{
  "Name": "IoTOTThreatMonitoringwithDefenderforIoT",
  "Author": "Microsoft - support@microsoft.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Workbooks/Images/Logos/Azure_Sentinel.svg\"width=\"75px\"height=\"75px\">",
  "Description": "The [Microsoft Defender for IoT](https://azure.microsoft.com/services/iot-defender/) solution for Microsoft Sentinel allows you to ingest Security alerts reported in Microsoft Defender for IoT on assessing your Internet of Things (IoT)/Operational Technology (OT) infrastructure. \n\n ** Underlying Microsoft Technologies used: ** \n\n This solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs:  \n\n a. [Codeless Connector Platform/Native Microsoft Sentinel Polling](https://docs.microsoft.com/azure/sentinel/create-codeless-connector?tabs=deploy-via-arm-template%2Cconnect-via-the-azure-portal)",
  "Workbooks": [
    "Workbooks/IoTOTThreatMonitoringwithDefenderforIoT.json"
  ],
  "Analytic Rules": [
    "Analytic Rules/IoTDenialofService.yaml",
    "Analytic Rules/IoTExcessiveLoginAttempts.yaml",
    "Analytic Rules/IoTFirmwareUpdates.yaml",
    "Analytic Rules/IoTHighBandwidth.yaml",
    "Analytic Rules/IoTINoSensorTrafficDetected.yaml",
    "Analytic Rules/IoTIllegalFunctionCodes.yaml",
    "Analytic Rules/IoTInsecurePLC.yaml",
    "Analytic Rules/IoTInternetAccess.yaml",
    "Analytic Rules/IoTMalware.yaml",
    "Analytic Rules/IoTNetworkScanning.yaml",
    "Analytic Rules/IoTPLCStopCommand.yaml",
    "Analytic Rules/IoTUnauthorizedDevice.yaml",
    "Analytic Rules/IoTUnauthorizedNetworkConfiguration.yaml",
    "Analytic Rules/IoTUnauthorizedPLCModifications.yaml",
    "Analytic Rules/IoTUnauthorizedRemoteAccess.yaml"
  ],
  "Playbooks": [
    "Playbooks/AutoCloseIncidents/AutoCloseIncidents.json",
    "Playbooks/MailBySensor/MailBySensor.json",
    "Playbooks/NewAssetServiceNowTicket/NewAssetServiceNowTicket.json",
    "Playbooks/AutoAlertStatusSync/AutoAlertStatusSync.json",
    "Playbooks/SendEmailToIoTOwner/SendEmailToIoTOwner.json",
    "Playbooks/AutoTriageIncident/AutoTriageIncident.json",
    "Playbooks/CVEAutoWorkflow/CVEAutoWorkflow.json"
  ],
  "Data Connectors": [
    "Data Connector/template_IoT.JSON"
  ],
  "Metadata": "SolutionMetadata.json",
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\IoTOTThreatMonitoringwithDefenderforIoT",
  "Version": "2.0.2",
  "TemplateSpec": true,
  "StaticDataConnectorIds": [
    "IoT"
  ]
}