← Blog

Post-SolarWinds: The Impact of Nation-State Attacks on DNS Security

How the SolarWinds supply chain attack reshaped thinking about DNS monitoring and defense-in-depth.

The SolarWinds attack, disclosed in December 2020, was a watershed moment for cybersecurity. A nation-state actor compromised the SolarWinds Orion build process, inserting a backdoor (SUNBURST) into legitimate software updates. When organizations installed the update, the backdoor activated — communicating with attacker-controlled infrastructure via DNS before establishing a full C2 channel.

SUNBURST's DNS communication was sophisticated. It encoded victim information in subdomain queries to avsvmcloud.com, using DNS as a covert communication channel. The malware used DNS to determine whether to activate, which C2 server to contact, and what actions to take. This DNS-first communication pattern made DNS logs one of the earliest and most reliable indicators of compromise.

Organizations with comprehensive DNS logging were able to determine their exposure quickly. Those who logged all DNS queries could search for avsvmcloud.com subdomains and immediately identify affected endpoints. Organizations without DNS logging had to rely on slower indicators — endpoint scans, network flow analysis, and forensic imaging.

The SolarWinds attack reinforced several DNS security principles. First, log everything — comprehensive DNS logging enables rapid incident response when new indicators emerge. Second, monitor for anomalous DNS patterns — SUNBURST's encoded subdomain queries were anomalous even before the specific indicator was published. Third, DNS is a primary attack communication channel — defending it is not optional.

Securd's architecture directly addresses lessons from SolarWinds. Comprehensive DNS logging captures every query for analysis. The Greywall would have flagged the initial DNS beacons to avsvmcloud.com subdomains as first-seen domains. Threat feed ingestion allows organizations to immediately block newly published IOCs at the DNS layer. And the audit trail ensures that any security policy changes made in response to an incident are documented and reversible.

Evaluate Agent DNS with your own agent traffic

Deploy on a single policy in learning mode and review the results with your security team.