Discover Organizations/Events News

Microsoft: We've open-sourced this tool we used to hunt for code by SolarWinds hackers

data:image/svg+xml,%3Csvg%20xmlns=%22https://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Microsoft is open-sourcing the CodeQL queries that it used to investigate the impact of Sunburst or Solarigate malware planted in the SolarWinds Orion software updates, enabling other organizations to use the queries to perform a similar analysis. Mike Hanley, CSO of GitHub, says  CodeQL provides, "key guardrails that help developers avoid incidents and shipping vulnerabilities".