{
	"Name": "Dev 0270 Detection and Hunting",
	"Author": "Microsoft - support@microsoft.com",
	"Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Azure_Sentinel.svg\"width=\"75px\"height=\"75px\">",
	"Description": "Microsoft threat intelligence teams have been tracking multiple ransomware campaigns and have tied these attacks to DEV-0270, also known as Nemesis Kitten, a sub-group of Iranian actor PHOSPHORUS. Microsoft assesses with moderate confidence that DEV-0270 conducts malicious network operations, including widespread vulnerability scanning, on behalf of the government of Iran. For more technical and mitigation information, please read the [Microsoft Security blog](https://www.microsoft.com/en-us/security/blog/2022/09/07/profiling-dev-0270-phosphorus-ransomware-operations/). As Microsoft continues to track DEV-0270’s tactics and techniques, we are also sharing guidance, detections and hunting queries to help our customers better defend against this threat through our security products.",
	"Analytic Rules": [
		"Analytic Rules/Dev-0270PowershellSep2022.yaml",
		"Analytic Rules/Dev-0270RegistryIOCSep2022.yaml",
		"Analytic Rules/Dev-0270WMICDiscoverySep2022.yaml",
		"Analytic Rules/Dev-0270NewUserSep2022.yaml"
	],
	"Metadata": "SolutionMetadata.json",
	"BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Dev 0270 Detection and Hunting",
	"Version": "3.0.1",
	"TemplateSpec": true
}