{
  "Name": "Dynatrace",
  "Author": "Dynatrace - microsoftalliances@dynatrace.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/dynatrace.svg\" width=\"75px\" height=\"75px\">",
  "Description": "Dynatrace is a leading observability platform that provides automatic and intelligent observability at scale for cloud-native and enterprise workloads; with Dynatrace Application Security, your DevSecOps teams can resolve security issues faster, accelerating software delivery.\r\nIntegrating Dynatrace with Microsoft Sentinel enables DevSecOps teams to detect, prioritize, triage, and remediate attacks rapidly. DevSecOps teams benefit from the high-accuracy threat signals Dynatrace surfaces. It helps them avoid time-consuming investigation activities, freeing them up for more critical tasks.\r\nMicrosoft Sentinel data connectors poll Dynatrace for new [attacks, vulnerabilities, audit logs](https://www.dynatrace.com/platform/application-security/), and [problem events](https://docs.dynatrace.com/docs/shortlink/davis-ai-landing).\r\n\r\n**Included data connectors:**\r\n- **Attacks**, Common attacks on application layer vulnerabilities which can be detected and blocked using Dynatrace, like SQL injection, command injection, and JNDI attacks.\r\n- **Runtime vulnerabilities**, Software vulnerabilities detected throughout all layers of the application stack.\r\n- **Audit logs**, Security-relevant events for a Dynatrace tenant.\r\n- **Problems**, AI-powered observability problems raised across cloud and hybrid environments.\r\n\r\n[Learn More about Dynatrace](https://www.dynatrace.com/) | [Dynatrace Docs](https://docs.dynatrace.com/docs)\r\n\r\n**Underlying Microsoft Technologies used:**\r\n\r\nThis solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs:\r\n\r\na. [Microsoft Sentinel](https://learn.microsoft.com/azure/sentinel/overview)\r\n\r\nb. [Azure Logic Apps](https://learn.microsoft.com/azure/logic-apps/logic-apps-overview)",
  "WorkbookBladeDescription": "This solution installs workbooks. Workbooks provide a flexible canvas for data monitoring, analysis, and the creation of rich visual reports within the Azure portal. They allow you to tap into one or many data sources from Microsoft Sentinel and combine them into unified interactive experiences.",
  "AnalyticalRuleBladeDescription": "This solution installs the following analytic rule templates. After installing the solution, create and enable analytic rules in Manage solution view. ",
  "PlaybooksBladeDescription": "This solution installs the following Playbook templates. After installing the solution, playbooks can be managed in the Manage solution view. ",
  "HuntingQueryBladeDescription": "",
  "Workbooks": [
    "Workbooks/Dynatrace.json"
  ],
  "Analytic Rules": [
    "Analytic Rules/DynatraceApplicationSecurity_AttackDetection.yaml",
    "Analytic Rules/DynatraceApplicationSecurity_CodeLevelVulnerabilityDetection.yaml",
    "Analytic Rules/DynatraceApplicationSecurity_ThirdPartyVulnerabilityDetection.yaml",
    "Analytic Rules/DynatraceApplicationSecurity_NonCriticalVulnerabilityDetection.yaml",
    "Analytic Rules/Dynatrace_ProblemDetection.yaml"
  ],
  "Playbooks": [
    "Playbooks/Add_DynatraceApplicationSecurityAttackSourceIpThreatIntelligence/azuredeploy.json",
    "Playbooks/Add_DynatraceApplicationSecurityAttackSourceIpSTIXThreatIntelligence/azuredeploy.json",
    "Playbooks/Enrich_DynatraceApplicationSecurityAttackIncident/azuredeploy.json",
    "Playbooks/Enrich-DynatraceAppSecAttackMSDefenderXDR/azuredeploy.json",
    "Playbooks/Enrich-DynatraceAppSecAttackWithSecurityAlerts/azuredeploy.json",
    "Playbooks/Ingest-DynatraceMSDefenderXDR/azuredeploy.json",
    "Playbooks/Ingest-DynatraceMSSentinelSecurityAlerts/azuredeploy.json"
  ],
  "Data Connectors": [
    "Data Connectors/DynatraceAttacksV1/Connector_Dynatrace_Attacks.json",
    "Data Connectors/DynatraceAttacksV2/Connector_Dynatrace_Attacks_Definition.json",
    "Data Connectors/DynatraceAuditLogsV1/Connector_Dynatrace_AuditLogs.json",
    "Data Connectors/DynatraceAuditLogsV2/Connector_Dynatrace_AuditLogs_Definition.json",
    "Data Connectors/DynatraceProblemsV1/Connector_Dynatrace_Problems.json",
    "Data Connectors/DynatraceProblemsV2/Connector_Dynatrace_Problems_Definition.json",
    "Data Connectors/DynatraceRuntimeVulnerabilitiesV1/Connector_Dynatrace_RuntimeVulnerabilities.json",
    "Data Connectors/DynatraceRuntimeVulnerabilitiesV2/Connector_Dynatrace_RuntimeVulnerabilities_Definition.json",
    "Data Connectors/DynatraceRuntimeVulnerabilitiesV3/Connector_Dynatrace_RuntimeVulnerabilities_Definition.json",
    "Data Connectors/DynatraceAttacksV3/Connector_Dynatrace_Attacks_Definition.json",
    "Data Connectors/DynatraceAuditLogsV3/Connector_Dynatrace_AuditLogs_Definition.json",
    "Data Connectors/DynatraceProblemsV3/Connector_Dynatrace_Problems_Definition.json"
  ],
  "Parsers": [
    "Parsers/DynatraceAttacks.yaml",
    "Parsers/DynatraceAuditLogs.yaml",
    "Parsers/DynatraceProblems.yaml",
    "Parsers/DynatraceSecurityProblems.yaml"
  ],
  "Summary Rules": [
    "Summary Rules/Consolidate_DynatraceRuntimeVulnerabilities.yaml"
  ],
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Dynatrace",
  "Version": "3.0.4",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": false,
  "Is1PConnector": false
}