{
  "Name": "ZeroNetworks",
  "Author": "Nicholas DiCola - nicholas@zeronetworks.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/ZeroNetworks.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The [Zero Networks Segment](https://zeronetworks.com/product) solution for Microsoft Sentinel allows monitoring Zero Networks Segment Audit activity. Audit log data is ingested in Microsoft Sentinel using REST API.\n\n**Underlying Microsoft Technologies used:**\n\nThis solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs\n\n a. [Azure Monitor HTTP Data Collector API ](https://learn.microsoft.com/azure/azure-monitor/logs/data-collector-api)\n\n b. [Azure Functions](https://azure.microsoft.com/products/functions/#overview)",
  "Workbooks": [
    "Workbooks/ZNSegmentAudit.json"
  ],
  "Analytic Rules": [
    "Analytic Rules/ZNSegmentMachineRemovedfromProtection.yaml",
    "Analytic Rules/ZNSegmentNewAPIToken.yaml",
    "Analytic Rules/ZNSegmentRareJITRuleCreation.yaml"
  ],
  "Parsers": [
    "Parsers/ZNSegmentAudit.yaml"
  ],
  "Hunting Queries": [
    "Hunting Queries/ZNSegmentExcessiveAccessbyUser.yaml",
    "Hunting Queries/ZNSegmentExcessiveAccesstoBuiltinGroupbyUser.yaml",
    "Hunting Queries/ZNSegmentInboundBlockRulesDeleted.yaml",
    "Hunting Queries/ZNSegmentOutboundBlockRulesDeleted.yaml"
  ],
  "Data Connectors": [
    "Data Connectors/ZNSegment_CCP_Push/ZNSegmentPush_connectorDefinition.json",
    "Data Connectors/ZNSegmentAudit_CCP_Pull/ZNSegmentAudit_ConnectorDefinition.json"
  ],
  "Playbooks": [
    "Playbooks/ZeroNetworksConnector/azuredeploy.json",
    "Playbooks/ZeroNetworksSegment-AddAssettoProtection/azuredeploy.json",
    "Playbooks/ZeroNetworksSegment-AddBlockOutboundRule/azuredeploy.json",
    "Playbooks/ZeroNetworksSegment-EnrichIncident/azuredeploy.json"
  ],
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\ZeroNetworks",
  "Metadata": "SolutionMetadata.json",
  "Version": "3.0.4",
  "TemplateSpec": true,
  "Is1Pconnector": false
}
