{
  "Name": "SecurityThreatEssentialSolution",
  "Author": "Microsoft Corporation - support@microsoft.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Azure_Sentinel.svg\" width=\"75px\" height=\"75px\">",
  "Description": "This solution published by Microsoft is based on the continuous evaluation of threat campaigns and provides out-of-the-box security content that helps you to enhance your security posture.\r\nThis solution leverages the following tables:\r \n • AuditLogs \r \n • AzureActivity \r \n • CommonSecurityLog \r \n • OfficeActivity \r \n • SigninLogs \r \n • VMConnection\r\n",
  "Hunting Queries": [
    "Hunting Queries/Signins-from-NordVPN-Providers.yaml",
    "Hunting Queries/Signins-From-VPS-Providers.yaml"    
  ],
  "Analytic Rules": [
    "Analytic Rules/Threat_Essentials_Mail_redirect_via_ExO_transport_rule.yaml",
    "Analytic Rules/Threat_Essentials_MultipleAdmin_membership_removals_from_NewAdmin.yaml",
    "Analytic Rules/Threat_Essentials_NRT_UseraddedtoPrivilgedGroups.yaml",
    "Analytic Rules/Threat_Essentials_TimeSeriesAnomaly_Mass_Cloud_Resource_Deletions.yaml",
    "Analytic Rules/Threat_Essentials_TimeSeriesAnomaly-MultiVendor_DataExfiltration.yaml",
    "Analytic Rules/Threat_Essentials_UserAssignedPrivilegedRole.yaml",
    "Analytic Rules/PossibleAiTMPhishingAttemptAgainstAAD.yaml"	
  ],
  "dependentDomainSolutionIds": [
    "azuresentinel.azure-sentinel-solution-azureactivedirectory",
    "azuresentinel.azure-sentinel-solution-office365",
    "azuresentinel.azure-sentinel-solution-azureactivity",
    "azuresentinel.azure-sentinel-solution-ciscoasa",
    "azuresentinel.azure-sentinel-solution-paloaltopanos",
    "zscaler1579058425289.zscaler_internet_access_mss"
  ],
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\SecurityThreatEssentialSolution",
  "Version": "3.0.3",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": true
}