Cyber Security Basics 📂 Slides · 15 of 15 36 min read

Advanced Persistent Threats and Supply Chain Attacks: Incident Analysis and Lessons Learned

The most dangerous attackers do not smash the door — they move in quietly and stay for months. This tutorial explains how APTs work stage by stage, how supply chain attacks like SolarWinds turn one trusted update into thousands of victims, and how analysts investigate incidents and turn every breach into lessons that prevent the next one.

🕵️

APTs & Supply Chain Attacks

The most dangerous attackers don't smash the door — they move in quietly and stay for months. Learn how APTs operate, how one poisoned update can hit thousands of companies, and how analysts turn incidents into lessons.
APT Lifecycle Supply Chain Attacks Incident Analysis Lessons Learned

Press Next → or use ← → arrow keys

Section 01

What Is an Advanced Persistent Threat?

A burglar smashes and grabs. A spy moves in.
An ordinary attacker is a burglar: get in, grab what's valuable, get out. An APT is a spy who secretly moves into your house — copies your keys, reads your mail every day, and leaves no trace for months.

Break the name down: Advanced — custom malware, zero-days, skilled teams. Persistent — they stay hidden for months or years and come back if removed. Threat — a specific, well-funded group with a mission, usually espionage or sabotage.
MonthsTypical time hidden before discovery
1Chosen target — you, not "anyone"
0-dayUnknown flaws used as weapons
APT28Groups get tracking numbers and names
Section 01 · Lifecycle

The APT Lifecycle — Five Quiet Stages

🕰️ DWELL TIME: MONTHS, EVEN YEARS 🔭 Recon study the target 🎣 Initial Access spear-phishing, zero-day 🪝 Foothold backdoors survive reboots 🕸️ Lateral Move hop machine to machine 📤 Exfiltrate steal data slowly, quietly The dot pauses at every stage — real APTs wait weeks between moves to stay invisible
🤫
Living Off the Land

APTs often avoid malware once inside. They use the victim's own admin tools — PowerShell, remote desktop, scheduled tasks — so their activity looks like normal IT work. That is why they are so hard to spot.

Section 01 · Traits

How to Recognise an APT

💰
Funded & Patient
salaried attackers
Usually state-backed teams. No rush for quick profit — the mission can take years.
🎯
Targeted
you were chosen
Not random spam. They research one organisation and craft attacks just for it.
🫥
Stealthy
silence is the goal
Low and slow. Small data transfers, normal-looking logins, activity in office hours.
🗂️
How APTs Get Their Names

Researchers number groups (APT1, APT28, APT29) and vendors add nicknames like "Fancy Bear" or "Lazarus". The public catalogue of their techniques is MITRE ATT&CK — the encyclopedia every defender should know.

Section 01 · History

APT Campaigns Worth Knowing

CampaignYearWhy it matters
Stuxnet2010APT sabotage that physically destroyed Iranian centrifuges
APT1 Report2013Mandiant publicly unmasked a military hacking unit — a first
OPM Breach2015Background-check records of ~21.5 million US employees stolen
Bangladesh Bank2016Lazarus Group stole $81 million through the SWIFT network
SolarWinds2020APT29 espionage through a poisoned software update — next section
🧠
The Common Thread

Every campaign stayed hidden for months and was found long after the damage began. Against APTs, detection speed matters as much as prevention.

Section 02

Supply Chain Attacks — Poison the Well

Don't rob 1,000 houses. Poison the water tank they share.
Attacking 1,000 well-defended companies one by one is hard. So attackers go upstream: they compromise one supplier that all 1,000 companies already trust — a software vendor, a code library, an IT service provider.

The victims then infect themselves, by installing a signed, official-looking update from a trusted name. That is a supply chain attack: break one, reach thousands.
✔️
Why It Beats Normal Defences

Firewalls and antivirus allow trusted vendors by design. When the poison arrives inside a digitally signed update, every normal check says "this is safe".

Section 02 · Flow

One Poisoned Update, Thousands of Victims

😈 Attacker breaks into one vendor 🏗️ Vendor Build malware hidden in the code 📦 SIGNED ✔ Official Update trusted by every customer 🏛️ Agencies 🏢 Companies 🏥 Hospitals One break-in upstream → automatic delivery to every customer downstream
📦
Not Just Big Vendors

The same trick works on open-source packages (fake or hijacked npm and PyPI libraries), hardware, and IT service providers. In 2021, one attack on the vendor Kaseya spread ransomware to about 1,500 businesses at once.

Section 02 · Case

SolarWinds — The Textbook Supply Chain Attack

The update that spied on its own customers
Attackers (later attributed to APT29) slipped a backdoor called SUNBURST into the build system of SolarWinds' Orion software. The company then shipped it to customers as a normal, digitally signed update.

About 18,000 organisations installed it — including US government agencies and major tech firms. The backdoor slept for two weeks, then woke up and let the attackers pick their real targets quietly.

It stayed undetected for around nine months, until the security firm FireEye caught it while investigating its own breach.
18kOrganisations installed the backdoor
~9Months hidden before discovery
14Days the backdoor slept before waking
1Vendor compromised to reach them all
Section 03

Incident Analysis — Detective Work After the Alarm

Treat the network like a crime scene
When an incident is confirmed, analysts become detectives. They collect evidence — logs, memory dumps, disk images, network captures — and rebuild the story: How did the attacker get in? Where did they go? What did they take? Are they still here?

The output is a timeline and a root cause. Without them, you clean the visible infection but leave the open door untouched — and the attacker walks back in next week.
🧾
Collect
preserve evidence
Logs, disk images, memory, network captures — before they are overwritten or wiped.
🧩
Reconstruct
build the timeline
Order every event: first entry, each hop, each file touched, each byte sent out.
🎯
Conclude
find the root cause
Name the real weakness — the unpatched server, the phished account, the missing MFA.
Section 03 · Process

The Incident Response Cycle

🚨 INCIDENT 📋 1 Preparation 🔍 2 Identify 🚧 3 Contain 🧹 4 Eradicate ♻️ 5 Recover 📚 6 Learn
🔄
It's a Circle, Not a Line

Prepare → Identify → Contain → Eradicate → Recover → Learn — and the lessons feed straight back into better preparation. Analysis (Section 03) powers steps 2 to 4. Lessons learned (next) is step 6.

Section 03 · Practice

The Five Questions Every Analysis Must Answer

QuestionWhere the answer lives
1. How did they get in?Email logs, VPN logs, vulnerability scans of exposed systems
2. When did it start?First malicious event in the timeline — often months before the alarm
3. Where did they go?Authentication logs, internal network traffic between machines
4. What did they take or change?File access records, database logs, unusual outbound transfers
5. Are they still inside?Hunt for backdoors, new accounts, scheduled tasks, persistence tricks
📝
No Logs, No Answers

Every question above is answered from records collected before the incident. If logging is off, the detective arrives at a crime scene that has already been swept clean. Logging is a decision you make today.

Section 04

Lessons Learned — Turning Pain Into Strength

📚 HOW TO RUN A LESSONS-LEARNED REVIEW
1
Hold it soon, while memory is fresh. Within two weeks of closing the incident, bring everyone involved into one room.
2
Keep it blameless. Ask "what allowed this?", never "who caused this?". People who fear blame hide facts — and hidden facts repeat incidents.
3
Fix root causes, not symptoms. Removing the malware is a symptom fix. Adding MFA and patching the entry point fixes the cause.
4
Give every action an owner and a date. "Improve monitoring" is a wish. "Deploy alerts on admin logins — Priya, by 30 June" is a plan.
5
Update the playbook and share. Rewrite the response plan with what you learned. Share safely with peers — your lesson can prevent someone else's breach.
6
Test that the fix works. Re-run the attack scenario in a drill. A lesson is only "learned" when the same trick no longer works.
Section 04 · Industry

What SolarWinds Taught the Whole Industry

🧾
Know Your Ingredients
Companies now demand an SBOM — a "Software Bill of Materials" listing every component inside a product, like a food label.
🚫
Zero Trust
"Trusted vendor" is no longer enough. Verify every login and every connection — even from software you bought.
🏗️
Protect the Build
Software makers now guard their build pipelines like vaults — that is where SUNBURST was planted.
🔍
Vet Your Vendors
Security questionnaires and audits for suppliers are now standard. Your security includes theirs.
📡
Hunt, Don't Wait
Assume compromise. Threat hunting looks for quiet intruders instead of waiting for alarms.
🗣️
Speak Up Fast
FireEye's honesty about its own breach exposed the whole campaign. Disclosure protects everyone.
FINAL

Assume Breach, Learn Fast

5Stages in the APT lifecycle
1→18kOne vendor to thousands of victims
6Steps in the incident response cycle
5Questions every analysis must answer
6Rules for a lessons-learned review
0Blame allowed in the review room
🎯
What You Now Know

APTs win with patience and stealth, so defenders must hunt, not just block. Supply chain attacks abuse trust, so trust must be verified. And every incident ends the same right way: analyse honestly, find the root cause, and make the same attack impossible tomorrow.

📚
Where To Go Next

Explore APT techniques on MITRE ATT&CK. Read Mandiant's yearly M-Trends report for real dwell-time data. Study the NIST incident handling guide (SP 800-61). And practise one drill: could your team answer the five questions today?

🕵️ End of tutorial · Press to review, or click Restart

You have completed Slides. View all sections →