{
  "Name": "ZeroFox",
  "Author": "ZeroFox - integration-support@zerofox.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/foxy-mark.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The [ZeroFox](https://www.zerofox.com/) solution for Microsoft Sentinel enables you to ingest [ZeroFox Alerts](https://www.zerofox.com/platform/) and [ZeroFox CTI events](https://www.zerofox.com/threat-intelligence/) into Microsoft Sentinel using the ZeroFox API. \n\n**Underlying Microsoft Technologies used:**\n\nThis solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs:\n\na. [Azure Monitor HTTP Data Collector API](https://docs.microsoft.com/azure/azure-monitor/logs/data-collector-api)\n\nb. [Azure Functions](https://azure.microsoft.com/services/functions/#overview)",
  "Data Connectors": [
    "Data Connectors/CTI/ZeroFoxCTI.json",
    "Data Connectors/Alerts/ZeroFoxAlerts_ConnectorDefinition.json"
  ],
  "Analytic Rules": [
    "Analytic Rules/ZF_Alerts_HighSeverityRule.yaml",
    "Analytic Rules/ZF_Alerts_InformationalSeverityRule.yaml",
    "Analytic Rules/ZF_Alerts_LowSeverityRule.yaml",
    "Analytic Rules/ZF_Alerts_MediumSeverityRule.yaml"
  ],
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\ZeroFox",
  "Version": "3.2.2",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": true,
  "Is1Pconnector": false
}
