{
  "Name": "Recorded Future",
  "Author": "Recorded Future Premier Integrations - support@recordedfuture.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/RecordedFuture.svg\" width=\"75px\" height=\"75px\">",
  "Description": "[Recorded Future](https://www.recordedfuture.com/) is the worlds largest provider of intelligence for enterprise security. By combining persistent and pervasive automated data collection and analytics with human analysis, Recorded Future delivers intelligence that is timely, accurate, and actionable.\n\nUnderlying Microsoft Technologies used:\nThis solution depends on underlying Microsoft technologies. Some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:\n* [Log Analytics](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/workspace-design)\n* [Logic apps](https://learn.microsoft.com/en-us/azure/logic-apps/logic-apps-pricing)\n* [Threat Indicators](https://learn.microsoft.com/en-us/azure/sentinel/upload-indicators-api)\n",
  "Data Connectors": [
    "Data Connectors/RecordedFuture_ConnectorDefinition.json"
  ],
  "Analytic Rules": [
    "Analytic Rules/ThreatHunting/RecordedFutureThreatHuntingHashAllActors.yaml",
    "Analytic Rules/ThreatHunting/RecordedFutureThreatHuntingIPAllActors.yaml",
    "Analytic Rules/ThreatHunting/RecordedFutureThreatHuntingDomainAllActors.yaml",
    "Analytic Rules/ThreatHunting/RecordedFutureThreatHuntingUrlAllActors.yaml",
    "Analytic Rules/IncidentCreation/RecordedFutureSandboxStorageAccount.yaml",
    "Analytic Rules/IncidentCreation/RecordedFutureSandboxEmailAttachment.yaml",
    "Analytic Rules/IncidentCreation/RecordedFutureAlerts.yaml",
    "Analytic Rules/IncidentCreation/RecordedFuturePlaybookAlerts.yaml"
  ],
  "Playbooks": [
    "Playbooks/Enrichment/RecordedFuture-IOC_Enrichment/azuredeploy.json",
    "Playbooks/Alerts/RecordedFuture-Playbook-Alert-Importer/azuredeploy.json",
    "Playbooks/Alerts/RecordedFuture-Alert-Importer/azuredeploy.json",
    "Playbooks/IndicatorImport/RecordedFuture-ThreatIntelligenceImport/azuredeploy.json",
    "Playbooks/IndicatorImport/RecordedFuture-Domain-IndicatorImport/azuredeploy.json",
    "Playbooks/IndicatorImport/RecordedFuture-Hash-IndicatorImport/azuredeploy.json",
    "Playbooks/IndicatorImport/RecordedFuture-IP-IndicatorImport/azuredeploy.json",
    "Playbooks/IndicatorImport/RecordedFuture-URL-IndicatorImport/azuredeploy.json",
    "Playbooks/Sandboxing/RecordedFuture-Sandbox_Enrichment-Url/azuredeploy.json",
    "Playbooks/Connectors/RecordedFuture-CustomConnector/azuredeploy.json",
    "Playbooks/ThreatHunting/RecordedFuture-ThreatMap-Importer/azuredeploy.json",
    "Playbooks/ThreatHunting/RecordedFuture-ThreatMapMalware-Importer/azuredeploy.json",
    "Playbooks/ThreatHunting/RecordedFuture-ActorThreatHunt-IndicatorImport/azuredeploy.json",
    "Playbooks/ThreatHunting/RecordedFuture-MalwareThreatHunt-IndicatorImport/azuredeploy.json"
  ],
  "Workbooks": [
    "Workbooks/RecordedFuturePlaybookAlertOverview.json",
    "Workbooks/RecordedFutureAlertOverview.json",
    "Workbooks/RecordedFutureDomainCorrelation.json",
    "Workbooks/RecordedFutureHashCorrelation.json",
    "Workbooks/RecordedFutureIPCorrelation.json",
    "Workbooks/RecordedFutureURLCorrelation.json",
    "Workbooks/RecordedFutureThreatActorHunting.json",
    "Workbooks/RecordedFutureMalwareThreatHunting.json"
  ],
  "BasePath": "/Users/emangsten/git/github/Azure-Sentinel/Solutions/Recorded Future",
  "Version": "3.2.22",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": false,
  "Is1PConnector": false
}
