{
	"Name": "Semperis Directory Services Protector",
	"Author": "Semperis",
	"Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Solutions/Semperis%20Directory%20Services%20Protector/Workbooks/Images/Logo/Semperis.svg\" width=\"75px\" height=\"75px\">",
	"Description": "The [Semperis Directory Services Protector](https://www.semperis.com/ds-protector/) solution provides the capability to ingest Windows event logs (i.e., Indicators of Exposure and Indicators of Compromise) into Microsoft Sentinel.\n\n**Underlying Microsoft Technologies used:**\n\nThis solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs:\n\na. [Agent based logs collection from Windows and Linux machines](https://docs.microsoft.com/azure/azure-monitor/agents/data-sources-custom-logs)",
	"Workbooks": [
		"Workbooks/SemperisDSPADChanges.json",
		"Workbooks/SemperisDSPNotifications.json",
		"Workbooks/SemperisDSPQuickviewDashboard.json",
		"Workbooks/SemperisDSPSecurityIndicators.json"
	],
	"Parsers": [
		"Parsers/dsp_parser.yaml"
	],
	"Analytic Rules": [
		"Analytic Rules/SemperisDSP_EvidenceOfMimikatzDCShadowAttack.yaml",
		"Analytic Rules/SemperisDSP_KerberoskrbtgtAccount.yaml",
		"Analytic Rules/SemperisDSP_RecentsIDHistoryChangesOnADObjects.yaml",
		"Analytic Rules/SemperisDSP_WellKnownPrivilegedSIDsInsIDHistory.yaml",
		"Analytic Rules/SemperisDSP_ZerologonVulnerability.yaml",
		"Analytic Rules/Semperis_DSP_Failed_Logons.yaml",
		"Analytic Rules/Semperis_DSP_Operations_Critical_Notifications_.yaml",
		"Analytic Rules/Semperis_DSP_RBAC_Changes.yaml"
	],
	"Data Connectors": [
		"Data Connectors/SemperisDSP-connector.json"
	],
	"BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Semperis Directory Services Protector",
	"Version": "3.0.2",
	"Metadata": "SolutionMetadata.json",
	"TemplateSpec": true,
	"Is1Pconnector": false
}