{
  "Name": "Halcyon",
  "Author": "Halcyon - support@halcyon.ai",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/halcyon.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The [Halcyon](https://www.halcyon.ai) solution for Microsoft Sentinel enables you to ingest Halcyon Events and Alert Updates into Microsoft Sentinel using the Microsoft Sentinel Analytics Workspace.\n\n**Underlying Microsoft Technologies used:**\n\nThis solution takes a dependency on the following Microsoft technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional data ingestion or operational costs:\n\na. [Microsoft Sentinel](https://learn.microsoft.com/azure/sentinel/)\n\nb. [Azure Monitor Data Collection Rules (DCR)](https://learn.microsoft.com/azure/azure-monitor/essentials/data-collection-rule-overview)\n\nc. [Azure Monitor Data Collection Endpoints (DCE)](https://learn.microsoft.com/azure/azure-monitor/essentials/data-collection-endpoint-overview)\n\nd. [Azure Log Analytics workspaces](https://learn.microsoft.com/azure/azure-monitor/logs/log-analytics-workspace-overview)",
  "Data Connectors": [
    "Data Connectors/Halcyon_ccp_v2/Halcyon_connectorDefinition.json"
  ],
  "Parsers": [
    "Parsers/Halcyon_Alerts.yaml",
    "Parsers/Halcyon_OCSF_ApplicationLifecycle.yaml",
    "Parsers/Halcyon_OCSF_Authentication.yaml",
    "Parsers/Halcyon_OCSF_DnsActivity.yaml",
    "Parsers/Halcyon_OCSF_FileActivity.yaml",
    "Parsers/Halcyon_OCSF_KernelActivity.yaml",
    "Parsers/Halcyon_OCSF_NetworkActivity.yaml",
    "Parsers/Halcyon_OCSF_ProcessActivity.yaml"
  ],
  "Workbooks": [],
  "Analytic Rules": [],
  "Hunting Queries": [],
  "Playbooks": [],
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Halcyon",
  "Version": "3.2.0",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": false,
  "Is1PConnector": false
}
