{
    "Name": "Samsung Knox Asset Intelligence",
    "Author": "Samsung - kai.sme@samsung.com",
    "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Samsung_Knox_Asset_Intelligence.svg\" width=\"75px\" height=\"75px\">",
    "Description": "The Knox Asset Intelligence for Microsoft Sentinel solution enables enterprise IT and SecOps (Security Operations) administrators to view and manage security threats to their Samsung Knox mobile devices. By integrating security events and logs from Knox Asset Intelligence with the Azure Monitor Log Ingestion API, the solution lets enterprise organizations easily view, identify and investigate security threats in near-real-time with Microsoft Sentinel.",
    "Data Connectors": [
      "Data Connectors/Template_Samsung.json"
    ],
    "Workbooks": ["Solutions/Samsung Knox Asset Intelligence/Workbooks/SamsungKnoxAssetIntelligence.json"],
    "WorkbookBladeDescription":"This Knox Asset Intelligence for Microsoft Sentinel solution installs a workbook that summarizes the mobile security events reported by Samsung Knox devices over a selected reporting period. You can use this workbook to quickly assess the threat type and severity, or identify patterns and anomalies in order to help prioritize incident responses or further investigations.",
    "AnalyticalRuleBladeDescription": "This solution comes with the following analytic rule templates, based on critical mobile security event data captured from Samsung Knox devices. You can also customize these analytic rule templates based on your organization’s needs.",
    "Analytic Rules": [
      "Solutions/Samsung Knox Asset Intelligence/Analytic Rules/SamsungKnoxApplicationPrivilegeEscalationOrChange.yaml",
      "Solutions/Samsung Knox Asset Intelligence/Analytic Rules/SamsungKnoxMobileDeviceBootCompromise.yaml",
      "Solutions/Samsung Knox Asset Intelligence/Analytic Rules/SamsungKnoxPasswordLockout.yaml",
      "Solutions/Samsung Knox Asset Intelligence/Analytic Rules/SamsungKnoxPeripheralAccessDetectionWithCamera.yaml",
      "Solutions/Samsung Knox Asset Intelligence/Analytic Rules/SamsungKnoxPeripheralAccessDetectionWithMic.yaml",
      "Solutions/Samsung Knox Asset Intelligence/Analytic Rules/SamsungKnoxSuspiciousURLs.yaml",
      "Solutions/Samsung Knox Asset Intelligence/Analytic Rules/SamsungKnoxSecurityLogFull.yaml"
    ],
    "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Samsung Knox Asset Intelligence",
    "Version": "3.0.3",
    "Metadata": "SolutionMetadata.json",
    "TemplateSpec": true, 
    "Is1PConnector": false
  }