Zeek-based Solution for detecting Sunburst/Dark Hallo

The SolarWinds security breach was dominating the security headlines last month. Fireeye published some Snort and Yara rules along with IOCs to guide how to defend against the Sunburst malware (used in the SolarWinds attack). I was wondering if anyone in the Zeek community has done anything to develop a zeek-based solution for this? Thanks a lot in advance!

Snort/Yara-based countermeasures: https://github.com/fireeye/sunburst_countermeasures

-- ND

Hello,

Corelight has been blogging about this:

https://corelight.blog/tag/sunburst/

And we did a Webinar:

https://youtu.be/zGlxC-nGEzE

Sincerely,

Richard