{
  "Name": "Legacy IOC based Threat Protection",
  "Author": "Microsoft - support@microsoft.com",
  "Logo": "<img src ='https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Azure_Sentinel.svg' width='75px' height='75px'>",
  "Description": "Microsoft Security Research, based on ongoing trends and exploits creates content that help identify existence of known IOCs based on known prevalent attacks and threat actor tactics/techniques, such as Nobelium, Gallium, Solorigate, etc. This solution contains packaged content written on some legacy IOCs that have been prevalent in the past but may still be relevant.\n\n**Pre-requisites:**\n\nThis is a [domain solution](https://learn.microsoft.com/azure/sentinel/sentinel-solutions-catalog#domain-solutions) and does not include any data connectors. The content in this solution supports the connectors listed below. Install one or more of the listed solutions, to unlock the value provided by this solution.\n\n1. Squid Proxy\n\n2. Windows Server DNS\n\n3. Cisco ASA\n\n4. Palo Alto Networks\n\n5. Microsoft Defender XDR\n\n6. Azure Firewall\n\n7. ZScaler Internet Access\n\n8. Infoblox NIOS\n\n9. Google Cloud Platform DNS\n\n10. NXLog DNS\n\n11. Cisco Umbrella\n\n12. Corelight \n\n13. Amazon Web Services\n\n14. Windows Forwarded Events\n\n15. Sysmon for Linux\n\n16. Microsoft 365\n\n17. Windows Security Events\n\n18. Microsoft Entra ID\n\n19. Azure Activity\n\n20. F5 Advanced WAF\n\n21. Fortinet FortiGate\n\n22. Check Point\n\n23. Common Event Format\n\n24. Windows Firewall",
  "Hunting Queries": [
    "Solutions/Legacy IOC based Threat Protection/Hunting Queries/Dev-0056CommandLineActivityNovember2021.yaml",
    "Solutions/Legacy IOC based Threat Protection/Hunting Queries/Dev-0322CommandLineActivityNovember2021(ASIMVersion).yaml",
    "Solutions/Legacy IOC based Threat Protection/Hunting Queries/Dev-0322CommandLineActivityNovember2021.yaml",
    "Solutions/Legacy IOC based Threat Protection/Hunting Queries/Dev-0322FileDropActivityNovember2021(ASIMVersion).yaml",
    "Solutions/Legacy IOC based Threat Protection/Hunting Queries/Dev-0322FileDropActivityNovember2021.yaml",
    "Solutions/Legacy IOC based Threat Protection/Hunting Queries/NetworkConnectiontoOMIPorts.yaml",
    "Solutions/Legacy IOC based Threat Protection/Hunting Queries/NylonTyphoonCommandLineActivity-Nov2021.yaml",
    "Solutions/Legacy IOC based Threat Protection/Hunting Queries/NylonTyphoonRegIOCPatterns.yaml",
    "Solutions/Legacy IOC based Threat Protection/Hunting Queries/SolarWindsInventory.yaml",
    "Solutions/Legacy IOC based Threat Protection/Hunting Queries/ForestBlizzard_IOC_RetroHunt.yaml"
  ],
  "dependentDomainSolutionIds": [
    "azuresentinel.azure-sentinel-solution-squidproxy",
    "azuresentinel.azure-sentinel-solution-dns",
    "azuresentinel.azure-sentinel-solution-ciscoasa",
    "azuresentinel.azure-sentinel-solution-paloaltopanos",
    "azuresentinel.azure-sentinel-solution-microsoft365defender",
    "sentinel4azurefirewall.sentinel4azurefirewall",
    "zscaler1579058425289.zscaler_internet_access_mss",
    "azuresentinel.azure-sentinel-solution-infobloxnios",
    "azuresentinel.azure-sentinel-solution-gcpdns",
    "nxlogltd1589381969261.nxlog_dns_logs",
    "azuresentinel.azure-sentinel-solution-ciscoumbrella",
    "corelightinc1584998267292.corelight-for-azure-sentinel",
    "azuresentinel.azure-sentinel-solution-amazonwebservices",
    "azuresentinel.azure-sentinel-solution-windowsforwardedevents",
    "azuresentinel.azure-sentinel-solution-sysmonforlinux",
    "azuresentinel.azure-sentinel-solution-office365",
    "azuresentinel.azure-sentinel-solution-securityevents",
    "azuresentinel.azure-sentinel-solution-azureactivedirectory",
    "azuresentinel.azure-sentinel-solution-azureactivity",
    "f5-networks.f5_bigip_mss",
    "azuresentinel.azure-sentinel-solution-fortinetfortigate",
    "checkpoint.checkpoint-sentinel-solutions",
    "azuresentinel.azure-sentinel-solution-commoneventformat",
    "azuresentinel.azure-sentinel-solution-windowsfirewall"
  ],
  "BasePath": "C:\\One\\Azure\\Azure-Sentinel",
  "Version": "3.0.5",
  "TemplateSpec": true,
  "Metadata": "SolutionMetadata.json"
}