{
  "Name": "Proofpoint On demand(POD) Email Security",
  "Author": "Proofpoint, Inc. - azure-support@proofpoint.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/PFPTLogo.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The [Proofpoint on Demand Email Security](https://www.proofpoint.com/us/products/email-security-and-protection/email-protection) solution for Microsoft Sentinel enables you to ingest Proofpoint on Demand Email Protection data and activity logs for monitoring email activity, events and threats in your organization.\r\n  \r\n  **Underlying Microsoft Technologies used:** \r\n\r\n This solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs:\r\n\n• [Microsoft Sentinel Codeless Connector Framework](https://aka.ms/Sentinel-CCP_Platform)",
  "Workbooks": [
    "Workbooks/ProofpointPOD.json"
  ],
  "Parsers": [
    "Parsers/ProofpointPOD.yaml"
  ],
  "Hunting Queries": [
    "Hunting Queries/ProofpointPODHighScoreAdultValue.yaml",
    "Hunting Queries/ProofpointPODHighScoreMalwareValue.yaml",
    "Hunting Queries/ProofpointPODHighScorePhishValue.yaml",
    "Hunting Queries/ProofpointPODHighScoreSpamValue.yaml",
    "Hunting Queries/ProofpointPODHighScoreSuspectValue.yaml",
    "Hunting Queries/ProofpointPODLargeOutboundEmails.yaml",
    "Hunting Queries/ProofpointPODRecipientsHighNumberDiscardReject.yaml",
    "Hunting Queries/ProofpointPODRecipientsLargeNumberOfCorruptedEmails.yaml",
    "Hunting Queries/ProofpointPODSendersLargeNumberOfCorruptedEmails.yaml",
    "Hunting Queries/ProofpointPODSuspiciousFileTypesInAttachments.yaml"
  ],
  "Analytic Rules": [
    "Analytic Rules/ProofpointPODBinaryInAttachment.yaml",
    "Analytic Rules/ProofpointPODDataExfiltrationToPrivateEmail.yaml",
    "Analytic Rules/ProofpointPODHighRiskNotDiscarded.yaml",
    "Analytic Rules/ProofpointPODMultipleArchivedAttachmentsToSameRecipient.yaml",
    "Analytic Rules/ProofpointPODMultipleLargeEmailsToSameRecipient.yaml",
    "Analytic Rules/ProofpointPODMultipleProtectedEmailsToUnknownRecipient.yaml",
    "Analytic Rules/ProofpointPODSuspiciousAttachment.yaml",
    "Analytic Rules/ProofpointPODWeakCiphers.yaml",
    "Analytic Rules/ProofpointPODEmailSenderInTIList.yaml",
    "Analytic Rules/ProofpointPODEmailSenderIPinTIList.yaml"
  ],
  "Data Connectors": [
    "Data Connectors/ProofPointEmailSecurity_CCP/ProofpointPOD_Definaton.json"
  ],
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\solutions\\Proofpoint On demand(POD) Email Security",
  "Version": "3.1.4",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": true,
  "Is1PConnector": false
}