Mathias R. Jessen Profile picture
frequent victim of nerd sniping; #PowerShell aficionado; blue teamer; black metal fanatic; (awful) drummer; ADHD galore; he/him; #tweetsizedoneliners
Dec 17, 2020 14 tweets 4 min read
No DNS logs?

Next best activity indicator seems to be file-write events to `SolarWindows.Orion.Core.BusinessLayer.dll.config` (used to track detection and modification of forensic/anti-tamper services)

... but you probably don't track those either 😉 #SolarWinds #SUNBURST Couple of colleagues also reported seeing reports that the config file should contain a setting key'd `ReportStatus`.

Looking at the March sample (32519b85..107d6c77) This is NOT true, the key names in the file on disk starts with `ReportWatcher`, not `ReportStatus`