{
  "Name": "SentinelOne",
  "Author": "Microsoft - support@microsoft.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Azure_Sentinel.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The [SentinelOne](https://www.sentinelone.com/) solution provides ability to bring SentinelOne events to your Microsoft Sentinel Workspace to inform and to examine potential security risks, analyze your team's use of collaboration, diagnose configuration problems and more. \r \n \r \n **Underlying Microsoft Technologies used:** \r \n \r \n This solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs:\r \n \r \n a. [Azure Monitor HTTP Data Collector API](https://docs.microsoft.com/azure/azure-monitor/logs/data-collector-api) \r \n \r \n b. [Azure Functions](https://azure.microsoft.com/services/functions/#overview)",
  "Data Connectors": [
    "Data Connectors/SentinelOne_ccp/connectorDefinition.json",
    "Data Connectors/SentinelOneV2_ccf/SentinelOneV2_ConnectorDefinition.json",
    "Data Connectors/SentinelOne_API_FunctionApp.json"
  ],
  "Workbooks": [
    "Workbooks/SentinelOne.json"
  ],
  "Parsers": [
    "Parsers/SentinelOne.yaml"
  ],
  "Analytic Rules": [
    "Analytic Rules/SentinelOneAdminLoginNewIP.yaml",
    "Analytic Rules/SentinelOneAgentUninstalled.yaml",
    "Analytic Rules/SentinelOneAlertFromCustomRule.yaml",
    "Analytic Rules/SentinelOneBlacklistHashDeleted.yaml",
    "Analytic Rules/SentinelOneExclusionAdded.yaml",
    "Analytic Rules/SentinelOneMultipleAlertsOnHost.yaml",
    "Analytic Rules/SentinelOneNewAdmin.yaml",
    "Analytic Rules/SentinelOneRuleDeleted.yaml",
    "Analytic Rules/SentinelOneRuleDisabled.yaml",
    "Analytic Rules/SentinelOneSameCustomRuleHitOnDiffHosts.yaml",
    "Analytic Rules/SentinelOneViewAgentPassphrase.yaml"
  ],
  "Hunting Queries": [
    "Hunting Queries/SentinelOneAgentNotUpdated.yaml",
    "Hunting Queries/SentinelOneAgentStatus.yaml",
    "Hunting Queries/SentinelOneAlertTriggers.yaml",
    "Hunting Queries/SentinelOneHostNotScanned.yaml",
    "Hunting Queries/SentinelOneNewRules.yaml",
    "Hunting Queries/SentinelOneRulesDeleted.yaml",
    "Hunting Queries/SentinelOneScannedHosts.yaml",
    "Hunting Queries/SentinelOneSourcesByAlertCount.yaml",
    "Hunting Queries/SentinelOneUninstalledAgents.yaml",
    "Hunting Queries/SentinelOneUsersByAlertCount.yaml"
  ],
  "BasePath": "C:\\Github\\Azure-Sentinel\\Solutions\\SentinelOne",
  "Version": "3.1.3",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": true,
  "Is1PConnector": false
}
