{
  "Name": "CrowdStrike Falcon Endpoint Protection",
  "Author": "Microsoft - support@microsoft.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Solutions/CrowdStrike%20Falcon%20Endpoint%20Protection/Data%20Connectors/Logo/crowdstrike.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The [CrowdStrike Falcon Endpoint Protection](https://www.crowdstrike.com/products/) solution allows you to easily onboard CrowdStrike Falcon Endpoint Protection to Microsoft Sentinel. The data collected can be used to create custom dashboards, alerts, and improve investigation. This gives you more insight into your organization's endpoints and improves your security operation capabilities. \n\nThis solution contains multiple Data Connectors that help ingest Falcon Data Replicator logs, Adversary Intelligence & other more specific data from CrowdStrike. Carefully review the capabilities of each connector and configure/enable the most relevant connector based on specific requirements.",
  "Data Connectors": [
    "Data Connectors/CrowdstrikeReplicatorCLv2/CrowdstrikeReplicatorV2_ConnectorUI.json",
    "Data Connectors/CrowdStrikeFalconAdversaryIntelligence/CrowdStrikeFalconAdversaryIntelligence_FunctionApp.json",
    "Data Connectors/CrowdStrikeS3FDR_ccp/DataConnectorDefinition.json",
    "Data Connectors/CrowdStrikeAPI_ccp/CrowdStrikeAPI_Definition.json"
  ],
  "Parsers": [
    "Parsers/CrowdStrikeFalconEventStream.yaml",
    "Parsers/CrowdstrikeReplicator.yaml",
    "Parsers/CrowdStrikeReplicatorV2.yaml"
  ],
  "Workbooks": [
    "Workbooks/CrowdStrikeFalconEndpointProtection.json"
  ],
  "Analytic Rules": [
    "Analytic Rules/CriticalOrHighSeverityDetectionsByUser.yaml",
    "Analytic Rules/CriticalSeverityDetection.yaml"
  ],
  "Playbooks": [
    "Playbooks/CrowdStrike_Base/azuredeploy.json",
    "Playbooks/CrowdStrike_Enrichment_GetDeviceInformation/azuredeploy.json",
    "Playbooks/CrowdStrike_ContainHost/azuredeploy.json"
  ],
  "dependentDomainSolutionIds": [
    "azuresentinel.azure-sentinel-solution-commoneventformat"
  ],
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\CrowdStrike Falcon Endpoint Protection",
  "Version": "3.4.1",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": true,
  "Is1Pconnector": false
}
