarWinds attack: A contrarian view and lessons learned

To understand how undetectable the SolarWinds attacks was(n’t), it is vital to understand how a sophisticated cyber-attack works, how attackers move through systems and how even the most sophisticated attack can be detected if Detection and Response measures have been set up right. With this publication Hunt & Hackett does not claim that it would have detected the SolarWinds attack with our MDR-service while the attack was ongoing. We analyze such attacks with the aim to improve our understanding, and to see whether lessons can be learned from it to improve our detection capabilities. When we feel it provides meaningful new insights than we like to share our these insights with the wider security community such as with this blog.

