{
  "Name": "Microsoft 365",
  "Author": "Microsoft - support@microsoft.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Workbooks/Images/Logos/office365_logo.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The Microsoft 365 solution for Microsoft Sentinel enables you to ingest operational logs from Microsoft 365 (formerly, Office 365) to gain insights into user and admin activity across your collaboration platforms such as Teams, SharePoint and Exchange.\r\n  \r\n  **Underlying Microsoft Technologies used:**\r\n\n  This solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs:\r\n\n  a. [Azure Monitor HTTP Data Collector API](https://docs.microsoft.com/azure/azure-monitor/logs/data-collector-api)",
 "Data Connectors": [
    "Data Connectors/Microsoft365.json"
  ],
	"Workbooks": [
    "Workbooks/SharePointAndOneDrive.json",
    "Workbooks/Office365.json" ,
    "Workbooks/ExchangeOnline.json"
  ],
  "Hunting Queries": [
       "Hunting Queries/AnomolousUserAccessingOtherUsersMailbox.yaml",
       "Hunting Queries/ExternalUserAddedRemovedInTeams_HuntVersion.yaml",
       "Hunting Queries/ExternalUserFromNewOrgAddedToTeams.yaml",
       "Hunting Queries/Mail_redirect_via_ExO_transport_rule_hunting.yaml",
       "Hunting Queries/MultiTeamBot.yaml",
       "Hunting Queries/MultiTeamOwner.yaml",
       "Hunting Queries/MultipleTeamsDeletes.yaml",
       "Hunting Queries/NewBotAddedToTeams.yaml",
       "Hunting Queries/New_WindowsReservedFileNamesOnOfficeFileServices.yaml",
       "Hunting Queries/OfficeMailForwarding_hunting.yaml",
       "Hunting Queries/TeamsFilesUploaded.yaml",
       "Hunting Queries/UserAddToTeamsAndUploadsFile.yaml",
       "Hunting Queries/WindowsReservedFileNamesOnOfficeFileServices.yaml",
       "Hunting Queries/double_file_ext_exes.yaml",
       "Hunting Queries/new_adminaccountactivity.yaml",
       "Hunting Queries/new_sharepoint_downloads_by_IP.yaml",
       "Hunting Queries/new_sharepoint_downloads_by_UserAgent.yaml",
       "Hunting Queries/nonowner_MailboxLogin.yaml",
       "Hunting Queries/powershell_or_nonbrowser_MailboxLogin.yaml",
       "Hunting Queries/sharepoint_downloads.yaml",
       "Hunting Queries/MultipleUsersEmailForwardedToSameDestination.yaml"    
  ],
  "Analytic Rules": [
       "Analytic Rules/External User added to Team and immediately uploads file.yaml",
       "Analytic Rules/ExternalUserAddedRemovedInTeams.yaml",
       "Analytic Rules/MailItemsAccessedTimeSeries.yaml",
       "Analytic Rules/Mail_redirect_via_ExO_transport_rule.yaml",
       "Analytic Rules/Malicious_Inbox_Rule.yaml",
       "Analytic Rules/MultipleTeamsDeletes.yaml",
       "Analytic Rules/Office_MailForwarding.yaml",
       "Analytic Rules/Office_Uploaded_Executables.yaml",
       "Analytic Rules/RareOfficeOperations.yaml",
       "Analytic Rules/SharePoint_Downloads_byNewIP.yaml",
       "Analytic Rules/SharePoint_Downloads_byNewUserAgent.yaml",
       "Analytic Rules/exchange_auditlogdisabled.yaml",
       "Analytic Rules/office_policytampering.yaml",
       "Analytic Rules/sharepoint_file_transfer_folders_above_threshold.yaml",
       "Analytic Rules/sharepoint_file_transfer_above_threshold.yaml"
  ],
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\solutions\\Microsoft 365",
  "Version": "3.0.5",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": true,
  "StaticDataConnectorIds": [
    "Office365"
  ]
}