↳ Source GitHubSolution

DEV-0537DetectionandHunting

Description

Microsoft Security teams have been actively tracking a large-scale social engineering and extortion campaign against multiple organizations with some seeing evidence of destructive elements. DEV-0537, also known as LAPSUS$ is known for using a pure extortion and destruction model without deploying ransomware payloads. For more technical and mitigation information, please read the [Microsoft Security blog ](https://www.microsoft.com/security/blog/2022/03/22/dev-0537-criminal-actor-targeting-organizations-for-data-exfiltration-and-destruction). As Microsoft continues to track DEV-0537’s tactics and techniques, we are also sharing guidance, detections and hunting queries to help our customers better defend against this threat through our security products. Note: [Security Threat Essentials ](https://portal.azure.com/#create/azuresentinel.azure-sentinel-solution-securitythreatessentialsolazure-sentinel-solution-securitythreatessentialsol) contains security content that is relevant for DEV-0537, please install the solution to enhance your security posture.
Version
2.0.0
Auteur / éditeur déclaré
Microsoft - support@microsoft.com
Niveau de support
Microsoft

Traçabilité de la source

GitHub

Les valeurs affichées proviennent des fichiers du dépôt Azure/Azure-Sentinel. Elles décrivent le modèle publié, pas la configuration de votre workspace.

Identifiant source
azure-sentinel-solution-DEV-0537DetectionandHunting
Autres fichiers source 2Solutions/DEV-0537DetectionandHunting/Data/Solution_DEV-0537 Detection and Hunting.jsonsolution-manifest ↗Solutions/DEV-0537DetectionandHunting/SolutionMetadata.jsonsolution-metadata ↗
GSTEP / SUIVI DU CATALOGUE

Ajouté au catalogue : 16 sept. 2026 · 05:49 UTC
Dernier changement observé : 16 sept. 2026 · 05:49 UTC

Dates de synchronisation GSTEP, distinctes des dates de publication du contenu source.