{
  "Name": "42Crunch API Protection",
  "Author": "42Crunch - plugins@42crunch.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/42CrunchLogo.svg\"width=\"75px\"height=\"75px\">",
  "Description": "The [42Crunch](https://42crunch.com/) API Protection solution protects APIs by installing a microfirewall inline with the API server. Access logs from the microfirewall are emitted to Microsoft Sentinel allowing analysis and investigation of attacks.",
  "WorkbookBladeDescription": "This Solution installs a workbook for 42Crunch API Protection. You can use this workbook to view and analyze the data collected by the 42Crunch API Protection data connector. The following workbook elements are included: 1. Requests by IP address - show the number of requests per unique IP address, 2. Status Code Return - shows a summary view of HTTP status codes returned, 3. Hits by Instances - the number of requests made to instances, 4. Requests over time - a time series view of requests to all instances, 5. Protection Instances - summary views of the known protection instances.",
  "Workbooks": [
    "Workbooks/42CrunchAPIProtectionWorkbook.json"
  ],
  "Analytic Rules": [
    "Analytic Rules/APIAccountTakeover.yaml",
    "Analytic Rules/APIAnomalyDetection.yaml",
    "Analytic Rules/APIAPIScaping.yaml",
    "Analytic Rules/APIBOLA.yaml",
    "Analytic Rules/APIFirstTimeAccess.yaml",
    "Analytic Rules/APIInvalidHostAccess.yaml",
    "Analytic Rules/APIJWTValidation.yaml",
    "Analytic Rules/APIKiterunnerDetection.yaml",
    "Analytic Rules/APIPasswordCracking.yaml",
    "Analytic Rules/APIRateLimiting.yaml",
    "Analytic Rules/APISuspiciousLogin.yaml"
  ],
  "Parsers": [
    "Parsers/FortyTwoCrunchAPIProtection.yaml",
    "Parsers/parser_FortyTwoCrunchAPIProtectionV2AliasFunction.json"
  ],
  "Data Connectors": [
    "Data Connectors/42Crunch/42CrunchAPIProtection.json",
    "Data Connectors/42Crunch_CCF/42CrunchAPIProtection_ConnectorDefinition.json"
  ],
  "Metadata": "SolutionMetadata.json",
  "BasePath": "Solutions/42Crunch API Protection",
  "Version": "3.0.3",
  "TemplateSpec": false,
  "Is1PConnector": false
}
