 {
    "Name": "ThreatConnect",
    "Author": "JP Bourget jp@bluecycle.net",
    "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/ThreatConnect.svg\" width=\"75px\" height=\"75px\">",
    "Description": "The [ThreatConnect Threat Intelligence Platform](https://threatconnect.com/) solution for Microsoft Sentinel provides Workbooks and Analytics to demonstrate the value of ThreatConnect data inside Microsoft Sentintel.",
    "WorkbookDescription": [],
    "Workbooks": ["Solutions/ThreatConnect/Workbooks/ThreatConnectOverview.json"],
    "WorkbookBladeDescription": "",
    "AnalyticalRuleBladeDescription": "This solution installs the following analytic rule templates. After installing the solution, create and enable analytic rules in Manage solution view. These rules require data from the ThreatConnect connector, and are meant to demonstrate what is possible by filering on just ThreatConnect TI.",
    "HuntingQueryBladeDescription": "",
    "PlaybooksBladeDescription": "",
    "Analytic Rules": [
      "Solutions/ThreatConnect/Analytic Rules/ThreatConnect_DomainEntity_DnsEvents.yaml",
      "Solutions/ThreatConnect/Analytic Rules/ThreatConnect_EmailEntity_OfficeActivity.yaml",
      "Solutions/ThreatConnect/Analytic Rules/ThreatConnect_EmailEntity_SigninLogs.yaml",
      "Solutions/ThreatConnect/Analytic Rules/ThreatConnect_IPEntity_NetworkSessions.yaml",
      "Solutions/ThreatConnect/Analytic Rules/ThreatConnect_URLEntity_OfficeActivity.yaml"
    ],
    "Playbooks": [],
    "PlaybookDescription": [],
    "Parsers": [],
    "SavedSearches": [],
    "Hunting Queries": [],
    "Data Connectors": [],
    "Watchlists": [],
    "WatchlistDescription": [],
    "BasePath": "/Users/punkrokk/repos/azureSentinelDev/Azure-Sentinel",
    "Version": "3.0.1", 
    "Metadata": "SolutionMetadata.json",
    "TemplateSpec": true,
    "Is1PConnector": false
  }
  