{
  "Name": "Red Sift",
  "Author": "Red Sift - support@redsift.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/redsift_logo.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The [Red Sift](https://redsift.com/) solution for Microsoft Sentinel provides the capability to ingest authentication events from Red Sift Pulse and email forensics events from OnDMARC into your Microsoft Sentinel workspace using the Codeless Connector Framework (CCF) Push pattern.\n\n**Underlying Microsoft Technologies used:**\n\nThis solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs:\n\na. [Microsoft Sentinel](https://learn.microsoft.com/azure/sentinel/overview)\n\nb. [Azure Monitor](https://learn.microsoft.com/azure/azure-monitor/overview)\n\nc. [Codeless Connector Framework](https://learn.microsoft.com/azure/sentinel/create-codeless-connector)",
  "Analytic Rules": [
    "Analytic Rules/RedSiftLoginFromNewIP.yaml",
    "Analytic Rules/RedSiftEmailUrlFromNewSource.yaml",
    "Analytic Rules/RedSiftEmailUrlFromNewSender.yaml",
    "Analytic Rules/RedSiftMFADisabled.yaml",
    "Analytic Rules/RedSiftEmailUrlWithNewDomain.yaml"
  ],
  "Data Connectors": [
    "Data Connectors/RedSift_ccp/RedSift_Definition.json"
  ],
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Red Sift",
  "Version": "3.0.0",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": false,
  "Is1PConnector": false
}
