{
  "Name": "1Password",
  "Author": "Rogier Dijkman (SecureHats)",
  "Logo": "<img src=\"https://raw.githubusercontent.com/azurekid/Azure-Sentinel/master/Logos/1password.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The [1Password](https://www.1password.com) solution for Microsoft Sentinel enables you to ingest sign-in attempts, item usage, and audit events from your 1Password Business account using the [1Password Events Reporting API](https://developer.1password.com/docs/events-api). This allows you to monitor and investigate events in 1Password in Microsoft Sentinel along with the other applications and services your organization uses.\n\n**Underlying Microsoft Technologies used:**\n\nThis solution depends on the following technologies, and some of which may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or may incur additional ingestion or operational costs:\n\na.  [Azure Functions](https://azure.microsoft.com/services/functions/#overview)",
  "WorkbookBladeDescription": "This Microsoft Sentinel Solution installs workbooks. Workbooks provide a flexible canvas for data monitoring, analysis, and creating rich visual reports within the Azure portal. They allow you to combine one or more data sources from Microsoft Sentinel into unified interactive experience.",
  "Data Connectors": [
    "Data Connectors/1Password_ccpv2/1Password_DataConnectorDefinition.json",
    "Data Connectors/1Password_API_FunctionApp.json"
  ],
  "Workbooks": [
    "Workbooks/1Password.json"
  ],
  "Parsers": [],
  "Analytic Rules": [
    "Analytics Rules/1Password - Changes to firewall rules.yaml",
    "Analytics Rules/1Password - Changes to SSO configuration.yaml",
    "Analytics Rules/1Password - Disable MFA factor or type for all user accounts.yaml",
    "Analytics Rules/1Password - Log Ingestion Failure.yaml",
    "Analytics Rules/1Password - Manual account creation.yaml",
    "Analytics Rules/1Password - New service account integration created.yaml",
    "Analytics Rules/1Password - Non-privileged vault user permission change.yaml",
    "Analytics Rules/1Password - Potential insider privilege escalation via group.yaml",
    "Analytics Rules/1Password - Potential insider privilege escalation via vault.yaml",
    "Analytics Rules/1Password - Privileged vault permission change.yaml",
    "Analytics Rules/1Password - Secret extraction post vault access change by administrator.yaml",
    "Analytics Rules/1Password - Service account integration token adjustment.yaml",
    "Analytics Rules/1Password - Successful anomalous sign-in.yaml",
    "Analytics Rules/1Password - User account MFA settings changed.yaml",
    "Analytics Rules/1Password - User added to privileged group.yaml",
    "Analytics Rules/1Password - Vault export post account creation.yaml",
    "Analytics Rules/1Password - Vault export prior to account suspension or deletion.yaml",
    "Analytics Rules/1Password - Vault export.yaml"
  ],
  "BasePath": "C:\\GitHub\\azure-Sentinel\\Solutions\\1Password",
  "Version": "3.0.5",
  "DataConnectorCCFVersion": "1.0.3",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": true,
  "Is1PConnector": false
}
