{
  "Name": "Cloud Service Threat Protection Essentials",
  "Author": "Microsoft - support@microsoft.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Azure_Sentinel.svg\" width=\"75px\" height=\"75px\">",
  "Description": "As cloud services increase in popularity, the volume of attacks against them is also increasing. Broad visibility, context and timely detection of these attacks are important for organization as they move more workloads to the cloud. The **Cloud Service Threat Protection Essentials** contains security content that is relevant for detection of attacks against various cloud services like key vault, storage, compute etc.\r\n \r\n**Pre-requisites:**\r\n \r\nThis is a [domain solution](https://learn.microsoft.com/en-us/azure/sentinel/sentinel-solutions-catalog#domain-solutions) and does not include any data connectors. The content in this solution supports the connectors listed below. Install one or more of the listed solutions, to unlock the value provided by this solution.\r\n \r\n 1.Microsoft 365\r\n \r\n 2.Azure Activity\r\n \r\n 3.Azure Key Vault\r\n \r\n**Keywords:** Storage, Key Vault, Compute, Office, Mail tampering, Azure, resources",
  "Hunting Queries": [
    "Hunting Queries/AzureResourceAssignedPublicIP.yaml",
    "Hunting Queries/AzureKeyVaultAccessManipulation.yaml"
  ],
  "dependentDomainSolutionIds": [
    "azuresentinel.azure-sentinel-solution-office365",
    "azuresentinel.azure-sentinel-solution-azureactivity",
    "azuresentinel.azure-sentinel-solution-azurekeyvault"
  ],
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Cloud Service Threat Protection Essentials",
  "Version": "3.0.0",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": true
}