{
	"Name": "Acronis Cyber Protect Cloud",
	"Author": "Acronis - support@acronis.com",
	"Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Acronis.svg\" width=\"75px\" height=\"75px\">",
	"Description": "The Acronis Cyber Protect Cloud solution for Microsoft Sentinel enables companies to ingest Acronis alerts, events, and activities into Microsoft Sentinel. The data is initially stored on a device on the company network using the Acronis agent as a writer. [See Acronis SIEM Connector documentation here](https://www.acronis.com/en-us/support/documentation/CyberProtectionService/index.html#siem-plans.html) The integration includes custom Acronis detection rules and hunting queries to help companies proactively hunt for threats.",
	"Data Connectors": [],
	"Workbooks": [],
	"Analytic Rules": [
		"Analytic Rules/AcronisLoginFromAbnormalIPLowOccurrence.yaml",
		"Analytic Rules/AcronisMultipleEndpointsAccessingMaliciousURLs.yaml",
		"Analytic Rules/AcronisMultipleEndpointsInfectedByRansomware.yaml",
		"Analytic Rules/AcronisMultipleInboxesWithMaliciousContentDetected.yaml"
	],
	"Hunting Queries": [
		"Hunting queries/AcronisAgentFailedUpdatingMoreThanTwiceInADay.yaml",
		"Hunting queries/AcronisAgentsOfflineFor2DaysOrMore.yaml",
		"Hunting queries/AcronisAuditLog.yaml",
		"Hunting queries/AcronisCloudConnectionErrors.yaml",
		"Hunting queries/AcronisEndpointsAccessingMaliciousURLs.yaml",
		"Hunting queries/AcronisEndpointsInfectedByRansomware.yaml",
		"Hunting queries/AcronisEndpointsWithBackupIssues.yaml",
		"Hunting queries/AcronisEndpointsWithEDRIncidents.yaml",
		"Hunting queries/AcronisEndpointsWithHighFailedLoginAttempts.yaml",
		"Hunting queries/AcronisInboxesWithMaliciousContentDetected.yaml",
		"Hunting queries/AcronisLoginFromAbnormalIPLowOccurrence.yaml",
		"Hunting queries/AcronisProtectionServiceErrors.yaml",
		"Hunting queries/AcronisUnauthorizedOperationIsDetected.yaml"
	],
	"BasePath": "C:\\Users\\Sergey.Bolzhatov\\acronis\\Azure-Sentinel\\Acronis Cyber Protect Cloud",
	"Version": "3.0.0",
	"Metadata": "SolutionMetadata.json",
	"TemplateSpec": true
}
