{
    "Name": "Cyborg Security HUNTER",
    "Author": "Mike Mitchell - mike@cyborgsecurity.com",
    "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/cyborgsecurity-logo-75px.svg\" width=\"75px\" height=\"75px\">",
    "Description": "The [Cyborg Security HUNTER](https://www.cyborgsecurity.com/) solution for Microsoft Sentinel helps analysts to configure the 'Open in Tool' button within the HUNTER platform, allowing the Microsoft Sentinel hunt packages to be deployed in the Microsoft Sentinel Platform",
    "HuntingQueryBladeDescription": "This solution installs the following Cyborg Security HUNTER hunting queries. After installing the solution, run these hunting queries to hunt for threats in Manage solution view",
    "Data Connectors": [
      "Data Connectors/CyborgSecurity_HUNTER.json"
    ],
    "Hunting Queries" : [
      "Hunting Queries/Attempted VBScript Stored in Non-Run CurrentVersion Registry Key Value.yaml",
      "Hunting Queries/Excessive Windows Discovery and Execution Processes - Potential Malware Installation.yaml",
      "Hunting Queries/LSASS Memory Dumping using WerFault.exe - Command Identification.yaml",
      "Hunting Queries/Metasploit Impacket PsExec Process Creation Activity.yaml",
      "Hunting Queries/Potential Maldoc Execution Chain Observed.yaml",
      "Hunting Queries/Powershell Encoded Command Execution.yaml",
      "Hunting Queries/PowerShell Pastebin Download.yaml",
      "Hunting Queries/Prohibited Applications Spawning cmd.exe or powershell.exe.yaml",
      "Hunting Queries/Proxy VBScript Execution via CurrentVersion Registry Key.yaml",
      "Hunting Queries/Rundll32 or cmd Executing Application from Explorer - Potential Malware Execution Chain.yaml"
    ],
    "BasePath": "Solutions/Cyborg Security HUNTER",
    "Version": "3.0.0",
    "Metadata": "SolutionMetadata.json",
    "TemplateSpec": true,
    "Is1Pconnector": false
  }