{
  "Name": "Cyfirma Cyber Intelligence",
  "Author": "Microsoft",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Cyfirma_logo.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The CYFIRMA Cyber Intelligence solution integrates with Microsoft Sentinel to provide actionable intelligence on IOCs, threat actors, malicious campaigns, and malware. This integration enables security teams to detect, analyze, and respond to emerging threats by correlating external threat data with internal telemetry. By ingesting enriched threat intelligence into Sentinel, organizations gain visibility into malicious activity, track threat actor tactics, and automate defense mechanisms to mitigate risks proactively.",
  "Analytic Rules": [
    "Analytic Rules/C2NetworkIndicatorsBlockHighSeverityRule.yaml",
    "Analytic Rules/C2NetworkIndicatorsBlockMediumSeverityRule.yaml",
    "Analytic Rules/C2NetworkIndicatorsMonitorHighSeverityRule.yaml",
    "Analytic Rules/C2NetworkIndicatorsMonitorMediumSeverityRule.yaml",
    "Analytic Rules/MalwareFileHashIndicatorsBlockHighSeverityRule.yaml",
    "Analytic Rules/MalwareFileHashIndicatorsBlockMediumSeverityRule.yaml",
    "Analytic Rules/MalwareFileHashIndicatorsMonitorHighSeverityRule.yaml",
    "Analytic Rules/MalwareFileHashIndicatorsMonitorMediumSeverityRule.yaml",
    "Analytic Rules/MalwareNetworkIndicatorsMonitorHighSeverityRule.yaml",
    "Analytic Rules/MalwareNetworkIndicatorsMonitorMediumSeverityRule.yaml",
    "Analytic Rules/MalwareNetworkIndicatorsBlockHighSeverityRule.yaml",
    "Analytic Rules/MalwareNetworkIndicatorsBlockMediumSeverityRule.yaml",
    "Analytic Rules/NetworkIndicatorsBlockHighSeverityRule.yaml",
    "Analytic Rules/NetworkIndicatorsBlockMediumSeverityRule.yaml",
    "Analytic Rules/NetworkIndicatorsMonitorHighSeverityRule.yaml",
    "Analytic Rules/NetworkIndicatorsMonitorMediumSeverityRule.yaml",
    "Analytic Rules/PhishingNetworkIndicatorsBlockHighSeverityRule.yaml",
    "Analytic Rules/PhishingNetworkIndicatorsBlockMediumSeverityRule.yaml",
    "Analytic Rules/PhishingNetworkIndicatorsMonitorHighSeverityRule.yaml",
    "Analytic Rules/PhishingNetworkIndicatorsMonitorMediumSeverityRule.yaml",
    "Analytic Rules/TORNodeNetworkIndicatorsBlockHighSeverityRule.yaml",
    "Analytic Rules/TORNodeNetworkIndicatorsBlockMediumSeverityRule.yaml",
    "Analytic Rules/TORNodeNetworkIndicatorsMonitorHighSeverityRule.yaml",
    "Analytic Rules/TORNodeNetworkIndicatorsMonitorMediumSeverityRule.yaml",
    "Analytic Rules/FileHashIndicatorsBlockHighSeverityRule.yaml",
    "Analytic Rules/FileHashIndicatorsBlockMediumSeverityRule.yaml",
    "Analytic Rules/FileHashIndicatorsMonitorHighSeverityRule.yaml",
    "Analytic Rules/FileHashIndicatorsMonitorMediumSeverityRule.yaml",
    "Analytic Rules/TrojanNetworkIndicatorsBlockHighSeverityRule.yaml",
    "Analytic Rules/TrojanNetworkIndicatorsBlockMediumSeverityRule.yaml",
    "Analytic Rules/TrojanFileHashIndicatorsBlockHighSeverityRule.yaml",
    "Analytic Rules/TrojanFileHashIndicatorsBlockMediumSeverityRule.yaml",
    "Analytic Rules/TrojanFileHashIndicatorsMonitorHighSeverityRule.yaml",
    "Analytic Rules/TrojanFileHashIndicatorsMonitorMediumSeverityRule.yaml",
    "Analytic Rules/TrojanNetworkIndicatorsMonitorHighSeverityRule.yaml",
    "Analytic Rules/TrojanNetworkIndicatorsMonitorMediumSeverityRule.yaml"
  ],
  "Parsers": [],
  "Data Connectors": [
    "Data Connectors/CyfirmaCyberIntelligence_ccp/CyfirmaCyberIntel_DataConnectorDefinition.json"
  ],
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Cyfirma Cyber Intelligence",
  "Version": "3.0.0",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": false,
  "Is1PConnector": false
}