{
    "Name": "Cyfirma Compromised Accounts",
    "Author": "Microsoft",
    "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Cyfirma_logo.svg\" width=\"75px\" height=\"75px\">",
    "Description": "The CYFIRMA Compromised Accounts solution integrates with Microsoft Sentinel to provide timely intelligence on user accounts exposed through data breaches, stealer logs, and dark web forums. It helps organizations identify compromised credentials linked to corporate domains, reducing the risk of account takeover and unauthorized access. Enriched account breach data is ingested into Sentinel, enabling security teams to correlate with internal activity, trigger alerts, and automate remediation actions such as password resets and access revocation.",
    "Analytic Rules": [
        "Analytic Rules/CompromisedEmployeesRule.yaml",
        "Analytic Rules/CustomerAccountsLeaksRule.yaml",
        "Analytic Rules/PublicAccountsLeaksRule.yaml"
    ],
    "Parsers": [],
    "Data Connectors": [
        "Data Connectors/CyfirmaCompromisedAccounts_ccp/CyfirmaCompAcc_DataConnectorDefinition.json"
    ],
    "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Cyfirma Compromised Accounts",
    "Version": "3.0.0",
    "Metadata": "SolutionMetadata.json",
    "TemplateSpec": false,
    "Is1PConnector": false
}