{
  "Name": "Trend Micro Cloud App Security",
  "Author": "Microsoft - support@microsoft.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Trend_Micro_Logo.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The [Trend Micro Cloud App Security](https://www.trendmicro.com/en_be/business/products/user-protection/sps/email-and-collaboration/cloud-app-security.html) data connector provides the capability to retrieve security event logs of the services that Cloud App Security protects and more events into Microsoft Sentinel through the Log Retrieval API. Refer to API [documentation](https://docs.trendmicro.com/enterprise/cloud-app-security-integration-api-online-help/supported-cloud-app-/log-retrieval-api/get-security-logs.aspx) for more information. The connector provides the ability to get events which helps to examine potential security risks, analyze your team's use of collaboration, diagnose configuration problems and more.  \r\n \r\n **Underlying Microsoft Technologies used:** \r\n \r\n This solution takes a dependency on the following technologies, and some of these dependencies might result in additional ingestion or operational costs:\r\n \r\n a. [Codeless Connector Framework (CCF)](https://learn.microsoft.com/azure/sentinel/create-codeless-connector) \r\n \r\n b. [Log Ingestion API](https://docs.microsoft.com/azure/azure-monitor/logs/logs-ingestion-api-overview) \r\n \r\n c. [Data Collection Rules (DCR)](https://docs.microsoft.com/azure/azure-monitor/essentials/data-collection-rule-overview) \r\n \r\n d. [Azure Monitor HTTP Data Collector API](https://docs.microsoft.com/azure/azure-monitor/logs/data-collector-api) \r\n \r\n e. [Azure Functions ](https://azure.microsoft.com/services/functions/#overview)",
  "Workbooks": [
    "Workbooks/TrendMicroCAS.json"
  ],
  "Parsers": [
    "Parsers/TrendMicroCAS.yaml"
  ],
  "Hunting Queries": [
    "Hunting Queries/TrendMicroCASFilesOnShares.yaml",
    "Hunting Queries/TrendMicroCASInfectedFilesInEmails.yaml",
    "Hunting Queries/TrendMicroCASRansomwareThreats.yaml",
    "Hunting Queries/TrendMicroCASRareFilesRecievedViaEmail.yaml",
    "Hunting Queries/TrendMicroCASRiskyUsers.yaml",
    "Hunting Queries/TrendMicroCASScanDiscoveredThreats.yaml",
    "Hunting Queries/TrendMicroCASSuspiciousFilesSharepoint.yaml",
    "Hunting Queries/TrendMicroCASTopFilesRecievedViaEmail.yaml",
    "Hunting Queries/TrendMicroCASUserDLPViolations.yaml",
    "Hunting Queries/TrendMicroCASVAThreats.yaml"
  ],
  "Data Connectors": [
    "Data Connectors/TrendMicroCAS_API_FunctionApp.json",
    "Data Connectors/TrendMicroCAS_CCF/TrendMicroCAS_ConnectorDefinition.json"
  ],
  "Analytic Rules": [
    "Analytic Rules/TrendMicroCASDLPViolation.yaml",
    "Analytic Rules/TrendMicroCASPossiblePhishingMail.yaml",
    "Analytic Rules/TrendMicroCASRansomwareOnHost.yaml",
    "Analytic Rules/TrendMicroCASRansomwareOutbreak.yaml",
    "Analytic Rules/TrendMicroCASSuspiciousFilename.yaml",
    "Analytic Rules/TrendMicroCASThreatNotBlocked.yaml",
    "Analytic Rules/TrendMicroCASUnexpectedFileInMail.yaml",
    "Analytic Rules/TrendMicroCASUnexpectedFileOnFileShare.yaml",
    "Analytic Rules/TrendMicroCASVAInfectedUser.yaml",
    "Analytic Rules/TrendMicroCASVAOutbreak.yaml"
  ],
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Trend Micro Cloud App Security",
  "Version": "3.1.2",
  "DataConnectorCCFVersion": "3.0.0",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": false,
  "Is1PConnector": false
}
