{
  "Name": "Microsoft Exchange Security - Exchange On-Premises",
  "Author": "Microsoft - support@microsoft.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Azure_Sentinel.svg\"width=\"75px\"height=\"75px\">",
  "Description": "The Exchange Security Audit and Configuration Insight solution analyze Exchange On-Premises configuration and logs from a security lens to provide insights and alerts.\n\n**Underlying Microsoft Technologies used:**\n\nThis solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs:\n\na. [Windows Event logs collection, including MS Exchange Management Event logs](https://learn.microsoft.com/azure/azure-monitor/agents/data-sources-windows-events)\n\nb. [Custom logs ingestion via Data Collector REST API](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/data-collector-api?tabs=powershell)",
  "Data Connectors": [
    "Data Connectors/ESI-ExchangeAdminAuditLogEvents.json",
    "Data Connectors/ESI-ExchangeOnPremisesCollector.json",
    "Data Connectors/ESI-Opt1ExchangeAdminAuditLogsByEventLogs.json",
    "Data Connectors/ESI-Opt2ExchangeServersEventLogs.json",
    "Data Connectors/ESI-Opt34DomainControllersSecurityEventLogs.json",
    "Data Connectors/ESI-Opt5ExchangeIISLogs.json",
    "Data Connectors/ESI-Opt6ExchangeMessageTrackingLogs.json",
    "Data Connectors/ESI-Opt7ExchangeHTTPProxyLogs.json"
  ],
  "Parsers": [
    "Parsers/ExchangeAdminAuditLogs.yaml",
    "Parsers/ExchangeConfiguration.yaml",
    "Parsers/ExchangeEnvironmentList.yaml",
    "Parsers/MESCheckVIP.yaml",
    "Parsers/MESCompareDataOnPMRA.yaml"
  ],
  "Workbooks": [
    "Workbooks/Microsoft Exchange Least Privilege with RBAC.json",
    "Workbooks/Microsoft Exchange Search AdminAuditLog.json",
    "Workbooks/Microsoft Exchange Admin Activity.json",
    "Workbooks/Microsoft Exchange Security Review.json"
  ],
  "Analytic Rules": [
    "Analytic Rules/CriticalCmdletsUsageDetection.yaml",
    "Analytic Rules/ServerOrientedWithUserOrientedAdministration.yaml"
  ],
  "Watchlists": [
    "Watchlists/ExchangeServicesMonitoring.json",
    "Watchlists/ExchangeVIP.json"
  ],
  "BasePath": "C:\\Git Repositories\\Azure-Sentinel\\Solutions\\Microsoft Exchange Security - Exchange On-Premises\\",
  "Version": "3.3.2",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": true,
  "Is1Pconnector": false
}