Welcome, Guest
You have to register before you can post on our site.

Username
  

Password
  





Search Forums

(Advanced Search)

Forum Statistics
» Members: 20,946
» Latest member: blackopsdlc
» Forum threads: 22,013
» Forum posts: 22,980

Full Statistics

Online Users
There are currently 2911 online users.
» 0 Member(s) | 2906 Guest(s)
Applebot, Baidu, Facebook, Google, Yandex

Latest Threads
When does Godzilla releas...
Forum: PC Discussion
Last Post: xSicKxBot

» Replies: 0
» Views: 11
[WoW Retail News] Ula'tek...
Forum: World of Warcraft
Last Post: xSicKxBot

» Replies: 0
» Views: 12
[DevBlog MS] Microsoft is...
Forum: C#, Visual Basic, & .Net Frameworks
Last Post: xSicKxBot

» Replies: 0
» Views: 16
[WoW Retail News] BlizzCo...
Forum: World of Warcraft
Last Post: xSicKxBot

» Replies: 0
» Views: 18
What is Celestial Codex i...
Forum: PC Discussion
Last Post: xSicKxBot

» Replies: 0
» Views: 21
[Ubuntu News] Fine tune y...
Forum: Linux, FreeBSD, and Unix types
Last Post: xSicKxBot

» Replies: 0
» Views: 15
[WoW Retail News] Xal'ata...
Forum: World of Warcraft
Last Post: xSicKxBot

» Replies: 0
» Views: 33
[Ubuntu News] Scaling And...
Forum: Linux, FreeBSD, and Unix types
Last Post: xSicKxBot

» Replies: 0
» Views: 25
[WoW Retail News] Comment...
Forum: World of Warcraft
Last Post: xSicKxBot

» Replies: 0
» Views: 25
How to unlock Maya Aguina...
Forum: PC Discussion
Last Post: xSicKxBot

» Replies: 0
» Views: 33

 
  News - Feature: The Best Hidden Gems And Overlooked Switch Games Of 2020
Posted by: xSicKxBot - 12-29-2020, 12:11 AM - Forum: Nintendo Discussion - No Replies

Feature: The Best Hidden Gems And Overlooked Switch Games Of 2020

Another year, another huge pile of excellent new vidya games sitting on Switch eShop. If you managed to play everything that caught your eye this year, we’re deeply envious! With so many great games, it was once again hard to keep up, even when many people found themselves with some unexpected free time in 2020.

Yes, this year we were once again spoiled for choice and forced to deal with the terrible reality of too many great games and not enough time. It’s the holiday season now, though, so if you’re sitting back and wondering what to play, we’d like to point you towards the twenty gems below that you might have missed — the best hidden gems on Switch in 2020.

We’ve asked for recommendations from Nintendo Life readers on a couple of occasions, but every single one of the games below was reviewed by Nintendo Life and scored at least an 8/10 (one of them even got the very top score possible!). We’re more than happy to highlight them again in this end of year period (as we did last year) in the hope that you’re able to catch them before the first haul of 2021 arrives imminently.

If any of the titles below are already part of your Switch library, bully for you! If, however, you’re looking for something to play and these gems passed you by, they’re sitting there right now on the Switch eShop. Enjoy!

Horace (Switch eShop)Horace (Switch eShop)

Publisher: 505 Games / Developer: Paul Helman

Release Date: 21st Oct 2020 (USA) / 21st Oct 2020 (UK/EU)

Horace is something very special — the only vaguely negative thing we can say about it is the fact that there are so many spectacularly brilliant indie games on Switch already vying for your attention that we fear Horace may fall somewhat by the wayside. If you have any interest in superb level design, excellent storytelling, terrific art, evocative music, great characters, hilarious situations and emotional gut-punches, Horace is a no-brainer. It’s moving without being manipulative, clever without being smug, and nostalgic without being a lazy rehash. It’s a platformer, but it’s so much more than that.

So yes, Horace is another indie masterpiece, and every gamer who enjoys quality experiences should play it; a masterpiece that owes so much to its medium, but has the strength, creativity and identity to stand alone as something very, very special. Buy this. Check out our interview with the two-person development team if you need more convincing.

Bug Fables: The Everlasting Sapling (Switch eShop)Bug Fables: The Everlasting Sapling (Switch eShop)

Publisher: DANGEN Entertainment / Developer: Moonsprout Games

Release Date: 28th May 2020 (USA) / 28th May 2020 (UK/EU)

Developer Moonsprout Games was probably relieved to get this loving homage to Nintendo’s Paper Mario series out the door and on the eShop before The Origami King was announced just a couple of months later. Bug Fables is a superbly polished independent tribute to the first two Paper Mario games – but that’s not to say it doesn’t have its own, strong identity. The sheer familiarity is a little bit wearying at times – seriously, it’s like it’s been traced over in places – but Paper Mario with the serial numbers filed off is still a very good time. There’s plenty to see and do, a rather compulsive card game to play and hidden secrets all over the place. Add all this silky-smooth performance, a splendid soundtrack and turn-based combat that’s never less than engaging and you’ve got a surefire winner here.

Evergate (Switch eShop)Evergate (Switch eShop)

Publisher: PQube / Developer: Stone Lantern Games

Release Date: 18th Aug 2020 (USA) / 18th Aug 2020 (UK/EU)

Evergate is a wonderfully designed puzzle/platformer that starts off strong and goes from strength to strength over the course of its campaign. Every new world you encounter here adds a new twist to proceedings, gradually becoming more complex as it layers mechanics on top of one each other, enabling you to experiment and come up with your own unique ways to bound across its intricate levels. Speed-running here, for us, feels like it was tacked on for no real reason but, besides this one little misstep, this really is an essential purchase for puzzle/platforming fans and a standout example of its genre on Switch.

Check out our interview with Stone Lantern if you’re after more information on the story behind the game.

To The Moon (Switch eShop)To The Moon (Switch eShop)

Publisher: X.D. Network / Developer: Freebird Games

Release Date: 16th Jan 2020 (USA) / 16th Jan 2020 (UK/EU)

To The Moon is a powerful interactive story. It’s a short game but it manages to make its players directly confront uncomfortable situations and emotions with which we’ll all struggle at some point in our lives. Mental illness, death, heartbreak, tragedy… it’s all in here, and handled honestly within a brilliant narrative setup that allows us to watch a lifetime deconstructed, layer by layer, revealing the very human mistakes and unavoidable interruptions of fate that shape how our lives ultimately turn out. All in a matter of four or five hours.

Wunderling (Switch eShop)Wunderling (Switch eShop)

Publisher: Retroid Interactive / Developer: Retroid Interactive

Release Date: 5th Mar 2020 (USA) / 5th Mar 2020 (UK/EU)

By removing the basic ability to turn direction whilst walking, Wunderling proves itself to be an incredibly addictive ‘Goomba-sim’ platformer that boasts excellent level design, brilliant writing, and adorable visuals. Its impressive accessibility means that almost anyone can pick it up, but it simultaneously remains challenging enough to keep you engaged for hours.

Check out our interview with developer Retroid for more details on this cute little platformer.

Stories Untold (Switch eShop)Stories Untold (Switch eShop)

Publisher: Devolver Digital / Developer: No Code

Release Date: 16th Jan 2020 (USA) / 16th Jan 2020 (UK/EU)

Stories Untold is a chilling adventure that manages to draw us right into its world through the ingenious use of its UI and perfectly realised lo-fi aesthetic. Through the walls of old technology and complicated machinery, it creates a uniquely strong bond between player and narrative, giving you a real sense of place within its world as it slowly corrupts and twists from the comfortingly familiar to something else entirely. It’s one of the best interactive horror stories we’ve ever played and a perfect fit for enjoying alone in the dark on Switch.

Good Job! (Switch eShop)Good Job! (Switch eShop)

Publisher: Nintendo / Developer: Paladin Studios

Release Date: 26th Mar 2020 (USA) / 26th Mar 2020 (UK/EU)

Good Job! Is a wonderful surprise that everyone should try out. Thanks to its hilarious physics, seemingly menial tasks have the potential to descend into utter carnage – whether intentional or not – and its grading system means there are plenty of opportunities to replay. Slight technical hiccups aside, Good Job! is absolutely guaranteed to have you in fits of laughter.

In Other Waters (Switch eShop)In Other Waters (Switch eShop)

Publisher: Fellow Traveller / Developer: Jump Over The Age

Release Date: 3rd Apr 2020 (USA) / 3rd Apr 2020 (UK/EU)

A very pleasant surprise indeed, In Other Waters is a bit of a minimalist masterpiece that you’ll often want to dip into for a more contemplative experience than the majority of the Switch’s library. It has found a perfect home on the handheld, the form factor of which massively works in the favour of the game’s mood and atmosphere to create an exceptional and unique experience. What you’re getting here is a story that you’re an integral part of, and it’s one of the coolest, cleverest games we’ve played in a long time. An absolutely first-class effort.

Lonely Mountains: Downhill (Switch eShop)Lonely Mountains: Downhill (Switch eShop)

Publisher: Thunderful / Developer: Megagon

Release Date: 7th May 2020 (USA) / 7th May 2020 (UK/EU)

An exquisite bike racer-cum-trials game with tight controls, varied courses, and uniquely zen-like presentation. At once calming and demanding, Lonely Mountains: Downhill looks and feels like no other game on the eShop. Barring one or two disappointing technical issues, it’s an absolute freewheeling delight.

Afterparty (Switch eShop)Afterparty (Switch eShop)

Publisher: Night School Studio / Developer: Night School Studio

Release Date: 3rd Mar 2020 (USA) / 3rd Mar 2020 (UK/EU)

Afterparty is certainly an acquired taste, but—like a fine wine or a good beer—it’s definitely worth the effort. From beginning to end, Night School’s follow up to Oxenfree is a thoroughly enjoyable narrative experience that draws you into a hellish world that you (ironically) won’t want to leave. Branching paths and a smartly implemented drink system add plenty of options for replayability, and though the performance leaves something to be desired, Afterparty proves itself to be a visual treat. We’d give Afterparty a high recommendation to anyone looking for a good story to immerse themselves in; this is one that goes down real smooth.

Check out our interview with Sean Krankel from Night School for some behind-the-scenes thoughts.



https://www.sickgaming.net/blog/2020/12/...s-of-2020/

Print this item

  News - Trump Pardons Congressman Who Spent Campaign Money On Steam Games
Posted by: xSicKxBot - 12-29-2020, 12:11 AM - Forum: Lounge - No Replies

Trump Pardons Congressman Who Spent Campaign Money On Steam Games

Former Republican congressman Duncan Hunter won't serve any time in prison for spending campaign funds on video games and other personal items for his family.

Hunter is one of 15 convicted criminals to receive a full pardon from President Donald Trump earlier this week. The son of prominent Republican politician Duncan Lee Hunter served as a US Representative for California's 50th congressional district from 2013 until resigning in early 2020 after pleading guilty to misusing campaign funds.

Hunter was sentenced to 11 months in prison after it was found out that he spent over $250,000 in campaign funds on luxury hotels, vacations, and other personal expenses. He even purchased plane tickets for his pet rabbits, named Eggburt and Cadbury. However, the politician never began his stint behind bars as the COVID-19 pandemic delayed his imprisonment until January 4, 2021.

Continue Reading at GameSpot

https://www.gamespot.com/articles/trump-...01-10abi2f

Print this item

  Xbox Wire - Secret Neighbor Winter Holidays Update is Here
Posted by: xSicKxBot - 12-28-2020, 08:56 PM - Forum: Xbox Discussion - No Replies

Secret Neighbor Winter Holidays Update is Here

Seasons Greetings, friends!

For any new home invaders in our midst, Secret Neighbor is an online multiplayer social horror game where the goal is to work together with other players to get into your suspicious neighbor’s basement. This isn’t just any senseless breaking and entering though, he’s hiding something and it’s up to you and the other kids to find out what. There’s only one problem, one of your friends is the neighbor in disguise…

With the most festive of holiday seasons just around the corner we’ve got some special surprises to drop under the tree, and you won’t even have to wait until Christmas day to unwrap them! So let’s dive in!

Secret Neighbor Winter Holidays Update

Do you want to build a snowman? ❄️

There’s nothing better than waking up to a snow day, and it looks like Raven Brooks has gotten its first snow of the year! In this winter update you’ll find the spooky decor swapped for something with a little more holiday cheer. The halls are decked, the gifts are wrapped with care, and you can deck someone with carefully wrapped gifts… wait.

Possible personal injury cases aside, we invite you to engage in more chilly shenanigans by building a snowman. You can create up to four sizes of snowballs, and can use these to build your own snow-army… or you can throw them into the faces of the nearest unsuspecting player. Your call.

Secret Neighbor Winter Holidays Update

Speaking of throwing, what’s a holiday season without snowball fights with your friends? So grab a couple of snowballs and send ‘em flying! Just be sure to hop back indoors and warm up every so often.

No we didn’t get you a pony

Snowballs and snowmen are cool, but they aren’t the star on top of the tree. We have a special present for all our OG Hello Neighbor fans and lore hounds this year and it comes in the form of a new map! The new map is based on the neighbor’s house from Act 1 of Hello Neighbor and… the basement is open?!

Secret Neighbor Winter Holidays Update

We know you’ve always wondered what is actually in the basement, and now you can see for yourself! Explore the Peterson house and creep through the basement for more clues. But just because you’ve made it to the basement doesn’t mean the story is over. If you know what you’re looking for it may help to shed some light on the neighbor, Nicky’s disappearance, and the bigger mystery of what is going on in Raven Brooks. But be careful that you don’t wind up with more questions than answers.

Bundle up boys and girls!

Of course with every holiday update there are plenty of new cosmetics to nab. This year we’re bringing double denim back, and we’re not in the least bit sorry. You can find a set of denim digs for every kid class, as well as a few new standalone outfits for them. The new Butcher Neighbor class also gets a bit spoiled this update with a couple of new outfits!

Secret Neighbor Winter Holidays Update

We’ve got lots to unwrap this holiday season so keep a sharp eye out, stay warm, and we hope you enjoy the new Secret Neighbor Winter update!

Xbox LiveXbox Live

Secret Neighbor


tinyBuild

200

$19.99 $7.99
Xbox Game Pass

A group of kids are trying to break into their suspicious Neighbor’s basement to rescue their missing friend. Only problem is that one of the kids is a traitor – a Secret Neighbor in disguise. His job is to gain the trust of other players and betray them. Kids win if they get into the basement. Playing as a child: – Collect keys
– Save you friends from the Neighbor
– Cooperate but don`t trust anyone If you are lucky enough to play as Neighbor: – The house is your territory! Use it to separate, scare and confuse intruders.
– Use your gadgets to get advantage over the kids’ team.
– Gain trust amongst your foes and attack in the right moment.
– Protect your basement!



https://www.sickgaming.net/blog/2020/12/...e-is-here/

Print this item

  News - Nier: Automata surpasses 5 million shipped
Posted by: xSicKxBot - 12-28-2020, 08:56 PM - Forum: Lounge - No Replies

Nier: Automata surpasses 5 million shipped

Newsbrief: Square Enix and Platinum Games’ Nier: Automata has now surpassed 5 million copies shipped and sold digitally since the game first launched on PlayStation 4 and PC in 2017 and on Xbox One in 2018.

Helped along by a Game of the YoRha Edition re-release last year, Nier has steadily crossed sales milestones over the past few years. It surpassed 3 million shipped in June 2018, 4 million in May 2019, and now 5 million in December 2020.

Square Enix also currently has a remake of Automata predecessor dubbed Nier: Replicant in the works, currently expected to launch in April 2021.



https://www.sickgaming.net/blog/2020/12/...n-shipped/

Print this item

  News - Gamasutra’s Best of 2020: Kris Graft’s top 5 games (+1)
Posted by: xSicKxBot - 12-28-2020, 08:56 PM - Forum: Lounge - No Replies

Gamasutra’s Best of 2020: Kris Graft’s top 5 games (+1)

I’ll spare you the ‘2020 was such a mess’ bit here and just say that I am so glad that these games came out this year.

The ones that resonated with me the most were games that connected me with other people, that encouraged persistence in the face of hell itself, and intimate stories that would be lessened if told in any other format other than video games. I was drawn to joyful games that generously doled out doses of comfort. Here are a few great games I played in 2020.

I’ve played Animal Crossing games in the past, but they never clicked with me like they did with so many other people. Animal Crossing: New Horizons changed that. When lockdowns were just beginning, opening my gates or visiting the islands of my Twitter friends gave me a a feeling of connectedness and presence that no other video game provided this year.

Every aspect of New Horizons is designed to exude joy, whether it’s your villager’s puns about fish, or the music that I’d turn the game on just to listen to. New Horizons turns simple actions into memorable interactions. Friends would come over soon after the game launched, and exchange some bells or fruit as they farmed resources from your own island and when that was first happening, it conveyed a kindess as real as any analog interaction. When a friend invited me over to see their aquarium before I had built mine, we took selfies and just sat together and watched fish swim.

There are a lot of simple memories like this that I and so many other people experienced in New Horizons, and how fortuitous that this game came out when it did.

Among the most universally-praised games of 2020 is Hades, Supergiant Games’ latest effort and proof positive that this studio is something special. Hades takes everything people love about roguelikes (replayability, predictable controls, tough but fair challenge) and smooths out the qualms that many have with the genre (repetitiveness, frustration, little to no narrative progression or character development).

Other games have approached character death or endgame states in unique ways as well, but Hades is a standout example. The game loop is intertwined with the narrative in such a way that one cannot exist without the other. Death loses its sting when you realize that dying pushes the story forward and develops not only Zagreus as a character, but all of the gods and monsters he encounters along the way.

This is a game explicitly designed around failure. When you fail, what you lose in terms of your current build and level progression, you gain in story development and access to new skills and abilities. Failure ensures a tradeoff that feels fair, and gives the player immediate encouragement to try another run. And that kind of positive persistence is something we can all relate to this year.

If Found… is an intimate coming of age story about a young trans woman named Kasio who’s trying to find her place in the world, who’s searching for a basic acceptance from friends and family; the kind of acceptance that many of us take for granted. As you take a journey through her diary–which you interact with by swooping an eraser across pages, making memories disappear–you learn about the ups and downs she experiences with the people she cares most about.

If Found‘s story about growing up queer in 1990s rural Ireland has a gentleness that makes it easy to empathize with Kasio. You’re angered on her behalf when she is wronged, sad when she’s lost and alone, happy when she finds joy.

The writing is absolutely brilliant and the player feels as if they were invited to peruse someone’s life and thoughts, all without feeling voyeuristic. The hand drawn art is a perfect complement to the game’s emotive writing and the music absolutely ties it all together (and can and should be listened to even when not playing the game). If Found… is soulful, energetic, and contemplative. It’s optimistic in the face of seemingly insurmountable challenges, and you should play it.

A number of games from this year help define certain periods of pandemic lockdown, and for us, the Jackbox Party Pack series occupied that early part of the pandemic. Remember back then? Regularly-scheduled happy hours with friends, family and coworkers. An apprehension about the months to come but a belief that “we’re all in this together.” Confusion about face masks, navigating mass toilet paper shortages, and the tendency to disinfect absolutely everything.

We’ve got more toilet paper now, but we got that in exchange for a dose of reality. But throughout the waves of anxiety Jackbox has been a welcome escape from the world while bringing family and friends together virtually.

While we’ve played every single Jackbox Party Pack this year as well as standalone Jackbox games like Quiplash and Fibbage, this year’s Jackbox Party Pack 7 is notable on its own. Made partially under remote working conditions, Party Pack 7 is a rare iteration of the franchise where every single game is pure gold. Whether it’s Talking Points (essentially an improvised presentation party), The Devils and the Details (a collaborative game where you’re part of a family of demons), or the classic word game Quiplash 3, Party Pack 7 is the best collection yet. It’s something we look forward to playing with friends and family when we’re not confined to our little Zoom phantom zones.

Yakuza: Like a Dragon is one of those games that has notable flaws–there are pacing issues, the grind can get tiresome, and it’s impossible to ignore the problematic issues that continue in the series regards to portrayal of women.

Ok, that’s a difficult intro to claw back from when making a game of the year argument. But the fact is that overall, Like a Dragon is an utter joy. Even in moments when protagonist Ichiban Kasuga is scraping rock bottom and making bad decisions there is something effervescent and innately playful about him. He’s loud, he wears his own joy and disappointment on his sleeve, he’s child-like. He’s flawed but exhibits moments of self-awareness which allow him to take the initial steps forward to improve himself.

Also notable aside from Ichiban and his small gang of outcasts is the switch from the series’ well-established real-time beat-em-up combat system to a turn-based RPG system. It’s an unexpected change that works surprisingly well. It changes the tenor of the action when compared to previous entries, while still retaining all the bodyslams in enemy encounters. When all the pieces of Like a Dragon are combined, the game is like Ichiban: a little fucked up, but ultimately memorable and so easy to root for.

Yeah, I know. Control originally came out last year and Gamasutra editors as a group even got the game on our top 10 overall list in 2019. But this is my 2020 personal list and I make the rules here (and hey, it came out in streaming form on Amazon Luna and Nintendo Switch this year!). Also: in 2020, time has lost all meaning anyway.

Control is an impressive feat in terms of level design, world-building and storytelling, taking foundational ideas and genre tropes from games and fiction to make a video game that’s unusually unique. The weird world of Control is so fleshed out, it’s something you’d like to see made into not just a game sequel, but a TV series or movie–there are infinite amounts of stories to be told here.

Control is the culmination of all of Remedy’s past work and it’s so good to see a triple-A level game with vision–a game that not only takes risks but executes on the vision successfully. (This is a lot of words when I could’ve just said “Ashtray Maze.”)



https://www.sickgaming.net/blog/2020/12/...5-games-1/

Print this item

  Microsoft - Using Microsoft 365 Defender to protect against Solorigate
Posted by: xSicKxBot - 12-28-2020, 05:07 PM - Forum: Windows - No Replies

Using Microsoft 365 Defender to protect against Solorigate

Microsoft security researchers continue to investigate and respond to the sophisticated cyberattack known as Solorigate (also referred to as Sunburst by FireEye) involving a supply chain compromise and the subsequent compromise of cloud assets. While the related investigations and impact assessments are ongoing, Microsoft is providing visibility into the attack chains and related threat intelligence to the defender community as early as possible so organizations can identify and take action to stop this attack, understand the potential scope of its impact, and begin the recovery process from this active threat. We have established a resource center that is constantly updated as more information becomes available at https://aka.ms/solorigate.

This blog is a comprehensive guide for security operations and incident response teams using Microsoft 365 Defender to identify, investigate, and respond to the Solorigate attack if it’s found in your environment. The description of the attack in this blog is based on current analysis and investigations by researchers across Microsoft, our partners, and the intelligence community who are actively collaborating to respond to the attack. This is an active threat that continues to evolve, and the findings included here represent what we know at the time of publishing. We continue to publish and update intelligence, indicators, tactics, techniques, and procedures (TTPs), and related details as we discover them. The report from the Microsoft Security Response Center (MSRC) includes the latest analysis of this threat, known indicators of compromise (IOCs), and initial recommended defenses, and will be updated as new data becomes available.

This blog covers:

Tracking the cross-domain Solorigate attack from endpoint to the cloud


The Solorigate attack is an example of a modern cross-domain compromise. Since these kinds of attacks span multiple domains, having visibility into the entire scope of the attack is key to stopping and preventing its spread.

This attack features a sophisticated technique involving a software supply chain compromise that allowed attackers to introduce malicious code into signed binaries on the SolarWinds Orion Platform, a popular IT management software. The compromised application grants attackers “free” and easy deployment across a wide range of organizations who use and regularly update the application, with little risk of detection because the signed application and binaries are common and are considered trusted. With this initial widespread foothold, the attackers can then pick and choose the specific organizations they want to continue operating within (while others remain an option at any point as long as the backdoor is installed and undetected). Based on our investigations, the next stages of the attack involve on-premises activity with the goal of off-premises access to cloud resources through the following steps:

  1. Using the compromised SolarWinds DLL to activate a backdoor that enables attackers to remotely control and operate on a device
  2. Using the backdoor access to steal credentials, escalate privileges, and move laterally to gain the ability to create valid SAML tokens using any of two methods:
    1. Stealing the SAML signing certificate (Path 1)
    2. Adding to or modifying existing federation trust (Path 2)
  3. Using attacker-created SAML tokens to access cloud resources and perform actions leading to the exfiltration of emails and persistence in the cloud

Diagram of the high-level Solorigate attack chain

Figure 1. High-level end-to-end Solorigate attack chain

This attack is an advanced and stealthy campaign with the ability to blend in, which could allow attackers to stay under the radar for long periods of time before being detected. The deeply integrated cross-domain security capabilities in Microsoft 365 Defender can empower organizations and their security operations (SOC) teams to uncover this attack, scope out the end-to-end breach from endpoint to the cloud, and take action to block and remediate it. This blog will offer step-by-step guidance to do this by outlining:

  • How indicators of attack show up across endpoints, identity, and the cloud
  • How Microsoft 365 Defender automatically combines alerts across these different domains into a comprehensive end-to-end story
  • How to leverage the powerful toolset available for deep investigation, hunting, and response to enable SOCs to battle the attackers and evict these attackers from both on-premises and cloud environments

Threat analytics: Understanding and responding to active attacks


As soon as this attack was discovered, Microsoft researchers published two threat analytics reports to help organizations determine if they are affected, assess the impact of the attack, and identify actions to contain it.

The reports are published in Microsoft 365 security center, available to all Microsoft Defender for Endpoint customers and Microsoft 365 Defender early adopters. In addition to detailed descriptions of the attack, TTPs, and indicators of compromise (IoCs), the reports provide real-time data aggregated from signals across Microsoft 365 Defender, indicating the all-up impact of the threat to the organization, as well as details about relevant incidents and alerts to initiate investigation on. These reports continue to be updated as additional information becomes available.

Given the significance of this threat, we are making similar relevant Microsoft threat intelligence data, including the updated list of IOCs, available to everyone publicly.  A comprehensive list of guidance and insights is available at https://aka.ms/solorigate.

Screenshot of threat analytics report on Soloriage in Microsoft Defender Security Center

Figure 2. Threat analytics report on Solorigate attack

We recommend Microsoft 365 Defender customers to start their investigations here. After gaining deep understanding of the threat and getting the latest research findings, you can take the following recommended steps:

Find devices with the compromised SolarWinds Orion application


The threat analytics report uses insights from threat and vulnerability management to identify devices that have the compromised SolarWinds Orion Platform binaries or are exposed to the attack due to misconfiguration.

From the Vulnerability patching status chart in threat analytics, you can view the mitigation details to see a list of devices with the vulnerability ID TVM-2020-0002, which was added specifically to help with Solorigate investigations:

Threat and vulnerability management insights on impact of Solorigate

Figure 3. Threat and vulnerability management data shows data on exposed devices

Threat and vulnerability management provides more info about the vulnerability ID TVM-2020-0002, as well as all relevant applications, via the Software inventory view. There are also multiple security recommendations to address this specific threat, including instructions to update the software versions installed on exposed devices.

Screenshot of security recommendations for Solorigate in Microsoft Defender Security Center

Figure 4. Security recommendations from threat and vulnerability management

Investigate related alerts and incidents


From the threat analytics report, you can quickly locate devices with alerts related to the attack. The Devices with alerts chart identifies devices with malicious components or activities known to be directly related to Solorigate. Click through to get the list of alerts and investigate.

Some Solorigate activities may not be directly tied to this specific threat but will trigger alerts due to generally suspicious or malicious behaviors. All alerts in Microsoft 365 Defender provided by different Microsoft 365 products are correlated into incidents. Incidents help you see the relationship between detected activities, better understand the end-to-end picture of the attack, and investigate, contain, and remediate the threat in a consolidated manner.

Review incidents in the Incidents queue and look for those with alerts relevant to this attacker’s TTPs, as described in the threat analytics report (also listed at the end of this blog).

Screenshot of Microsoft Defender Security Center incidents view for Solorigate

Figure 5. Consolidated Incident view for Solorigate

Some alerts are specially tagged with Microsoft Threat Experts to indicate malicious activities that Microsoft researchers found in customer environments during hunting. As part of the Microsoft Threat Experts service, researchers investigated this attack as it unfolded, hunting for associated attacker behaviors, and sent targeted attack notifications. If you see an alert tagged with Microsoft Threat Experts, we strongly recommend that you give it immediate attention.

Screenshot of Microsoft Defender Security Center showing Microsoft Threat Experts detections

Figure 6. Microsoft Threat Experts targeted attack notification

Additionally, Microsoft Threat Experts customers with Experts on demand subscriptions can reach out directly to our on-demand hunters for additional help in understanding the Solorigate threat and the scope of its impact in their environments.

Hunt for related attacker activity


The threat analytics report also provides advanced hunting queries that can help analysts locate additional related or similar activities across endpoint, identity, and cloud. Advanced hunting uses a rich set of data sources, but in response to Solorigate, Microsoft has enabled streaming of Azure Active Directory (Azure AD) audit logs into advanced hunting, available for all customers in public preview. These logs provide traceability for all changes done by various features within Azure AD. Examples of audit logs include changes made to any resources within Azure AD, such as adding or removing users, apps, groups, roles, and policies.  Customers who do not have Microsoft Defender for Endpoint or are not early adopters for Microsoft 365 Defender can see our recommended advanced hunting queries.

Currently, this data is available to customers who have Microsoft Cloud App Security with the Office365 connector. Our intent is to expand availability to more Microsoft 365 Defender customers. The new log data is available in the CloudAppEvents table:

CloudAppEvents
| where Application == “Office 365”

The log data contains activity logs useful for investigating and finding Azure AD-related activities. This data further enriches the CloudAppEvents table, which also has Exchange Online and Microsoft Teams activities.

As part of making this new data available, we also published a handful of relevant advanced hunting queries, identified by the suffix [Solorigate], to the GitHub repo.

Here’s an example query that helps you see when credentials are added to an Azure AD application after ‘Admin Consent’ permissions were granted:

CloudAppEvents
| where Application == “Office 365”
| where ActionType == “Consent to application.”
| where RawEventData.ModifiedProperties[0].Name == “ConsentContext.IsAdminConsent” and RawEventData.ModifiedProperties[0].NewValue == “True”
| extend spnID = tostring(RawEventData.Target[3].ID)
| parse RawEventData.ModifiedProperties[4].NewValue with * “=> [[” dummpy “Scope: ” After “]]” *
| extend PermissionsGranted = split(After, “]”,0)
| project ConsentTime = Timestamp , AccountDisplayName , spnID , PermissionsGranted
| join (
CloudAppEvents
| where Application == “Office 365”
| where ActionType == “Add service principal credentials.” or ActionType == “Update application – Certificates and secrets management “
| extend spnID = tostring(RawEventData.Target[3].ID)
| project AddSecretTime = Timestamp, AccountDisplayName , spnID
) on spnID
| where ConsentTime < AddSecretTime and AccountDisplayName <> AccountDisplayName1

Microsoft 356 Defender advanced hunting can also assist in many of the recommended incident investigation tasks outlined in the blog, Advice for incident responders on recovery from systemic identity compromises.

In the remaining sections, we will discuss select examples of alerts raised by Microsoft 365 solutions that monitor and detect Solorigate activities across the attack chain on endpoint, identity, and the cloud. These are alerts you may encounter when investigating incidents in Microsoft 365 security center if your organization is affected by this threat. We will also indicate activities which are now blocked by Microsoft 365 Defender. Lastly, each section contains examples of hunting queries you will find useful for hunting for various attacker activities in your environment.

Detecting and blocking malware and malicious behavior on endpoints


Diagram showing attack chain on endpoints involving the Solorigate malware

Figure 7. Solorigate attack chain: Initial access and command-and-control

Discovering and blocking backdoor activity


When the compromised SolarWinds binary SolarWinds.Orion.Core.BusinessLayer.dll gets loaded on a device through normal update channels, the backdoor goes through an extensive list of checks to ensure it’s running in an actual enterprise network and not on an analyst’s machine. It then contacts a command-and-control (C2) server using a subdomain that is generated partly with information gathered from the affected device, which means a unique subdomain is generated for each affected domain. The backdoor allows the attackers to remotely run commands on the device and move to the next stages of the attack. For more information, read our in-depth analysis of the Solorigate malware.

Microsoft Defender for Endpoint delivers comprehensive protection against this threat (see full list of detection and protection alerts at the end of this blog). Microsoft Defender Antivirus, the default antimalware solution on Windows 10, detects and blocks the malicious DLL and its behaviors. It quarantines the malware, even if the process is running.

Screenshot of Microsoft Defender Security Center showing alert for blocking of Solorigate malware

Figure 8. Microsoft Defender for Endpoint blocks malicious binaries

If the malicious code is successfully deployed, the backdoor lies dormant for up to two weeks. It then attempts to contact numerous C2 domains, with the primary domain being *.avsvmcloud[.]com. The backdoor uses a domain generation algorithm to evade detection. Microsoft 365 Defender detects and blocks this behavior.

Screenshot of Microsoft Defender Security Center showing alert for malicious network connection

Figure 9. Microsoft Defender for Endpoint prevented malicious C2 callback

Discovering potentially tampered devices


To evade security software and analyst tools, the Solorigate malware enumerates the target system looking for certain running processes, loaded drivers, and registry keys, with the goal of disabling them.

The Microsoft Defender for Endpoint sensor is one of the processes the malware attempts to disable. Microsoft Defender for Endpoint has built-in protections against many techniques attackers use to disable endpoint sensors ranging from hardened OS protection, anti-tampering policies, and detections for a variety of tampering attempts, including “Attempt to stop Microsoft Defender for Endpoint sensor”, “Tampering with Microsoft Defender for Endpoint sensor settings”, or “Possible sensor tampering in memory”.

Successfully disabling Microsoft Defender for Endpoint can prevent the system from reporting observed activities. However, the multitude of signals reported into Microsoft 365 Defender provides a unique opportunity to hunt for systems where the tampering technique used might have been successful. The following advanced hunting query can be used to locate devices that should be reporting but aren’t:

// Times to be modified as appropriate
let timeAgo=1d;
let silenceTime=8h;
// Get all silent devices and IPs from network events
let allNetwork=materialize(DeviceNetworkEvents
| where Timestamp > ago(timeAgo)
and isnotempty(LocalIP)
and isnotempty(RemoteIP)
and ActionType in (“ConnectionSuccess”, “InboundConnectionAccepted”)
and LocalIP !in (“127.0.0.1”, “::1”)
| project DeviceId, Timestamp, LocalIP, RemoteIP, ReportId);
let nonSilentDevices=allNetwork
| where Timestamp > ago(silenceTime)
| union (DeviceProcessEvents | where Timestamp > ago(silenceTime))
| summarize by DeviceId;
let nonSilentIPs=allNetwork
| where Timestamp > ago(silenceTime)
| summarize by LocalIP;
let silentDevices=allNetwork
| where DeviceId !in (nonSilentDevices)
and LocalIP !in (nonSilentIPs)
| project DeviceId, LocalIP, Timestamp, ReportId;
// Get all remote IPs that were recently active
let addressesDuringSilence=allNetwork
| where Timestamp > ago(silenceTime)
| summarize by RemoteIP;
// Potentially disconnected devices were connected but are silent
silentDevices
| where LocalIP in (addressesDuringSilence)
| summarize ReportId=arg_max(Timestamp, ReportId), Timestamp=max(Timestamp), LocalIP=arg_max(Timestamp, LocalIP) by DeviceId
| project DeviceId, ReportId=ReportId1, Timestamp, LocalIP=LocalIP1

Microsoft is continuously developing additional measures to both block and alert on these types of tampering activities.

Detecting hands-on-keyboard activity within an on-premises environment


Diagram showing Solorigate hands-on-keyboard attack on premises

Figure 10. Solorigate attack chain: Hands-on-keyboard attack on premises

After establishing a backdoor connection on an affected device, the attacker’s next goal is to achieve off-premises access to the organization’s cloud services. To do this, they must find a way to gain permissions to those services. One technique we have seen the attackers use is to go after the organization’s Active Directory Federation Services (AD FS) server to obtain the proverbial “keys” to the identity kingdom. AD FS enables federated identity and access management by securely sharing digital identity and entitlement rights across security and enterprise boundaries; effectively, it is the “LSASS for the cloud.” Among other things, AD FS stores the Security Assertion Markup Language (SAML) token signing certificate, which is used to create authorization tokens for users or services in the organization so they can access cloud applications and resources after authentication.

To attack the AD FS infrastructure, the attackers must first obtain appropriate domain permissions through on-premises intelligence gathering, lateral movement, and credential theft. Building from the backdoor described above, the attackers leverage fileless techniques for privilege escalation, persistence, and lateral movement, including evading analysis by using system binaries and exploration tools that masquerade as other benign binaries. The attackers also carefully chose organization-specific command-and-control (C2) domains and use custom organization-specific tool naming and locations.

Microsoft Defender for Endpoint detects a wide array of these attack techniques, allowing SOC teams to track the attacker’s actions in the environment and take actions to contain the attack. The following section covers detections for the techniques used by the attackers to compromise the AD FS infrastructure.

Identifying attacker reconnaissance


Attackers collect data from Active Directory using a renamed version of the utility ADFind, running queries against Domain Controllers as part of the reconnaissance stage of the attack. Microsoft Defender for Endpoint detects this behavior and allows the SOC analyst to track compromised devices at this stage to gain visibility into the information the attacker is looking for.

Screenshot of Microsoft Defender Security Center alert for detection of exploration tools

Figure 11. Microsoft Defender for Endpoint detects usage of masquerading exploration tools

Screenshot of Microsoft Defender Security Center alert for detection of LDAP queries

Figure 12. Microsoft Defender for Endpoint detects usage LDAP query for reconnaissance.

Stopping lateral movement and credential theft


To gain access to a highly privileged account needed for later steps in the kill chain, the attackers move laterally between devices and dump credentials until an account with the needed privileges is compromised, all while remaining as stealthy as possible.

A variety of credential theft methods, such as dumping LSASS memory, are detected and blocked by Microsoft Defender for Endpoint. The example below shows the detection of lateral movement using Windows Management Instrumentation (WMI) to run the attacker’s payload using the Rundll32.exe process.

Screenshot of Microsoft Defender Security Center alert for detection of remote WMI execution

Figure 13. Microsoft Defender for Endpoint alert for suspicious remote WMI execution highlighting the attacker’s device and payload

Microsoft Defender for Identity also detects and raises alerts on a variety of credential theft techniques. In addition to watching for alerts, security analysts can hunt across identity data in Microsoft 365 Defender for signs of identity compromise. Here are a couple of example Microsoft Defender for Identity queries looking for such patterns:

Enumeration of high-value DC assets followed by logon attempts to validate stolen credentials in time proximity

let MaxTime = 1d;
let MinNumberLogon = 5;
//devices attempting enumeration of high-value DC
IdentityQueryEvents
| where Timestamp > ago(30d)
| where Application == “Active Directory”
| where QueryTarget in (“Read-only Domain Controllers”)
//high-value RODC assets
| project Timestamp, Protocol, Query, DeviceName, AccountUpn
| join kind = innerunique (
//devices trying to logon {MaxTime} after enumeration
IdentityLogonEvents
| where Timestamp > ago(30d)
| where ActionType == “LogonSuccess”
| project LogonTime = Timestamp, DeviceName, DestinationDeviceName) on DeviceName
| where LogonTime between (Timestamp .. (Timestamp + MaxTime))
| summarize n=dcount(DestinationDeviceName), TargetedDC = makeset(DestinationDeviceName) by Timestamp, Protocol, DeviceName
| where n >= MinNumberLogon

High-volume of LDAP queries in short time filtering for non-DC devices

let Threshold = 12;
let BinTime = 1m;
//approximate list of DC
let listDC=IdentityDirectoryEvents
| where Application == “Active Directory”
| where ActionType == “Directory Services replication”
| summarize by DestinationDeviceName;
IdentityQueryEvents
| where Timestamp > ago(30d)
//filter out LDAP traffic across DC
| where DeviceName !in (listDC)
| where ActionType == “LDAP query”
| parse Query with * “Search Scope: ” SearchScope “, Base Object:” BaseObject “, Search Filter: ” SearchFilter
| summarize NumberOfDistinctLdapQueries = dcount(SearchFilter) by DeviceName, bin(Timestamp, BinTime)
| where NumberOfDistinctLdapQueries > Threshold

At this point, SOC teams can take containment measures within the Microsoft 365 security center, for example, using indicators to isolate the devices involved and block the remotely executed payload across the environment, as well as mark suspect users as compromised.

Detecting and remediating persistence


Microsoft Defender for Endpoint also detects the advanced defense evasion and masquerading techniques used by the attackers to make their actions as close to normal as possible, such as binding a WMI event filter with a logical consumer to remain persistent. Follow the recommended actions in the alert to remove persistence and prevent the attacker’s payload from loading after reboot.

Screenshot of Microsoft Defender Security Center alert for detection of WMI event filter bound to suspicious consumer

Figure 14. Microsoft Defender for Endpoint alert for WMI event filter bound to a suspicious consumer showing the persistence and the scheduled command line

Catching AD FS compromise and the attacker’s ability to impersonate users in the cloud


The next step in the attack focuses on the AD FS infrastructure and can unfold in two separate paths that lead to the same outcome—the ability to create valid SAML tokens allowing impersonation of users in the cloud:

  • Path 1 – Stealing the SAML signing certificate: After gaining administrative privileges in the organization’s on-premises network, and with access to the AD FS server itself, the attackers access and extract the SAML signing certificate. With this signing certificate, the attackers create valid SAML tokens to access various desired cloud resources as the identity of their choosing.
  • Path 2 – Adding to or modifying existing federation trust: After gaining administrative Azure Active Directory (Azure AD) privileges using compromised credentials, the attackers add their own certificate as a trusted entity in the domain either by adding a new federation trust to an existing tenant or modifying the properties of an existing federation trust. As a result, any SAML token they create and sign will be valid for the identity of their choosing.

In the first path, obtaining the SAML signing certificate normally entails first querying the private encryption key that resides on the AD FS container and then using that key to decrypt the signing certificate. The certificate can then be used to create illicit but valid SAML tokens that allow the actor to impersonate users, enabling them to access enterprise cloud applications and services.

Microsoft Defender for Endpoint and Microsoft Defender for Identity detect the actions that attackers take to steal the encryption key needed to decrypt the SAML signing certificate. Both solutions leverage unique LDAP telemetry to raise high-severity alerts highlighting the attacker’s progress towards creating illicit SAML tokens.

Screenshot of Microsoft Defender Security Center alert for LDAP query and AD FS private key extraction 

Figure 15. Microsoft Defender for Endpoint detects a suspicious LDAP query being launched and an attempted AD FS private key extraction

Figure 16. Microsoft Defender for Identity detects private key extraction via malicious LDAP requests

For the second path, the attackers create their own SAML signing certificate outside of the organization’s environment. With Azure AD administrative permissions, they then add the new certificate as a trusted object. The following advanced hunting query over Azure AD audit logs shows when domain federation settings are changed, helping to discover where the attackers configured the domain to accept authorization tokens signed by their own signing certificate. As these are rare actions, we advise verifying that any instances identified are the result of legitimate administrative activity.

ADFSDomainTrustMods

let auditLookback = 1d; CloudAppEvents
| where Timestamp > ago(auditLookback)
| where ActionType =~ “Set federation settings on domain.”
| extend targetDetails = parse_json(ActivityObjects[1])
| extend targetDisplayName = targetDetails.Name
| extend resultStatus = extractjson(“$.ResultStatus”, tostring(RawEventData), typeof(string))
| project Timestamp, ActionType, InitiatingUserOrApp=AccountDisplayName, targetDisplayName, resultStatus, InitiatingIPAddress=IPAddress, UserAgent

If the SAML signing certificate is confirmed to be compromised or the attacker has added a new one, follow the best practices for invalidating through certificate rotation to prevent further use and creation of SAML tokens by the attacker. Additionally, affected AD FS servers may need to be isolated and remediated to ensure no remaining attacker control or persistence.

If the attackers accomplish either path, they gain the ability to create illicit SAML tokens for the identities of their choosing and bypass multifactor authentication (MFA), since the service or application accepting the token assumes MFA is a necessary previous step in creating a properly signed token. To prevent attackers from progressing to the next stage, which is to access cloud resources, the attack should be discovered and remediated at this stage.

Detecting the hands-on-keyboard activity in the cloud environment


Diagram of hands-on-keyboard attacks in the cloud

Figure 17. Solorigate attack chain: Hands-on-keyboard attack in the cloud

With the ability to create illicit SAML tokens, the attackers can access sensitive data without having to originate from a compromised device or be confined to on-premises persistence. By abusing API access via existing OAuth applications or service principals, they can attempt to blend into the normal pattern of activity, most notably apps or service principals with existing Mail.Read or Mail.ReadWrite permissions to read email content via Microsoft Graph from Exchange Online. If the application does not already have read permissions for emails, then the app may be modified to grant those permissions.

Identifying unusual addition of credentials to an OAuth app


Microsoft Cloud App Security (MCAS) has added new automatic detection of unusual credential additions to an OAuth application to alert SOCs about apps that have been compromised to extract data from the organization. This detection logic is built on an anomaly detection engine that learns from each user in the environment, filtering out normal usage patterns to ensure alerts highlight real attacks and not false positives. If you see this alert in your environment and confirm malicious activity, you should take immediate action to suspend the user, mark the user as compromised, reset the user’s password, and remove the credential additions. You may consider disabling the application during investigation and remediation.

Figure 18. Microsoft Defender Cloud App Security alert for unusual addition of credentials to an OAuth app

SOCs can use the following Microsoft 365 Defender advanced hunting query over Azure AD audit logs to examine when new credentials have been added to a service principle or application. In general, credential changes may be rare depending on the type and use of the service principal or application. SOCs should verify unusual changes with their respective owners to ensure they are the result of legitimate administrative actions.

NewAppOrServicePrincipalCredential

let auditLookback = 1d; CloudAppEvents
| where Timestamp > ago(auditLookback)
| where ActionType in (“Add service principal.”, “Add service principal credentials.”, “Update application – Certificates and secrets management “)
| extend RawEventData = parse_json(RawEventData)
| where RawEventData.ResultStatus =~ “success”
| where AccountDisplayName has “@”
| extend targetDetails = parse_json(ActivityObjects[1])
| extend targetId = targetDetails.Id
| extend targetType = targetDetails.Type
| extend targetDisplayName = targetDetails.Name
| extend keyEvents = RawEventData.ModifiedProperties
| where keyEvents has “KeyIdentifier=” and keyEvents has “KeyUsage=Verify”
| mvexpand keyEvents
| where keyEvents.Name =~ “KeyDescription”
| parse keyEvents.NewValue with * “KeyIdentifier=” keyIdentifier:string “,KeyType=” keyType:string “,KeyUsage=” keyUsage:string “,DisplayName=” keyDisplayName:string “]” *
| parse keyEvents.OldValue with * “KeyIdentifier=” keyIdentifierOld:string “,KeyType” *
| where keyEvents.OldValue == “[]” or keyIdentifier != keyIdentifierOld
| where keyUsage == “Verify”
| project-away keyEvents
| project Timestamp, ActionType, InitiatingUserOrApp=AccountDisplayName, InitiatingIPAddress=IPAddress, UserAgent, targetDisplayName, targetId, targetType, keyDisplayName, keyType, keyUsage, keyIdentifier

Discovering malicious access to mail items


OAuth applications or service principals with Mail.Read or Mail.ReadWrite permissions can read email content from Exchange Online via the Microsoft Graph. To help increase visibility on these behaviors, the MailItemsAccessed action is now available via the new Exchange mailbox advanced audit functionality. See if this feature is enabled by default for you. Important note for customers: If you have customized the list of audit events you are collecting, you may need to manually enable this telemetry.

If more than 1,000 MailItemsAccessed audit records are generated in less than 24 hours, Exchange Online stops generating auditing records for MailItemsAccessed activity for 24 hours and then resumes logging after this period. This throttling behavior is a good starting point for SOCs to discover potentially compromised mailboxes.

MailItemsAccessedThrottling

let starttime = 2d;
let endtime = 1d;
CloudAppEvents
| where Timestamp between (startofday(ago(starttime))..startofday(ago(endtime)))
| where ActionType == “MailItemsAccessed”
| where isnotempty(RawEventData[‘ClientAppId’]) and RawEventData[‘OperationProperties’][1] has “True”
| project Timestamp, RawEventData[‘OrganizationId’],AccountObjectId,UserAgent

In addition to looking for throttled telemetry, you can also hunt for OAuth applications reading mail via the Microsoft Graph API whose behavior has changed prior to a baseline period.

OAuthGraphAPIAnomalies

//Look for OAuth App reading mail via GraphAPI — that did not read mail via graph API in prior week
let appMailReadActivity = (timeframeStart:datetime, timeframeEnd:datetime) {
CloudAppEvents
| where Timestamp between (timeframeStart .. timeframeEnd)
| where ActionType == “MailItemsAccessed”
| where RawEventData has “00000003-0000-0000-c000-000000000000” // performance check
| extend rawData = parse_json(RawEventData)
| extend AppId = tostring(parse_json(rawData.AppId))
| extend OAuthAppId = tostring(parse_json(rawData.ClientAppId)) // extract OAuthAppId
| summarize by OAuthAppId
};
appMailReadActivity(ago(1d),now()) // detection period
| join kind = leftanti appMailReadActivity(ago(7d),ago(2d)) // baseline period
on OAuthAppId

Microsoft 365 Defender’s cross-domain XDR correlation enables stronger response to critical security incidents


Like the rest of the security industry, Microsoft continues to track the Solorigate attack, an active threat that continues to unfold as well as evolve. As part of empowering our customers and the larger security community to respond to this attack through sharing intelligence and providing advice, this blog serves to guide Microsoft 365 customers to take full advantage of the comprehensive visibility and the rich investigation tools available in Microsoft 365 Defender. This blog shows that many of the existing capabilities in Microsoft 365 Defender help address this attack, but the unique scenarios created by the threat resulted in some Solorigate-specific detections and other innovative protections, including ones that are made possible by deeply integrated cross-domain threat defense.

For additional information and further guidance, refer to these Microsoft resources:

Microsoft will continue to provide public information about the patterns and techniques of this attack and related intelligence for customers to defend themselves, in addition to enhancing the protection capabilities of Microsoft security solutions.

Appendix: Additional details for detection and hunting


Detection details


Attack stage Microsoft 365 Defender detection or alert
Initial access Microsoft Defender for Endpoint:

  • ‘Solorigate’ high-severity malware was detected/blocked/prevented (Trojan:MSIL/Solorigate.BR!dha)
  • SolarWinds Malicious binaries associated with a supply chain attack
Execution and persistence Microsoft Defender for Endpoint:
Command and Control Microsoft Defender for Endpoint:
Defense evasion Microsoft Defender for Endpoint:

  • Suspicious audit policy tampering
Reconnaissance Microsoft Defender for Endpoint:

  • Masquerading Active Directory exploration tool
  • Suspicious sequence of exploration activities
  • Execution of suspicious known LDAP query fragments
Credential access Microsoft Defender for Endpoint:

  • Suspicious access to LSASS (credential access)
  • AD FS private key extraction attempt
  • Possible attempt to access ADFS key material
  • Suspicious ADFS adapter process created

Microsoft Defender for Identity:

  • Unusual addition of permissions to an OAuth app
  • Active Directory attributes Reconnaissance using LDAP

Microsoft Cloud App Security:

  • Unusual addition of credentials to an OAuth app
Lateral movement Microsoft Defender for Endpoint

  • Suspicious file creation initiated remotely (lateral movement)
  • Suspicious Remote WMI Execution (lateral movement)
Exfiltration Microsoft Defender for Endpoint

  • Suspicious mailbox export or access modification
  • Suspicious archive creation

Advanced hunting queries





https://www.sickgaming.net/blog/2020/12/...olorigate/

Print this item

  (Free Game Key) Stranded Deep - Free Daily Epic Giveaway (Day 12)
Posted by: xSicKxBot - 12-28-2020, 02:19 PM - Forum: Deals or Specials - No Replies

Stranded Deep - Free Daily Epic Giveaway (Day 12)

Visit the store page and add the game to your account:

Stranded Deep[store.epicgames.com]

There might also be issues claiming it due to the site's servers handling the high traffic. Wait it out a bit until claiming it again.

The game is free to keep for 24 hours until Dec 29th, 2020 - 16:00 UTC. Epic is also giving everyone a $10 coupon to be used on any purchase of $15 or higher.

We are welcoming everyone to join our discord[discord.gg]. We are more active there on finding giveaways, small or large, and there are daily raffles you can participate.

?GrabFreeGames.com ?Twitter ?Steam Curator ?Facebook[fb.me]?Discord[discord.gg]
❤️Support us: ✔️HumbleBundle Partner[www.humblebundle.com] Epic Tag: GrabFreeGames


https://steamcommunity.com/groups/GrabFr...5461838687

Print this item

  News - Video: Uncovering The WorkBoy – The Long Lost Nintendo Game Boy Add-On
Posted by: xSicKxBot - 12-28-2020, 10:57 AM - Forum: Nintendo Discussion - No Replies

Video: Uncovering The WorkBoy – The Long Lost Nintendo Game Boy Add-On


Video game historian and Nintendo Life contributor Liam Robertson has uncovered the long-lost peripheral and unreleased device known as the WorkBoy. The WorkBoy – for those that don’t know – was an add-on for the Game Boy that turned Nintendo’s famous handheld device into a PDA – essentially a small personal computer.

Robertson has gone above and beyond to share the story of the WorkBoy and his own experiences with it. A trademark for this peripheral was first registered in 1992. It was designed by Source Research and Development in the UK, while a start-up company called Fabtek in the US planned to produce it in close collaboration with Nintendo.

You can get the full history of this unique Game Boy accessory in the video above. It’s definitely worth a look!



https://www.sickgaming.net/blog/2020/12/...oy-add-on/

Print this item

  News - Poll: Box Art Brawl #73 – 1080° Snowboarding
Posted by: xSicKxBot - 12-28-2020, 10:57 AM - Forum: Nintendo Discussion - No Replies

Poll: Box Art Brawl #73 – 1080° Snowboarding

Main

Welcome to the Box Art Brawl, our weekly (well, most of the time) vote to decide which of two or more regional retro box art variants is the best.

Last time, we sized up Tuff E Nuff, one of the latest additions to the Nintendo Switch Online SNES catalogue. The Japanese version — known as Dead Dance in those parts — was the clear victor. The infamous North American version came in second with a third of the vote, and poor Europe limped home in third place. Clearly not tough enough, then.

In an effort to get into the festive holiday spirit, this week we’re looking at the gloriously snow-filled 1080° Snowboarding for N64. C’mon, it’s got ‘snow’ in the title — what more do you want? We looked at the N64’s other premier snowboarding series this time last year, so Nintendo’s cracking first-party effort is the obvious choice this holiday season.

So, pick your ‘boarder of choice (Ricky Winterborn! Akari Hayami! Dion Blaster!) and let’s get out on them slopes.

North America


NA

The NA version presents a dynamic low-angle shot of a snowboarding CG mannequin spinning over you, presumably mid-1080. The logo itself stands out in the top right corner against the background of white powder kicked up by Señor CG, with a crisp blue sky providing a serene backdrop for the rest of the image.

A handful of fir treetops break the frame along the bottom, in a relatively uncluttered cover. Not bad.

Europe


EU

The EU version gets the customary first-party black border around its ‘boarder and uses a completely different image, courtesy of Steve Astephen. The Lamar board branding is once again visible and the logo stands out thanks to the blur effect applied to the background.

The black border is admittedly an acquired taste (we’re quite partial to the way it makes the console logo stand out along the top edge), but overall we probably prefer this to its NA counterpart.

Japan


JP

The Japanese version uses the same image as the EU variant, splashed in the middle of a while box in ‘portrait’ orientation. Lamar gets a more explicit shout-out with its range of boards listed on the left, and the logo is blown up to occupy the bottom half of the cover.

We like the added detail of the little board in the bottom left corner, although the white-out effect feels a bit cheap. Some snow-covered terrain would have looked better, no?


So, you’ve seen the boarders, but which one actually pulls off the fabled 1080? Pick your favourite and hit ‘Vote’ to let us know below:

We hope you’re enjoying the holidays. Join us next time for a less-festive but just-as-wonderful box art-based bout. Until then!



https://www.sickgaming.net/blog/2020/12/...wboarding/

Print this item

  News - Video: Sega Shares Eggman Holiday Short
Posted by: xSicKxBot - 12-28-2020, 03:47 AM - Forum: Nintendo Discussion - No Replies

Video: Sega Shares Eggman Holiday Short

When he’s not paying off a loan to Tom Nook, Liam likes to report on the latest Nintendo news and admire his library of video games. His favourite Nintendo character used to be a guitar-playing dog, but nowadays he prefers to hang out with Judd the cat.



https://www.sickgaming.net/blog/2020/12/...day-short/

Print this item