{
  "Name": "GoogleCloudPlatformDNS",
  "Author": "Microsoft - support@microsoft.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/google_logo.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The Google Cloud Platform DNS solution  provides the capability to ingest [Cloud DNS query logs](https://cloud.google.com/dns/docs/monitoring#using_logging) and [Cloud DNS audit logs](https://cloud.google.com/dns/docs/audit-logging) into Microsoft Sentinel using the [GCP Logging](https://cloud.google.com/logging/docs/api) API. Refer to GCP Logging [API documentation](https://cloud.google.com/logging/docs/api) for more information.\n\n**Underlying Microsoft Technologies used:**\n\nThis solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs\n\n • [Microsoft Sentinel Codeless Connector Framework](https://aka.ms/Sentinel-CCP_Platform)",
  "Data Connectors": [
    "GoogleCloudPlatformDNS/Data Connectors/GCPDNSLog_CCP/GCPDNSLog_ConnectorDefinition.json"
  ],
  "Parsers": [
    "GoogleCloudPlatformDNS/Parsers/GCPCloudDNS.yaml"
  ],
  "WorkBooks": [
    "GoogleCloudPlatformDNS/WorkBooks/GCPDNS.json"
  ],
  "Analytic Rules": [
    "GoogleCloudPlatformDNS/Analytic Rules/GCPDNSDataExfiltration.yaml",
    "GoogleCloudPlatformDNS/Analytic Rules/GCPDNSExchangeAutodiscoverAbuse.yaml",
    "GoogleCloudPlatformDNS/Analytic Rules/GCPDNSCVE-2021-40444.yaml",
    "GoogleCloudPlatformDNS/Analytic Rules/GCPDNSIpCheck.yaml",
    "GoogleCloudPlatformDNS/Analytic Rules/GCPDNSIpDynDns.yaml",
    "GoogleCloudPlatformDNS/Analytic Rules/GCPDNSMaliciousPythonPackages.yaml",
    "GoogleCloudPlatformDNS/Analytic Rules/GCPDNSMultipleErrorsFromIp.yaml",
    "GoogleCloudPlatformDNS/Analytic Rules/GCPDNSMultipleErrorsQuery.yaml",
    "GoogleCloudPlatformDNS/Analytic Rules/GCPDNSPrintNightmare.yaml",
    "GoogleCloudPlatformDNS/Analytic Rules/GCPDNSSIGREDPattern.yaml",
    "GoogleCloudPlatformDNS/Analytic Rules/GCPDNSUNC2452AptActivity.yaml"
  ],
  "Hunting Queries": [
    "GoogleCloudPlatformDNS/Hunting Queries/GCPDNSErrors.yaml",
    "GoogleCloudPlatformDNS/Hunting Queries/GCPDNSIpLookup.yaml",
    "GoogleCloudPlatformDNS/Hunting Queries/GCPDNSOnlineShares.yaml",
    "GoogleCloudPlatformDNS/Hunting Queries/GCPDNSRareDomains.yaml",
    "GoogleCloudPlatformDNS/Hunting Queries/GCPDNSRareErrors.yaml",
    "GoogleCloudPlatformDNS/Hunting Queries/GCPDNSRequestToTOR.yaml",
    "GoogleCloudPlatformDNS/Hunting Queries/GCPDNSServerLatency.yaml",
    "GoogleCloudPlatformDNS/Hunting Queries/GCPDNSSourceHighErrors.yaml",
    "GoogleCloudPlatformDNS/Hunting Queries/GCPDNSUnexpectedTLD.yaml",
    "GoogleCloudPlatformDNS/Hunting Queries/GCPDNSUnusualTLD.yaml"
  ],
  "BasePath": "C:\\Github\\Azure-Sentinel\\Solutions",
  "Version": "3.0.1",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": true,
  "Is1PConnector": false
}