{
    "Name":  "Speculus Threat Intelligence",
    "Author":  "Speculus - dev@speculus.co",
    "Logo":  "\u003cimg src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/speculus_logo.svg\"width=\"75px\"height=\"75px\"\u003e",
    "Description":  "The [Speculus Threat Intelligence](https://speculus.co) solution ingests STIX 2.1 IP indicators from the Speculus TAXII 2.1 server into Microsoft Sentinel using the Codeless Connector Framework (CCF). Indicators carry risk scoring, named attribution, scanner/Tor/proxy classification, and geo/network enrichment. The solution deploys a REST API poller connector, a custom log table, a data collection rule, analytics rules for matching indicators against network and sign-in telemetry, and an incident-enrichment playbook that looks up IP entities against the Speculus REST API on demand.",
    "Data Connectors":  [
                            "Data Connectors/SpeculusThreatIntel_CCF/Speculus_ConnectorDefinition.json"
                        ],
    "Analytic Rules":  [
                           "Analytic Rules/Speculus - IP Indicator Match CommonSecurityLog.yaml",
                           "Analytic Rules/Speculus - IP Indicator Match SigninLogs.yaml",
                           "Analytic Rules/Speculus - Feed Outage Detection.yaml"
                       ],
    "Playbooks":  [
                       "Playbooks/SpeculusIncidentEnrichment_Playbook.json"
                  ],
    "Metadata":  "SolutionMetadata.json",
    "BasePath":  "C:\\Users\\marcu\\projects\\Azure-Sentinel\\Solutions\\Speculus Threat Intelligence",
    "Version":  "3.0.0",
    "TemplateSpec":  true,
    "Is1Pconnector":  false
}
