{
  "Name": "CheckPoint Harmony Email and Collaboration",
  "Author": "Checkpoint - support@checkpoint.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/CloudGuardLogo.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The [Check Point Harmony Email and Collaboration](https://www.checkpoint.com/harmony/email-collaboration/) solution for Microsoft Sentinel enables ingestion of security events from the Check Point Harmony Email and Collaboration API into Microsoft Sentinel using Microsoft Sentinel’s Codeless Connector Platform. The connector supports DCR-based [ingestion-time transformations](https://learn.microsoft.com/azure/azure-monitor/logs/custom-logs-overview) to parse incoming security event data into custom columns, reducing the need for query-time parsing and improving query performance.\n\n**Underlying Microsoft Technologies used:**\n\nThis solution takes a dependency on the following Microsoft technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs:\n\na. [Microsoft Sentinel](https://learn.microsoft.com/azure/sentinel/overview)\n\nb. [Microsoft Sentinel Codeless Connector Platform (CCP)](https://learn.microsoft.com/azure/sentinel/create-codeless-connector)\n\nc. [Azure Monitor Logs custom logs and Data Collection Rules (DCR)](https://learn.microsoft.com/azure/azure-monitor/data-collection/data-collection-rule-overview)\n\nd. [Data Collection Rule ingestion-time transformations](https://learn.microsoft.com/azure/azure-monitor/logs/custom-logs-overview)",
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Checkpoint Harmony Email and Collaboration",
  "Version": "3.0.0",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": false,
  "Is1PConnector": false,
  "Data Connectors": [
    "Data Connectors/CheckpointHEC_Definition.json"
  ],
  "Hunting Queries":[
    "Hunting Queries/CheckpointEventPerUser.yaml",
    "Hunting Queries/CheckpointEventRecapLastDay.yaml",
    "Hunting Queries/CheckpointHighConfidenceSpam.yaml",
    "Hunting Queries/CheckpointPhishing.yaml",
    "Hunting Queries/CheckpointDLPEvent.yaml"
  ],
  "Analytic Rules" : [
    "Analytic Rules/CheckpointHECPhishingNotQuarantined.yaml"
  ],
  "Playbooks":[
    "Playbooks/Quarantine/quarantine.json"
  ]
}
