{
  "Name": "Intel471",
  "Author": "Intel 471 Inc.",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/intel471_logo.svg\" >",
  "Description": "The Intel 471 solution for Microsoft Sentinel ingests malware indicators from Intel 471's Verity 471 or Titan API into the Log Analytics workspace, and provides a curated set of community hunting queries to proactively hunt for threats in Microsoft Sentinel.",
  "PlaybooksBladeDescription": "This solution installs the following Playbook templates. After installing the solution, playbooks can be managed in the Manage solution view. ",
  "HuntingQueryBladeDescription": "This solution installs the following hunting queries. After installing the solution, run these hunting queries to hunt for threats in Manage solution view.",
  "Playbooks": [
    "Solutions/Intel471/Playbooks/Intel471-ImportMalwareIntelligenceToSentinel/azuredeploy.json"
  ],
  "Hunting Queries": [
    "Solutions/Intel471/Hunting Queries/anydesk-execution-from-abnormal-folder-potential-malicious-use-of-rmm-tool.yaml",
    "Solutions/Intel471/Hunting Queries/anydesk-service-installation-potentially-malicious-rmm-tool-installation.yaml",
    "Solutions/Intel471/Hunting Queries/autorun-or-asep-registry-key-modification.yaml",
    "Solutions/Intel471/Hunting Queries/aws-identity-and-access-management-iam-discovery.yaml",
    "Solutions/Intel471/Hunting Queries/browser-spawning-suspicious-applications-potential-exploit-or-social-engineering.yaml",
    "Solutions/Intel471/Hunting Queries/creating-a-shadow-copy.yaml",
    "Solutions/Intel471/Hunting Queries/dump-lsass-via-renamed-procdump.yaml",
    "Solutions/Intel471/Hunting Queries/execution-bat-script-to-unpack-payload.yaml",
    "Solutions/Intel471/Hunting Queries/file-created-in-startup-folder.yaml",
    "Solutions/Intel471/Hunting Queries/java-spawning-child-process-by-unique-child-process-name-potential-exploitation-activity.yaml",
    "Solutions/Intel471/Hunting Queries/meshagent-suspicious-child-process-potential-malicious-rmm-tool-usage.yaml",
    "Solutions/Intel471/Hunting Queries/methods-for-downloading-files-with-powershell.yaml",
    "Solutions/Intel471/Hunting Queries/netsupport-manager-execution-from-abnormal-folder-potential-malicious-use-of-rmm-tool.yaml",
    "Solutions/Intel471/Hunting Queries/potential-maldoc-execution-chain-observed.yaml",
    "Solutions/Intel471/Hunting Queries/powershell-encoded-command-execution.yaml",
    "Solutions/Intel471/Hunting Queries/powershell-history-modification-or-deletion.yaml",
    "Solutions/Intel471/Hunting Queries/python-executing-from-non-standard-directory.yaml",
    "Solutions/Intel471/Hunting Queries/remote-atera-agent-download-command-line.yaml",
    "Solutions/Intel471/Hunting Queries/scheduled-task-executing-from-abnormal-location.yaml",
    "Solutions/Intel471/Hunting Queries/shadow-copies-deletion-using-operating-systems-utilities.yaml",
    "Solutions/Intel471/Hunting Queries/suspect-child-process-to-iis-worker-process-w3wp-exe-potential-exploitation.yaml",
    "Solutions/Intel471/Hunting Queries/suspicious-child-process-for-java-potential-exploitation-activity.yaml",
    "Solutions/Intel471/Hunting Queries/user-added-to-default-privileged-windows-security-groups.yaml",
    "Solutions/Intel471/Hunting Queries/wevtutil-cleared-log.yaml",
    "Solutions/Intel471/Hunting Queries/wmic-windows-internal-discovery-and-enumeration.yaml"
  ],
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Intel471",
  "Version": "3.0.1",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": true,
  "Is1PConnector": false
}
