{
  "Name": "GoogleWorkspaceReports",
  "Author": "Microsoft - support@microsoft.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/google-workspace-logo.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The [Google Workspace](https://workspace.google.com/) solution for Microsoft Sentinel enables you to ingest Google Workspace Activity events into Microsoft Sentinel. \n \n **Underlying Microsoft Technologies used:**\n\n This solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs: \n \n • [Microsoft Sentinel Codeless Connector Framework](https://aka.ms/Sentinel-CCP_Platform)\n\n",
  "Workbooks": [
    "Workbooks/GoogleWorkspace.json"
  ],
  "Parsers": [
    "Parsers/GWorkspaceActivityReports.yaml"
  ],
  "Analytic Rules": [
    "Analytic Rules/GWorkspaceAdminPermissionsGranted.yaml",
    "Analytic Rules/GWorkspaceAlertEvents.yaml",
    "Analytic Rules/GWorkspaceApiAccessToNewClient.yaml",
    "Analytic Rules/GWorkspaceChangedUserAccess.yaml",
    "Analytic Rules/GWorkspaceDifferentUAsFromSingleIP.yaml",
    "Analytic Rules/GWorkspaceOutboundRelayAddedToSuiteDomain.yaml",
    "Analytic Rules/GWorkspacePossibleBruteForce.yaml",
    "Analytic Rules/GWorkspacePossibleMaldocFileNamesInGDRIVE.yaml",
    "Analytic Rules/GWorkspaceTwoStepAuthenticationDisabledForUser.yaml",
    "Analytic Rules/GWorkspaceUnexpectedOSUpdate.yaml"
  ],
  "Data Connectors": [
    "Data Connectors/GoogleWorkspaceTemplate_ccp/GoogleWorkspaceReports_DataConnectorDefinition.json"
  ],
  "Hunting Queries": [
    "Hunting Queries/GWorkspaceDocumentSharedExternally.yaml",
    "Hunting Queries/GWorkspaceDocumentSharedPublicily.yaml",
    "Hunting Queries/GWorkspaceDocumentSharedPublicilyWithLink.yaml",
    "Hunting Queries/GWorkspaceMultiIPAddresses.yaml",
    "Hunting Queries/GWorkspacePossibleSCAMSPAMorPhishingCalendar.yaml",
    "Hunting Queries/GWorkspaceRareDocType.yaml",
    "Hunting Queries/GWorkspaceSharedPrivateDocument.yaml",
    "Hunting Queries/GWorkspaceSuspendedUsers.yaml",
    "Hunting Queries/GWorkspaceUncommonUAsString.yaml",
    "Hunting Queries/GWorkspaceUnknownLoginType.yaml",
    "Hunting Queries/GWorkspaceUserReportedCalendarInviteAsSpam.yaml",
    "Hunting Queries/GWorkspaceUserWithSeveralDevices.yaml"
  ],
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\GoogleWorkspaceReports",
  "Version": "3.1.0",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": true,
  "Is1Pconnector": false,
  "createPackage": false
}
