{
  "Name": "ContraForce",
  "Author": "ContraForce - support@contraforce.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/contraforce.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The [ContraForce](https://www.contraforce.com) solution for Microsoft Sentinel ingests security service delivery events from your ContraForce workspace: incident detections from every connected security platform, administrative access changes (role and member changes), machine credential activity, and destructive workspace actions. The packaged analytic rules create Microsoft Sentinel incidents for privileged access changes, machine credential activity, and destructive workspace actions, so you can monitor the security operations ContraForce performs on your workspace from inside your own Microsoft Sentinel.",
  "Data Connectors": [
    "Data Connectors/ContraForceEvents_ccp/ContraForceEvents_DataConnectorDefinition.json"
  ],
  "Analytic Rules": [
    "Analytic Rules/ContraForcePrivilegedAccessChange.yaml",
    "Analytic Rules/ContraForceMachineCredentialActivity.yaml",
    "Analytic Rules/ContraForceDestructiveWorkspaceAction.yaml"
  ],
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\ContraForce",
  "Version": "3.0.0",
  "DataConnectorCCFVersion": "1.0.0",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": true,
  "Is1PConnector": false
}
