{
  "Name": "Uniqkey",
  "Author": "Uniqkey - support@uniqkey.eu",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Uniqkey.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The [Uniqkey](https://uniqkey.eu/) solution for Microsoft Sentinel enables ingestion of security and audit events from the Uniqkey business password management platform. Events cover authentication, credential access, credential management, sharing, policy management, threat detection and other administrative activity, giving security teams visibility into password and access hygiene across the organization.\n\n**Underlying Microsoft Technologies used:**\n\nThis solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs:\n\na. [Microsoft Sentinel Codeless Connector Framework](https://aka.ms/Sentinel-CCP_Platform)",
  "BasePath": "C:\\Repositories\\sentinel\\Azure-Sentinel\\Solutions\\Uniqkey",
  "Version": "3.0.0",
  "TemplateSpec": false,
  "Is1PConnector": false,
  "Data Connectors": [
    "Data Connectors/UniqkeyAuditLogs_ccf/Uniqkey_ConnectorDefinition.json"
  ],
  "Analytic Rules": [
    "Analytic Rules/Uniqkey - Sign-in from unfamiliar IP address.yaml",
    "Analytic Rules/Uniqkey - Data export activity.yaml",
    "Analytic Rules/Uniqkey - Departing employee credential export.yaml",
    "Analytic Rules/Uniqkey - Credential export from newly created account.yaml",
    "Analytic Rules/Uniqkey - Excessive credential access.yaml",
    "Analytic Rules/Uniqkey - Self-granted privilege or access change.yaml",
    "Analytic Rules/Uniqkey - Security policy change.yaml",
    "Analytic Rules/Uniqkey - Platform threat detection.yaml",
    "Analytic Rules/Uniqkey - Event ingestion stopped.yaml"
  ],
  "Workbooks": [
    "Workbooks/Uniqkey.json"
  ],
  "Metadata": "SolutionMetadata.json"
}
