|
6 | 6 | "config": { |
7 | 7 | "isWizard": false, |
8 | 8 | "basics": { |
9 | | - "description": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Samsung_Knox_Asset_Intelligence.svg\" width=\"75px\" height=\"75px\">\n\n**Note:** Please refer to the following before installing the solution: \n\n• Review the solution [Release Notes](https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/Samsung%20Knox%20Asset%20Intelligence/ReleaseNotes.md)\n\n • There may be [known issues](https://aka.ms/sentinelsolutionsknownissues) pertaining to this Solution, please refer to them before installing.\n\nThe Knox Asset Intelligence for Microsoft Sentinel solution enables enterprise IT and SecOps (Security Operations) administrators to view and manage security threats to their Samsung Knox mobile devices. By integrating security events and logs from Knox Asset Intelligence with the Azure Monitor Log Ingestion API, the solution lets enterprise organizations easily view, identify and investigate security threats in near-real-time with Microsoft Sentinel.\n\n**Data Connectors:** 1, **Workbooks:** 1, **Analytic Rules:** 8\n\n[Learn more about Microsoft Sentinel](https://aka.ms/azuresentinel) | [Learn more about Solutions](https://aka.ms/azuresentinelsolutionsdoc)", |
| 9 | + "description": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Samsung_Knox_Asset_Intelligence.svg\" width=\"75px\" height=\"75px\">\n\n**Note:** Please refer to the following before installing the solution: \n\n• Review the solution [Release Notes](https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/Samsung%20Knox%20Asset%20Intelligence/ReleaseNotes.md)\n\n • There may be [known issues](https://aka.ms/sentinelsolutionsknownissues) pertaining to this Solution, please refer to them before installing.\n\nThe Knox Asset Intelligence for Microsoft Sentinel solution enables enterprise IT and SecOps (Security Operations) administrators to view and manage security threats to their Samsung Knox mobile devices. By integrating security events and logs from Knox Asset Intelligence with the Azure Monitor Log Ingestion API, the solution lets enterprise organizations easily view, identify and investigate security threats in near-real-time with Microsoft Sentinel.\n\n**Data Connectors:** 1, **Workbooks:** 1, **Analytic Rules:** 7\n\n[Learn more about Microsoft Sentinel](https://aka.ms/azuresentinel) | [Learn more about Solutions](https://aka.ms/azuresentinelsolutionsdoc)", |
10 | 10 | "subscription": { |
11 | 11 | "resourceProviders": [ |
12 | 12 | "Microsoft.OperationsManagement/solutions", |
|
160 | 160 | { |
161 | 161 | "name": "analytic2", |
162 | 162 | "type": "Microsoft.Common.Section", |
163 | | - "label": "Samsung Knox - Keyguard Disabled Feature Set Events", |
164 | | - "elements": [ |
165 | | - { |
166 | | - "name": "analytic2-text", |
167 | | - "type": "Microsoft.Common.TextBlock", |
168 | | - "options": { |
169 | | - "text": "When an admin has set disabled keyguard features on a Knox device." |
170 | | - } |
171 | | - } |
172 | | - ] |
173 | | - }, |
174 | | - { |
175 | | - "name": "analytic3", |
176 | | - "type": "Microsoft.Common.Section", |
177 | 163 | "label": "Samsung Knox - Mobile Device Boot Compromise Events", |
178 | 164 | "elements": [ |
179 | 165 | { |
180 | | - "name": "analytic3-text", |
| 166 | + "name": "analytic2-text", |
181 | 167 | "type": "Microsoft.Common.TextBlock", |
182 | 168 | "options": { |
183 | 169 | "text": "When a Knox device boot binary is at risk of compromise." |
|
186 | 172 | ] |
187 | 173 | }, |
188 | 174 | { |
189 | | - "name": "analytic4", |
| 175 | + "name": "analytic3", |
190 | 176 | "type": "Microsoft.Common.Section", |
191 | 177 | "label": "Samsung Knox - Password Lockout Events", |
192 | 178 | "elements": [ |
193 | 179 | { |
194 | | - "name": "analytic4-text", |
| 180 | + "name": "analytic3-text", |
195 | 181 | "type": "Microsoft.Common.TextBlock", |
196 | 182 | "options": { |
197 | 183 | "text": "When maximum password attempts have been reached, and the Knox device is locked out. This is based on a threshold set in the MDM device policy" |
|
200 | 186 | ] |
201 | 187 | }, |
202 | 188 | { |
203 | | - "name": "analytic5", |
| 189 | + "name": "analytic4", |
204 | 190 | "type": "Microsoft.Common.Section", |
205 | 191 | "label": "Samsung Knox - Peripheral Access Detection with Camera Events", |
206 | 192 | "elements": [ |
207 | 193 | { |
208 | | - "name": "analytic5-text", |
| 194 | + "name": "analytic4-text", |
209 | 195 | "type": "Microsoft.Common.TextBlock", |
210 | 196 | "options": { |
211 | 197 | "text": "When camera access has been detected on a Knox device, even though such access is disabled through an MDM device policy." |
|
214 | 200 | ] |
215 | 201 | }, |
216 | 202 | { |
217 | | - "name": "analytic6", |
| 203 | + "name": "analytic5", |
218 | 204 | "type": "Microsoft.Common.Section", |
219 | 205 | "label": "Samsung Knox - Peripheral Access Detection with Mic Events", |
220 | 206 | "elements": [ |
221 | 207 | { |
222 | | - "name": "analytic6-text", |
| 208 | + "name": "analytic5-text", |
223 | 209 | "type": "Microsoft.Common.TextBlock", |
224 | 210 | "options": { |
225 | 211 | "text": "When microphone access has been detected on a Knox device, even though such access is disabled through an MDM device policy." |
|
228 | 214 | ] |
229 | 215 | }, |
230 | 216 | { |
231 | | - "name": "analytic7", |
| 217 | + "name": "analytic6", |
232 | 218 | "type": "Microsoft.Common.Section", |
233 | 219 | "label": "Samsung Knox - Suspicious URL Accessed Events", |
234 | 220 | "elements": [ |
235 | 221 | { |
236 | | - "name": "analytic7-text", |
| 222 | + "name": "analytic6-text", |
237 | 223 | "type": "Microsoft.Common.TextBlock", |
238 | 224 | "options": { |
239 | 225 | "text": "When a Knox device user clicks on URLs or links detected as suspicious (potentially phishing or malicious) with a high degree of confidence." |
|
242 | 228 | ] |
243 | 229 | }, |
244 | 230 | { |
245 | | - "name": "analytic8", |
| 231 | + "name": "analytic7", |
246 | 232 | "type": "Microsoft.Common.Section", |
247 | 233 | "label": "Samsung Knox - Security Log Full Events", |
248 | 234 | "elements": [ |
249 | 235 | { |
250 | | - "name": "analytic8-text", |
| 236 | + "name": "analytic7-text", |
251 | 237 | "type": "Microsoft.Common.TextBlock", |
252 | 238 | "options": { |
253 | 239 | "text": "When the Knox Security Log is full on a device." |
|
0 commit comments