{
  "Name": "Darktrace",
  "Author": "Darktrace - customers@darktrace.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Darktrace.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The [Darktrace](https://darktrace.com/) Microsoft Sentinel Solution lets users connect Darktrace AI-based alerting in real-time with Microsoft Sentinel, allowing creation of custom Dashboards, Workbooks, Notebooks and Custom Alerts to improve investigation. Microsoft Sentinel's enhanced visibility into Darktrace logs enables monitoring and mitigation of security threats. \n\n**Underlying Microsoft Technologies used:**\n\n This solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs: \n\na. [Microsoft Sentinel Data Collector API](https://docs.microsoft.com/azure/sentinel/connect-rest-api-template)\n\n For more details about this solution refer to [Darktrace Customer Portal](https://customerportal.darktrace.com/guides)",
  "Workbooks": [
    "Workbooks/DarktraceWorkbook.json",
    "Workbooks/DarktraceActiveAISecurityPlatformWorkbook.json"
  ],
  "Analytic Rules": [
    "Analytic Rules/CreateAlertFromModelBreach.yaml",
    "Analytic Rules/CreateIncidentFromAIAnalystIncident.yaml",
    "Analytic Rules/CreateAlertFromSystemStatus.yaml",
    "Analytic Rules/DarktraceIncidentEvent.yaml",
    "Analytic Rules/DarktraceModelAlert.yaml"
  ],
  "Data Connectors": [
    "Data Connectors/DarktraceConnectorRESTAPI.json",
    "Data Connectors/ccf/Darktrace_ConnectorDefinition.json"
  ],
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Darktrace",
  "Version": "3.1.1",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": false,
  "Is1PConnector": false
}
