{
  "Name": "Box",
  "Author": "Microsoft - support@microsoft.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Solutions/Box/Workbooks/Images/Logo/box.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The [Box](https://developer.box.com/guides/events/enterprise-events/for-enterprise/) solution connector provides the capability to ingest [Box enterprise's events](https://developer.box.com/guides/events/#admin-events) into Microsoft Sentinel using the Box REST API \r\n \r\n **Underlying Microsoft Technologies used:** \r\n \r\n This solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs:\r\n \r\n a. [Azure Monitor HTTP Data Collector API](https://docs.microsoft.com/azure/azure-monitor/logs/data-collector-api) \r\n \r\n b. [Azure Functions ](https://azure.microsoft.com/services/functions/#overview)",
  "Workbooks": [
    "Workbooks/Box.json"
  ],
  "Parsers": [
    "Parsers/BoxEvents.yaml"
  ],
  "Hunting Queries": [
    "Hunting Queries/BoxAdminIpAddress.yaml",
    "Hunting Queries/BoxDeletedUsers.yaml",
    "Hunting Queries/BoxInactiveAdmins.yaml",
    "Hunting Queries/BoxInactiveUsers.yaml",
    "Hunting Queries/BoxNewUsers.yaml",
    "Hunting Queries/BoxSuspiciousFiles.yaml",
    "Hunting Queries/BoxUserDownloadsByVolume.yaml",
    "Hunting Queries/BoxUserGroupChanges.yaml",
    "Hunting Queries/BoxUserUploadsByVolume.yaml",
    "Hunting Queries/BoxUsersWithOwnerPermissions.yaml"
  ],
  "Data Connectors": [
    "Data Connectors/Box_API_FunctionApp.json",
    "Data Connectors/BoxEvents_ccp/BoxEvents_DataConnectorDefinition.json"
  ],
  "Analytic Rules": [
    "Analytic Rules/BoxAbnormalUserActivity.yaml",
    "Analytic Rules/BoxBinaryFile.yaml",
    "Analytic Rules/BoxDownloadForbiddenFiles.yaml",
    "Analytic Rules/BoxInactiveUserLogin.yaml",
    "Analytic Rules/BoxItemSharedToExternalUser.yaml",
    "Analytic Rules/BoxMultipleItemsDeletedByUser.yaml",
    "Analytic Rules/BoxNewExternalUser.yaml",
    "Analytic Rules/BoxSensitiveFile.yaml",
    "Analytic Rules/BoxUserLoginAsAdmin.yaml",
    "Analytic Rules/BoxUserRoleChangedToOwner.yaml"
  ],
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Box",
  "Version": "3.1.6",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": true,
  "Is1PConnector": false
}
