Blogs
TsaiMerr
Staff
Staff

We are continuously the data disclosed by FireEye on the “Sunburst”/UNC2452 operation and working with customers ensure their protection, detect and mitigate this issue.

All published and subsequent discovered IOCs were immediately added to our FortiGuard threat intelligence network will be leveraged by solutions including FortiGate, FortiAnalyzer, FortiEDR, FortiSandBox, FortiSIEM and FortiClient.  As new IOCs are uncovered, they will also be immediately added to our databases.

 

Here is a summary of resources and how to stay current with the Fortinet products and solutions you have to ensure your protection and on-going detection.

 

FortiGatge customers,  make sure you run for full protection

 

FortiAnalyzer development has created special reports and an event handler to help a customer identify issues related to SolarWinds:

  • New FAZ Report:  Historical report to scan back to see if any connection to the Command & Control sites – FNDN Community:  Go
  • New FAZ Event Handler:  New event handler to trigger on the same events (raise incident, alert email, etc.) - FNDN Community:  Go

 

FortiEDR customers were natively protected from this attack on any system running FortiEDR no change or upgrade is required.   And here are the best practices:

  • Make sure to set post-execution policies to blocking mode. This will allow you to block malicious behavior even if the system is already compromised through a trusted source, such as this supply chain attack. 
  • Apply contextual pre-canned policies that can enable proactive actions in case of malicious or inconclusive activities. In this case, these actions would have removed the associated DLL file. 
  • If you subscribe to the MDR service or were not in protection mode at the time of the attack, please work with the MDR team to assist you with proactive threat hunting. 

 

FortiSIEM customer – you can access FortiSIEM Forensic Report in this community discussiohttps://fusecommunity.fortinet.com/groups/community-home/digestviewer/viewthread?MessageKey...