This 5min video outlines some of the aspects of the SolarWinds Orion software platform being compromised by a highly sophisticated threat actor.
The content of the video is reflecting my understanding of the facts documented by SolarWinds security advisory and the Microsoft Blog for customer guidance available by midday 16-Dec-2020 CET. Read as well the advisory of US CERT.
The video shall help understanding the complexity of the attack and encourage to follow the guidelines given by SolarWinds and Microsoft.
The Check Point response to this attack is published in sk171000 and I encourage to monitor this article. Check Point released an IPS signature 'Sunburst Backdoor Suspicious Traffic', Anti-Virus, Anti-Bot and Threat Emulation functionalities covering this threat.