{
    "Name": "SpyCloud Enterprise Protection",
    "Author": "SpyCloud",
    "Logo": "<img src=\"raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/SpyCloud_Enterprise_Protection.svg\" width=\"75\" height=\"75\" >",
    "Description": "Cybercriminals continue to utilize stolen corporate credentials as the number one technique for account takeover (ATO). In fact, the FBI estimated that this resulted in estimated losses totaling more than $2.7 billion in 2022. SpyCloud helps prevent account takeover and ransomware attacks by identifying exposed credentials related to a company’s domains, IP addresses and emails. Through this integration, breach and malware data from SpyCloud can be loaded into Sentinel.",
    "Playbooks": [
        "Playbooks/Custom Connector/azuredeploy.json",
        "Playbooks/SpyCloud-Breach-Playbook/azuredeploy.json",
        "Playbooks/SpyCloud-Get-Domain-Breach-Data-Playbook/azuredeploy.json",
        "Playbooks/SpyCloud-Get-Email-Breach-Data-Playbook/azuredeploy.json",
        "Playbooks/SpyCloud-Get-IP-Breach-Data-Playbook/azuredeploy.json",
        "Playbooks/SpyCloud-Get-Password-Breach-Data-Playbook/azuredeploy.json",
        "Playbooks/SpyCloud-Get-Username-Breach-Data-Playbook/azuredeploy.json",
        "Playbooks/SpyCloud-Malware-Playbook/azuredeploy.json",
        "Playbooks/SpyCloud-Monitor-Watchlist-Data/azuredeploy.json"
    ],
    "Analytic Rules": [
        "Analytic Rules/SpyCloudEnterpriseProtectionBreachRule.yaml",
        "Analytic Rules/SpyCloudEnterpriseProtectionMalwareRule.yaml"
    ],
    "BasePath": "D:\\GitHub\\Azure-Sentinel\\Solutions\\SpyCloud Enterprise Protection",
    "Version": "3.0.1",
    "Metadata": "SolutionMetadata.json",
    "TemplateSpec": true,
    "Is1PConnector": false
}
