{
  "Name": "Lastpass Enterprise Activity Monitoring",
  "Author": "Thijs Lecomte - thijs.lecomte@thecollective.eu",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/LastPass.svg\" width=\"120px\" height=\"60px\">",
  "Description": "[Lastpass Enterprise Activity Monitoring ](https://www.lastpass.com/en/products/business) is a cloud password manager used by organizations to securely save and share passwords.\n\n**Underlying Microsoft Technologies used:**\n\nThis solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs\n\n a. [Codeless Connector Platform/Native Sentinel Polling ](https://docs.microsoft.com/azure/sentinel/create-codeless-connector?tabs=deploy-via-arm-template%2Cconnect-via-the-azure-portal)",
  "Workbooks": [
	"Workbooks/LastPassWorkbook.json"
  ],
  "Analytic Rules": [
	"Analytic Rules/EmployeeAccountDeleted.yaml",
	"Analytic Rules/FailedSigninDueToMFA.yaml",
	"Analytic Rules/HighlySensitivePasswordAccessed.yaml",
	"Analytic Rules/TIMapIPEntityToLastPass.yaml",
	"Analytic Rules/UnusualVolumeOfPasswordsUpdatedOrRemoved.yaml"
  ],
  "Hunting Queries": [
	"Hunting Queries/FailedSigninsDueToMFA.yaml",
	"Hunting Queries/LoginIntoLastPassFromUnknownIP.yaml",
	"Hunting Queries/PasswordMoveToSharedFolder.yaml"
  ],
  "Data Connectors": [
    "Data Connectors/LastPassAPIConnector.json"
  ],
  "Watchlists": [
	"Watchlists/HighlySensitivePasswords.json"
  ],
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\LastPass",
  "Version": "2.0.1",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": true,
  "Is1PConnector": false
}
