{
  "Name": "GitHub",
  "Author": "Microsoft - support@microsoft.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/GitHub.svg\"width=\"75px\"height=\"75px\">",
  "Description": "The [GitHub](https://github.com/) Solution for Microsoft Sentinel enables you to easily ingest events and logs from GitHub to Microsoft Sentinel using GitHub audit log API and  webhooks. This enables you to view and analyze this data in your workbooks, query it to create custom alerts, and incorporate it to improve your investigation process, giving you more insight into your platform security.\n \n **Underlying Microsoft Technologies used:** \n \n This solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs:\n \n 1. [Codeless Connector Framework (CCF) (used in GitHub Enterprise Audit Log data connector)](https://docs.microsoft.com/azure/sentinel/create-codeless-connector?tabs=deploy-via-arm-template%2Cconnect-via-the-azure-portal) \n \n 2. [Azure Functions ](https://azure.microsoft.com/services/functions/#overview)\n\n<p><span style='color:red; font-weight:bold;'>NOTE</span>: Microsoft recommends installation of \"GitHubAuditDefinitionV2\" (via Codeless Connector Framework). This connector is build on the Codeless Connector Framework (CCF), which uses the Log Ingestion API, which replaces ingestion via the <a href='https://aka.ms/Sentinel-Logs_migration' style='color:#1890F1;'>deprecated HTTP Data Collector API</a>. CCF-based data connectors also support <a href='https://aka.ms/Sentinel-DCR_Overview' style='color:#1890F1;'>Data Collection Rules</a> (DCRs) offering transformations and enrichment.</p>\n\n<p><span style='color:red; font-weight:bold;'>Important</span>: While the updated connector(s) can coexist with their legacy versions, running them together will result in duplicated data ingestion. You can disable the older versions of these connectors to avoid duplication of data..</p>",
  "Workbooks": [
    "Workbooks/GitHubAdvancedSecurity.json",
    "Workbooks/GitHub.json"
  ],
  "Analytic Rules": [
    "Analytic Rules/GitHub - A payment method was removed.yaml",
    "Analytic Rules/GitHub - Activities from Infrequent Country.yaml",
    "Analytic Rules/GitHub - Oauth application - a client secret was removed.yaml",
    "Analytic Rules/GitHub - Repository was created.yaml",
    "Analytic Rules/GitHub - Repository was destroyed.yaml",
    "Analytic Rules/GitHub - Two Factor Authentication Disabled in GitHub.yaml",
    "Analytic Rules/GitHub - User visibility Was changed.yaml",
    "Analytic Rules/GitHub - User was added to the organization.yaml",
    "Analytic Rules/GitHub - User was blocked.yaml",
    "Analytic Rules/GitHub - User was invited to the repository.yaml",
    "Analytic Rules/GitHub - pull request was created.yaml",
    "Analytic Rules/GitHub - pull request was merged.yaml",
    "Analytic Rules/NRT Two Factor Authentication Disabled.yaml",
    "Analytic Rules/Security Vulnerability in Repo.yaml"
  ],
  "Hunting Queries": [
    "Hunting Queries/First Time User Invite and Add Member to Org.yaml",
    "Hunting Queries/Inactive or New Account Usage.yaml",
    "Hunting Queries/Mass Deletion of Repositories .yaml",
    "Hunting Queries/Oauth App Restrictions Disabled.yaml",
    "Hunting Queries/Org Repositories Default Permissions Change.yaml",
    "Hunting Queries/Repository Permission Switched to Public.yaml",
    "Hunting Queries/User First Time Repository Delete Activity.yaml",
    "Hunting Queries/User Grant Access and Grants Other Access.yaml"
  ],
  "Parsers": [
    "Parsers/GitHubAuditData.yaml",
    "Parsers/GitHubCodeScanningData.yaml",
    "Parsers/GitHubDependabotData.yaml",
    "Parsers/GitHubSecretScanningData.yaml",
    "Parsers/GitHubScanAudit.yaml"
  ],
  "Data Connectors": [
    "Data Connectors/GitHubAuditLogs_AzStorage/ConnectorDefinition.json",
    "Data Connectors/GitHubAuditLogs_CCF/GitHubAuditLogs_ConnectorDefinition.json",
    "Data Connectors/azuredeploy_GitHub_native_poller_connector.json",
    "Data Connectors/GithubWebhook/GithubWebhook_API_FunctionApp.json",
    "Data Connectors/GithubWebhookV2/GithubWebhookV2_API_FunctionApp.json"
  ],
  "Metadata": "SolutionMetadata.json",
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\GitHub",
  "Version": "3.5.1",
  "TemplateSpec": true,
  "Is1PConnector": false
}
