{
  "Name": "Infoblox",
  "Author": "Infoblox",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/infoblox_logo.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The Infoblox Solution for Microsoft Sentinel is designed to enhance the capabilities of Security Operations Centers (SOC) by integrating actionable intelligence and contextual network data derived from DNS data into Microsoft Sentinel. This integration provides SOC analysts with the tools they need to quickly identify and respond to potential threats such as malware and data exfiltration, improving overall security posture. With seamless configuration and intuitive dashboards, the solution ensures that critical security events are monitored and correlated, offering actionable insights that streamline threat detection and response. \nSOC analysts will benefit from the app’s ability to provide contextual network data, including user and device attribution, through various lookups and visualizations. By leveraging unique DNS-based threat intelligence, audit logs and other data sources, analysts can conduct faster and more effective investigations. The solution’s functionalities, such as IQ for TD Insights Overview and DNS Events, empower analysts to reduce alert fatigue by focusing on correlated events, ultimately leading to improved efficiency and protection against emerging threats.\n\n**Benefits**\n1. **Reduce alert fatigue with actionable insights through IQ for TD Insights**: Focus on the most critical alerts and insights to streamline threat detection and response. \n2. **Faster investigations with contextual network data**: Quickly correlate network activities with potential threats using detailed lookups and visualizations. \n3. **Unique DNS-based Infoblox Threat Intel**: Access unparalleled DNS-based threat intelligence to enhance security decision-making and threat mitigation. ",
  "Data Connectors": [
    "Data Connectors/InfobloxCloudDataConnector/Infoblox_API_FunctionApp.json",
    "Data Connectors/InfobloxSOCInsights/InfobloxSOCInsightsDataConnector_AMA.json",
    "Data Connectors/InfobloxSOCInsights/InfobloxSOCInsightsDataConnector_API.json",
    "Data Connectors/InfobloxCEFDataConnector/template_InfobloxCloudDataConnectorAma.json"
  ],
  "Workbooks": [
    "Workbooks/Infoblox_Lookup_Workbook.json",
    "Workbooks/Infoblox_Workbook.json"
  ],
  "Analytic Rules": [
    "Analytic Rules/Infoblox-SOCInsight-Detected-APISource.yaml",
    "Analytic Rules/Infoblox-SOCInsight-Detected-CDCSource.yaml"
  ],
  "Parsers": [
    "Parsers/InfobloxCDC_SOCInsights.yaml",
    "Parsers/InfobloxInsight.yaml",
    "Parsers/InfobloxInsightAssets.yaml",
    "Parsers/InfobloxInsightEvents.yaml",
    "Parsers/InfobloxInsightIndicators.yaml"
  ],
  "Playbooks": [
    "Playbooks/Infoblox Block Allow IP Domain/azuredeploy.json",
    "Playbooks/Infoblox Block Allow IP Domain Incident Based/azuredeploy.json",
    "Playbooks/InfoBlox Config Insight Details/azuredeploy.json",
    "Playbooks/Infoblox Config Insights/azuredeploy.json",
    "Playbooks/Infoblox Data Connector Trigger Sync/azuredeploy.json",
    "Playbooks/Infoblox DHCP Lookup/azuredeploy.json",
    "Playbooks/Infoblox Get IP Space Data/azuredeploy.json",
    "Playbooks/Infoblox Get Service Name/azuredeploy.json",
    "Playbooks/Infoblox IPAM Lookup/azuredeploy.json",
    "Playbooks/Infoblox IQ for TD Take Action API/azuredeploy.json",
    "Playbooks/Infoblox SOC Get Insight Details/azuredeploy.json",
    "Playbooks/Infoblox SOC Get Open Insights API/azuredeploy.json",
    "Playbooks/Infoblox SOC Import Indicators TI/azuredeploy.json",
    "Playbooks/Infoblox TIDE Lookup/azuredeploy.json",
    "Playbooks/Infoblox TIDE Lookup Incident Based/azuredeploy.json",
    "Playbooks/Infoblox TIDE Lookup Incident Comment Based/azuredeploy.json",
    "Playbooks/Infoblox TimeRangeBased DHCP Lookup/azuredeploy.json",
    "Playbooks/Infoblox Get Host Name/azuredeploy.json"
  ],
  "BasePath": "C:\\Azure-Sentinel\\Solutions\\Infoblox",
  "Version": "3.1.2",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": true,
  "Is1PConnector": false
}
