{
 "Name": "StealthTalk",
 "Author": "StealthTalk - support@stealthtalk.com",
 "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Solutions/StealthTalk/Workbooks/Images/Logo/st-ms-def-hub.svg\" width=\"75px\" height=\"75px\">",
 "Description": "The **StealthTalk Anomalous Authentication** solution ingests StealthTalk Enterprise sign-in anomaly data into Microsoft Sentinel so SOC teams can investigate anomalous authentication activity alongside Microsoft security telemetry. The solution includes a Logs Ingestion API data connector, scheduled analytic rules, hunting queries, ASIM authentication parsers, a workbook, and a Microsoft Teams playbook. It depends on [Microsoft Sentinel](https://learn.microsoft.com/azure/sentinel/overview), [Azure Monitor Logs Ingestion](https://learn.microsoft.com/azure/azure-monitor/logs/logs-ingestion-api-overview), [custom tables](https://learn.microsoft.com/azure/azure-monitor/logs/create-custom-table), [Logic Apps](https://learn.microsoft.com/azure/logic-apps/logic-apps-overview), and [ASIM](https://learn.microsoft.com/azure/sentinel/normalization).",
 "WorkbookDescription": "The StealthTalk Anomalous Auth Monitor workbook provides a real-time SOC dashboard with five sections: Overview (5 KPI tiles + timeline + composite User Risk Leaderboard + Multi-Vector Correlation), Off-Hours, New Devices, Geo Anomaly, and Brute Force. Includes an interactive World Map and per-user forensic tables.",
 "Workbooks": [
  "Workbooks/StealthTalkAnomalousAuthMonitor.json"
 ],
 "WorkbookBladeDescription": "This Microsoft Sentinel Solution installs workbooks. Workbooks provide a flexible canvas for data monitoring, analysis, and the creation of rich visual reports within the Azure portal. They allow you to tap into one or many data sources from Microsoft Sentinel and combine them into unified interactive experiences.",
 "AnalyticalRuleBladeDescription": "This Microsoft Sentinel Solution installs scheduled analytic rules for StealthTalk anomalous-auth detections. These rules can be configured upon installation.",
 "HuntingQueryBladeDescription": "This Microsoft Sentinel Solution installs hunting queries for StealthTalk that the SOC team can leverage during proactive threat-hunting activities.",
 "PlaybooksBladeDescription": "This Microsoft Sentinel Solution installs playbooks for StealthTalk to post anomalous-auth incidents to a Microsoft Teams channel.",
 "Analytic Rules": [
  "Analytic Rules/AfterHoursWork.yaml",
  "Analytic Rules/MultiNewDevicesRegistration.yaml",
  "Analytic Rules/LoginOutsideWorkZone.yaml",
  "Analytic Rules/PasswordBruteForce.yaml"
 ],
 "Hunting Queries": [
  "Hunting Queries/ImpossibleTravel.yaml",
  "Hunting Queries/AccountTakeoverSequence.yaml",
  "Hunting Queries/BruteForceFollowedBySuspicious.yaml"
 ],
 "Playbooks": [
  "Playbooks/StealthTalk-LogicApp-AlertToTeams/azuredeploy.json"
 ],
 "Data Connectors": [
  "Data Connectors/StealthTalkConnector.json"
 ],
 "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\StealthTalk",
 "Version": "3.0.0",
 "Metadata": "SolutionMetadata.json",
 "TemplateSpec": false,
 "Is1PConnector": false
}
