{
  "Name": "Utimaco Enterprise Secure Key Manager",
  "Author": "Utimaco - support@utimaco.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/UtimacoLogoSVG.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The [Utimaco ESKM](https://utimaco.com/key-management/enterprise-secure-key-manager) solution ingests KMIP server logs from Utimaco Enterprise Secure Key Manager (ESKM) into Microsoft Sentinel using the Codeless Connector Platform (CCP). It enables monitoring of key management operations, authentication events, and KMIP client activity, helping you detect misuse, configuration issues, and unauthorized access to cryptographic material. \r \n \r \n **Underlying Microsoft Technologies used:** \r \n \r \n a. [Microsoft Sentinel Codeless Connector Platform (CCP)](https://learn.microsoft.com/azure/sentinel/create-codeless-connector) \r \n \r \n b. [Azure Monitor Data Collection Rules and Endpoints](https://learn.microsoft.com/azure/azure-monitor/essentials/data-collection-rule-overview)",
  "Data Connectors": [
    "Data Connectors/sentinel-connectors/UtimacoESKM_CCF/UtimacoESKM_ConnectorDefinition.json"
  ],
  "Workbooks": [
    "Workbooks/ESKMworkbook.json"
  ],
  "Parsers": [],
  "Hunting Queries": [
    "Hunting Queries/UtimacoESKM_RareKmipUsers.yaml",
    "Hunting Queries/UtimacoESKM_NewSourceIPs.yaml",
    "Hunting Queries/UtimacoESKM_HighVolumeKeyRetrieval.yaml",
    "Hunting Queries/UtimacoESKM_AfterHoursActivity.yaml"
  ],
  "Analytic Rules": [
    "Analytic Rules/UtimacoESKM_AuthFailureBruteForce.yaml",
    "Analytic Rules/UtimacoESKM_PermissionDeniedBurst.yaml",
    "Analytic Rules/UtimacoESKM_DestroyBurst.yaml"
  ],
  "Playbooks": [],
  "BasePath": "Solutions/Utimaco Enterprise Secure Key Manager",
  "Version": "3.0.0",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": false,
  "Is1PConnector": false
}
