{
  "Name": "Vectra XDR",
  "Author": "TME - tme@vetcra.ai",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Vectra_RUX.svg\" width=\"75px\" height=\"75px\">",
  "Description": "Vectra AI is the leader in AI-driven threat detection and response for hybrid and multi-cloud enterprises. Vectra AI's cloud-native platform - powered by our patented Attack Signal Intelligence- provide security teams with unified threat visibility, context and control across public cloud, SaaS, identity and data center networks in a prioritized feed. Vectra AI-driven Attack Signal IntelligenceTM, empowers SOC analysts to rapidly prioritize, investigate and respond to the most urgent cyber-attacks in their hybrid cloud environment. Organizations worldwide rely on Vectra AI's cloud-native platform and MDR services to see and stop attacks from becoming breaches. The Vectra AI App enables the security operations team to consume the industry's richest threat signals spanning public cloud, SaaS, identity and data center networks inside of Microsoft Sentinel. For more information, visit www.vectra.ai.\n\n The Vectra XDR App for Microsoft Sentinel contains:\n Data Connector to ingest events generated by Vectra XDR (through OMS agent).\n Workbook: Dynamic dashboard view of Entities, Detections, Lockdown, Audit and, Health",
  "Data Connectors": [
    "Data Connectors/VectraDataConnector/VectraXDR_API_FunctionApp.json",
    "Data Connectors/VectraCCFConnector/VectraRUX_ConnectorDefinition.json"
  ],
  "Parsers": [
    "Parsers/VectraDetectionsCombined.yaml",
    "Parsers/VectraEntities.yaml",
    "Parsers/VectraLockdown.yaml"
  ],
  "Analytic Rules": [
    "Analytic Rules/Vectra_RUX_Incident_Detection_Account.yaml",
    "Analytic Rules/Vectra_RUX_Incident_Detection_Host.yaml"
  ],
  "Workbooks": [
    "Workbooks/VectraRUXSecurityDashboard.json",
    "Workbooks/VectraRUXDetectionTimeline.json"
  ],
  "Playbooks": [
    "Playbooks/VectraAddNoteToDetections/azuredeploy.json",
    "Playbooks/VectraAddNoteToEntity/azuredeploy.json",
    "Playbooks/VectraAddTagToDetections/azuredeploy.json",
    "Playbooks/VectraAddTagToEntity/azuredeploy.json",
    "Playbooks/VectraAddTagToEntityAllDetections/azuredeploy.json",
    "Playbooks/VectraAddTagToEntitySelectedDetections/azuredeploy.json",
    "Playbooks/VectraAssignDynamicUserToEntity/azuredeploy.json",
    "Playbooks/VectraAssignStaticUserToEntity/azuredeploy.json",
    "Playbooks/VectraCloseDetections/azuredeploy.json",
    "Playbooks/VectraCloseDetectionsOnIncidentClose/azuredeploy.json",
    "Playbooks/VectraDetectionTimelineLink/azuredeploy.json",
    "Playbooks/VectraDownloadPcapFileToStorage/azuredeploy.json",
    "Playbooks/VectraDynamicAssignMembersToGroup/azuredeploy.json",
    "Playbooks/VectraGenerateAccessToken/azuredeploy.json",
    "Playbooks/VectraIncidentTimelineUpdate/azuredeploy.json",
    "Playbooks/VectraOpenClosedDetections/azuredeploy.json",
    "Playbooks/VectraSetDetectionStatus/azuredeploy.json",
    "Playbooks/VectraStaticAssignMembersToGroup/azuredeploy.json",
    "Playbooks/VectraUpdateIncidentBasedOnTagAndNotify/azuredeploy.json"
  ],
  "BasePath": "C:\\Users\\nirali.shah\\Azure-Sentinel\\Solutions\\Vectra XDR",
  "Version": "3.3.1",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": true,
  "Is1PConnector": false
}
