{
  "Name": "DEV-0537DetectionandHunting",
  "Author": "Microsoft - support@microsoft.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Azure_Sentinel.svg\" width=\"75px\" height=\"75px\">",
  "Description": "Microsoft Security teams have been actively tracking a large-scale social engineering and extortion campaign against multiple organizations with some seeing evidence of destructive elements. DEV-0537, also known as LAPSUS$ is known for using a pure extortion and destruction model without deploying ransomware payloads. For more technical and mitigation information, please read the [Microsoft Security blog ](https://www.microsoft.com/security/blog/2022/03/22/dev-0537-criminal-actor-targeting-organizations-for-data-exfiltration-and-destruction). As Microsoft continues to track DEV-0537’s tactics and techniques, we are also sharing guidance, detections and hunting queries to help our customers better defend against this threat through our security products.\n\nNote: [Security Threat Essentials ](https://portal.azure.com/#create/azuresentinel.azure-sentinel-solution-securitythreatessentialsolazure-sentinel-solution-securitythreatessentialsol) contains security content that is relevant for DEV-0537, please install the solution to enhance your security posture.",
    "Hunting Queries": [
    "Hunting Queries/Empty.yaml"
 ],
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\DEV-0537DetectionandHunting",
  "Version": "2.0.0",
  "Metadata": "SolutionMetadata.json",
 "TemplateSpec": true,
  "Is1PConnector": false
}