<0NcIo|}^t$(DcTR6U!ZES^sqv>|XntTPl6tpzO8!Bo8EW;9n#zgR|0tQ50tBHq^
zE^+%=gueP#?8v|-?m@A^e)A-CbSKVxjrG>=BJ=TspC5=%sK$hojY5s&e6NH#eN1gx
zoY150BAu01C^yx5vAnKgUZqD~zcDcARKB%_sbi&y;|nuQh1Y6yQP*PLm%l0TMj7T8bh-rt5>1hHR0t%PmUs7`{+ywTV7iU1g
zE451mVA2e@U{$TZ07)kZYiGoEg{gOh%{B5dVz8Z;>^JkGBzRITw=GP1Eqo39tLaE~
zZ}+zpf#ZQ{S)n{bxj@R*FsvQ9GB56CWF)6A(MUR8N~vz7ST|TtS!kZOpBt+)Q1VkC
z8YLz0a+u71%5h_i==M>^1voi8?^I$dSwT0@Dp+g51V9SuMwDqvH0s9Lt{*
zhFWH{hh!%jdizw`Q#Kzmo6`R@6$U1v;T{d+BeBV)+RR~wC~Gg(&VbTpdx
z*2WfdidNXVinx@WP5{nydJk}-Mw5y!YYlu~kurOvdiIL=32h)O9)sBzoroD7ZRVnM
zvaSrAQ~G8ggG!p9Tzi(XI5f#=UK)JN>`%b#T&Vx%fIw8znm3U%c-Aq>6gJscIo}Sj
z>k@W4^cA^*$r6k*L#--TTp$UTQo8;$+y3Sh>Beh8X2p$h2VkSQOwxV9BT^7*DY>GN
zwp=f4oh(w%eIcp5yG3X~EN@C7MA@i5;kriqSlhx}+w;J7M?ibMuj+&{g%#@y0ZDT5
z$41xf!9J^KcgLEBf*LZi*72=hEW2wb4%2
zERshAj@09!5pBCB}sE3QRdcmZfW>a&4%;SGYqgzF5D)OR2y
z^f;x#c^P^6E@&25hCGzH3fOqV03;z2%!7_Shhcu~GJat?-gM&iVZA-EadIE@n3T25x8bcXB64HyOv~W8>9-c-
zciYK?agy^nNRGThIa^+)GAioq$>FS`1FUA
zkt?gWY1{A4+NRCaP|25Fnnqb5UY>y5KH1x8ugp`^^hpmk{-ncCfu&fvLa4Fn!j3K^
zsEaj}zpkgrTi;scF2`G?J(HSYF&3pdoE0AUh}TKJ_}9TXaXBmhGA)_WtB>_+45-z|
z88~(~8PvQ+Q82gzQ^VdmwpO0Y&5m$nt0&8WJFrZay);~dVq$qbR${@R(nUdU=(jSI
zUf=TZLx(UXul8R6Wa|TfQ9S$dPp|=q9bj#)TC3ChFBg;m_`*iElTjTn{e@VBFpA!I
z8|pU@C6fB>4r<{gBO}bi&r6E8Wd3%w6l7VJKSYIWs+02bh08p)izIfO-fll2&Ng^&
z1O5JCB!CA_@8T-mor}L6oX31rK9KeFz}qdo=6-A(ZC6{ncG_s=2(6m^X<3obWKL*J
zTeb9ESz+Fjdi5KTMRiuUFJ=t3_r0>2t9d)KPA=i*0LK;Ie0(hW3(cf$>9e_&!8aYh
zJFJ46ei|)(2M>6B{2ejuR7aTK;RM`nC?wrppS$<_KT@C5-;lq*BM@!~5Yc5{|4))g
z@FPG$_LN2)re~{5H^T~ftNJ6Oqig<&g6x5};X(gWs{G38>guV4s^1Z*zZ02oMApX8
zx-UQWG98mRy$2WUhgFNQ=kL`9k7d7^C=2Qr&;Nz-^dC&3a_LyQBXL^+1fC4fH?MMP
z?CI@&Z$3?_PZ-;9F@3zH{#Ln+Zi%*2!SR*pSGmamoC#%Kd
zw?KIC*LLNrI-$9sVIDR_Tt+l!O364V?RI-?%wOAP?6CdUXWPL%bluKlhZuY~l^q~8
z^JJrb-0$fH^pi%~f#Vk}h_xq=LDOCTWNXmJtgv-^y%XWt2k*ocC9Q6bPmN&Hy_F9jkTqBhh8BEZ*8U2#n(-|2?R5%;#-1qm2cDF4GGMh3g9Yh
zOI|ULUV*m
z=sXF0wg5evJV_Z3E3?OMW6mPi?=BNah1s=bf|w<&Kfww*g>ks%>o?eK|4Z@=>IbbGr(x9lI56G7=Ruf
zkXd=@A3r0y?1vZWBKqS2t!r2PARp4F4#WikY+xUP=dM6&7oj((`}fz^=Z9f*;A=?d
zP1e{F7h3>XsgM_{(7
zjy`|y2FT&+LBp5iZ4JFB#}{?3sz<
zUGh-+gNTHL`~!$yl(gC|avp&gNPDpe$O4z@LY65b;ERBTUv!0gl^OMg28#l<9r3jq
z7dZ>iNI&4fA|^R(>)fv{r#JsXWM9C`KpdjiOH?xDfuh&f`spdg#cFuqV!7fKdubQT
z$DmPYsE9;`w7KU++(p;`}cp1vM$lU{ud`4
zyA82((wGK7ifQ-+>|T}5IelEq^BG{oJ(6EP(oLJW!KV#c-~Pgqw4&GeayvM9xTD+<
z`SnO~d;llLPDu1U;cW{PZo5thCy7M7C0_ZL#McBzQa5a?VAKmni&tcKXHS3qu{15^t{VdAUIUE+PF
zLAN|z-@KI0Be9m_#u^~1UwSF8!4LN>JU43uw6inb)uS-V#j9~S5j_)r`;3C
zl|$nnFmXTQy!<@v!Gl_&rc_F_%goL1ep!1K8p$)Ec`i9so#bmwgN;q>>>PWr?sUWB
zWyD6HwbqngCG%2KKIQiqB1;T}`%&lKfE?V}u>}`_t8JwNQ$IECECZ@cec;2()
z^cggt$mx&D%2qaZ1rqm^I*rB-=Z^?u_@i_L})9pL>)l%|E19MI51s(42
zX82248h-mZdY7EkV$)lTpz={XgHE~97?;0--}u@KYkK>RKs4hqUBpxhR=r42S@?-Afmdsp00
zpeJ{>;3UxJo(zqR_%&aE4#);*wfe)2B@wdWM;Qd!@=%C4a(l4!giCT;JyZ$0loBilKYBnBT&?WeiK{zcYFz)8$4FlUy%R3PSqe%C-$YyF
z%ZMXPM}5*ImZGlp{%3*#3L9fHU`V|ljKfT9v2C(Z%bu!VAbg+f8=Xn#XwHt0-dLyO
zN*KT2B;@>q8PE1x@Bac8I`Eb574)0Qz`#~_d;;FLf_bwepiURNz;4LYPukLqEYcB^
zr~sV@pl;-iT)))J`dh9FC;A6$C1DT*oNwW&oJN{U)OPW)`3%8P4_wy;EK$V!@sLZq
zmZZvvc;)FB8xAouLQ_aB{aLMifz!0HLjs>4Ej&`g?#F9{f(UMh5>;I#j9=h#?;
zup%87WTD#mKVi_WOyA(9?W(OUND$!*(O^VLHng(()%1&f1Rg`(39bp9Pq#y($2PJL
zs7_g`4?i;2WDPIuo>GSjsuTei9JDs%;gx1+@HBinh{(!lE@dC^brZpx_A>-yv8pRc
zH_pS1X68jT*cPP|n-E`7@2U9yr;r>N8XDHeWba~JJ{4WQ#G#7rUK@<&a6Up(L1d_V
zCCAZ5v0kiy+ER)Y>Wf~j++DsfFBiOiH!7wzK_>blVFe58YnL;m3{P|F+uUm-&f84&xSha
z&DIPW6IPAUn6v+V)PD~U)k*&?3;N#qZ(lLu(tpc>ail;I_J1$j4lS&BPWs+lfAP|)
QW$@?xS;aGPr>@=oACeSgd;kCd
literal 0
HcmV?d00001
diff --git a/Solutions/Torq/Playbooks/Torq-Sentinel-Incident-Trigger/readme.md b/Solutions/Torq/Playbooks/Torq-Sentinel-Incident-Trigger/readme.md
new file mode 100644
index 00000000000..955b4b98091
--- /dev/null
+++ b/Solutions/Torq/Playbooks/Torq-Sentinel-Incident-Trigger/readme.md
@@ -0,0 +1,43 @@
+# Torq-Sentinel-Incident-Trigger
+
+## Summary
+
+When a new Sentinel Incident is created or updated, this playbook gets triggered and sends a notification (HTTPS POST Request) to a Microsoft Sentinel Webhook in Torq
+
+
+
+### Prerequisites
+
+1. Prior to the deployment of this playbook, create a new Microsoft Sentinel Trigger integration in Torq.
+2. Take note of the endpoint URL, the authentication header name, and the authentication header secret configured in the Microsoft Sentinel Trigger integration.
+
+
+### Deployment instructions
+
+1. To deploy the Playbook, click the Deploy to Azure button. This will launch the ARM Template deployment wizard.
+2. Fill in the required paramteres:
+ * Playbook Name: Enter the playbook name here
+ * Torq_Webhook_Enpoint_URL: Enter the endpoint URL for the Microsoft Sentinel Trigger integration previously created in Torq.
+ * Torq_Webhook_Auth_Header_Name: Enter the authentication header name for the Microsoft Sentinel Trigger integration previously created in Torq.
+ * Torq_Webhook_Auth_Header_Secret: Enter the authentication header secret for the Microsoft Sentinel Trigger integration previously created in Torq.
+
+[![Deploy to Azure](https://aka.ms/deploytoazurebutton)](https://portal.azure.com/#create/Microsoft.Template/uri/https%3A%2F%2Fraw.githubusercontent.com%2FAzure%2FAzure-Sentinel%2Fmaster%2FSolutions%2FTorq%2FPlaybooks%2FPlaybooks%2FTorq-Sentinel-Incident-Trigger%2Fazuredeploy.json) [![Deploy to Azure](https://aka.ms/deploytoazuregovbutton)](https://portal.azure.us/#create/Microsoft.Template/uri/https%3A%2F%2Fraw.githubusercontent.com%2FAzure%2FAzure-Sentinel%2Fmaster%2FSolutions%2FTorq%2FPlaybooks%2FPlaybooks%2FTorq-Sentinel-Incident-Trigger%2Fazuredeploy.json)
+
+### Post-Deployment instructions
+
+1. Browse to your Microsoft Sentinel workspace > Configuration > Automation
+2. Click "+ Create" and select "Automation rule" to create a new automation rule meant to send a notification to Torq when a new Sentinel Incident is **created**.
+3. Give the automation rule a meaningful name, like "Notify Torq when new Sentinel Incident is created".
+4. From the "Trigger" drop-down menu, select **"When incident is created"**.
+5. Leve "Conditions" to its default values.
+6. From the "Actions" drop-down menu, select "Run playbook".
+7. From the playbook selection drop-down, select the playbook "Sentinel_Incident_Sync_to_Torq"
+8. Click the "Apply" button.
+9. Click "+ Create" again and select "Automation rule" to create a new automation rule meant to send a notification to Torq when an existing Sentinel Incident is **updated**.
+10. Give the automation rule a meaningful name, like "Notify Torq when a Sentinel Incident is updated".
+11. From the "Trigger" drop-down menu, select **"When incident is updated"**
+12. Leve "Conditions" to its default values.
+13. From the "Actions" drop-down menu, select "Run playbook".
+14. From the playbook selection drop-down, select the playbook "Sentinel_Incident_Sync_to_Torq"
+15. Click the "Apply" button.
+
diff --git a/Solutions/Torq/Playbooks/logo.png b/Solutions/Torq/Playbooks/logo.png
new file mode 100644
index 0000000000000000000000000000000000000000..cc5d3be7328bb4453610b79ee2aafc62e53e59ee
GIT binary patch
literal 3449
zcmZ{ncQhQ%7RQ$;OC(x^MB7!f5)!?)Rf6a&(M4Y+646;*bXG}p!f%yW-69B^qC{tf
z6L4}}cd{?^VcbYIk{RH;fk21;
z$uN4+bMfJwJcZ*Fd35&rdLY_0Fc3U3IG5h06^3Y002td0hs)MbQqF2|6ltbt)xK$0HFYYe`=cWOl_oK`n0g?r95I8
z+up&RxrN1V0qlgI_LLt?+Z>GZj)fzO(I7F8%WV(xl9hV;uPGi2tvt1>VQ^XN#t@mc
zNxjUf$>QWm3G{-(M3v1PtD+4i)HARH`MK(z7=^TRtIkBnd^`ceJsMo0BBs3IzChw8
z8-60cCpYus^OjWaq;3+ngDS;Oz15DpoU?#lvPo73QOT{jR>Nzx!ZfS5ln|(b$M6PHWf(}l=q
zfld{23sTqOVL|!n@yx#hx(^GT9m>WMx4bW+Ou%4X6e8socq@|)JzPeHhVxzxNNWir
zFl0GLPr}=@5Zd}w5O9+4Ar)Ma1P+V4_K5jwWQ4oC9?Pl__2KCFtdhD06+GhU+++}H
zw&^-Ec&qf4!uHzx53fB%X?te&th>pFw`NbJJa+8e%~QjiLVM}Khz@$@SB)w=X!B&1
zi`+Ezt;V5ug!X}Ht*7SMDb>dD8l8#A?V*t4MrZNH+HYOiF91UApVregWkVk_%`X`Q
zrBoQHMkBXP4#dX4!C8jfxLLca9{lhvsns9%j?5TBlO!N(8nd^UP6~P8WmW
z44x_+F*0mqTQjF=9ef`rITsLD1aLIjecqw9JpxyP5>;lm`c`~t53@-@DCq}ok!jjT
zJp+n9wboggoFj8&K)5egtL;n5F7Fp#ZQT!5+S^JBxr@^j!jKH3q-H#HMmzBg2E>7Z
z-S0$K?}2628z7V_MqM~**L_>B^rEk{U00O^nxo^Sr&{=Mo|4G$01$pt
zJ96y#@9*W5i@74`$U9+{&nC8;-(-jm1~g?xQ}>s81r83%=b`#(;{c4pa9`)7
zkH{EMv99{0E|%H6WbfASgOSV)M^SE?O+H1)acW*dA$>+IS5{)N&B5P83oX9;1@t)M
zWsf&Go>wLJ7x9ir%BNT|f06psez`8S_4rJEar)Lr>6v-hYBiIzap){hi1dK-{>O;O
z?j+tuGSK(PoE;%f|m|OG>up~g5ES}SS4PCQbTk6Y;*Xm
z6Cu{cdhB`CGOa5`)N69PGbR4x1W@F1I1*~x8nYixj`VW8gH1qPK<2uPQIKUb
zzB$>FO4k1ZA9vpS?g+f&7n19CnqZ-%mXn+{Zfe?QY)^NZy#@tdBIrowUCdFk*sG
zuxE9rGS6ThD8{m9sh^3XrF&24I}vP*hA1bOs@bfq&QkfNdjkqO{hO7zlRK{@Q$xz&
zyVz?d3K8#8K9k~a8KcykkL#vd(fZq&(sms+{(Ux_`3c~i5rkG5gkVoa3}KP_^!k_N
zk8Px)r(1o?I~rK=MzV(5VaI7@$SWV!LUIa0)L3l7Z`3o3_LK}@r}k4V9uteBT2hNa
zm6`mN51?r8`*z~yG8MQ*p3r{%VbN|sO9}`JE~eeySOL#u{MR&W%>YHV(q3{r=89lj
z^mBEMlW^OS%4kzubY`QpVui}oZeCP!1z9y8jU5e{D|6*rO}skURM(~z*pGbs11YHj
z-|D8GxHNWZW;qgVqTvl;-wWReLmsMBn&^3i!_87%GP>^;H!u!fUv}HR0yTGfV{PKn
z>=WC-=;Z)WZ|?QED{?|C9JFg7KtZVbg(6|6h}AfoK~^sy1PCwsdOM4Z
z_kubMS>X?aZ0iS6sucsES{fu8H~v#5>Wu(h!j7bLxTm}C9sJl{>+{?50f28m+@S0^
z+BF448Qb<*YBbJaS6b5obfSf*fpFSN!MVzvjnLP2zdDPZ>PFQ_z+2%gD_s+T1G9Jg
zJKx{z{`xBd={wxmm3x2?Bqk^EwuNhUNdbhKWkkbFEFM87Wfp-@DTA7@XbrnsYfhn$dJTevXrkTH_Gb+AW1&4`%@-5u(iZ#CAF#h{TkT)
zdFl#WR`xkgMB6pjtlXY*r`#$C0ImYrrU;a4*~9*-tEe`NgH>^w+M<^hKooSiJ9%oA
zT0PNIF2%Rm^RT*C^)5=4EtsRkZeOZaYB3Y-28+QNS`A}z6Hb+XLDR8LRry{_bhzIl
zXNC=DOLRK{-+Y#d*Pb?&{4M6tB@RymH4lEtDeBJ|<7It6OYLR|S59F*Us2^sNy5Sn
zZih~tVQzls`IKka=_P?>>|HO0Z+w!&m|o;rOZJQ{AgMHjLrVkvz>ye46Zys&B8{^X0inBBKc>N&Sdg6~v6Cp({!%1xXl
ze#6nNVVL*{T3n=Ma1X}p&YD^%Sdt1y|B|EG7>Q%%wFwq#TQqDW=-zF+oKeS@{h(=V
zY|EG0ML)s#4pTZ!bDenH&1Dk_jXvI4yB6Iq5&6(h?A3gb6JU=4r+1}Ug}d0ZC6cEE
zl(XzGND~$>)_l+A$5+9a;75CuG@2TY%{B#yd)Y;dx)F!=^Oj9aieWTSn2*j?9Y0N&
z#x=tf9bURn^;3xg0)T6jgyT$|{(%?mvueM@Pt{7^YGn=pP|UbTuO>|=I+YjunO6=;!f?1I3DWegn4p{(<>hyjn>l5Hb9}Cg1L`qDOYw-ALO7Pfr5{tKB
z|3YJQTcygyN=@m4YF9yH)>IrV4+HL{pU6~DWIE5%)xixxUBSL-oB2IcP(E@BaZ(#b
z(?ac5v9CzBT6{KcF2qc(^AXxgl{Mw7=o}z>!T1s{6T~TZUnsRWzjXQYO
zK}AAH&ax4E?Z6ZBjRzLPfG$37%>JA+y_@R~vtYmwI($ZgpEaXAeRUZpokL`+p;q%0
z?%OLMl~A_dM;dKE@k@PY-W;Qfgwz!`#bXXQY?GPm=2#SotAT;-ZO8SPC=6>i)A2@e
zdrH=Yu-*ex@lGbF`Qrm|$G`Hs1zwQwqR0-wBvob_Fmm%}35S8*?Uc!
zqt?TB7%#J&=^nXO=_V{k`=`2t#XbhsoU^J7Of2?q&<^_kcH+0~m6bfb+1hXGx96Mo
zehZxr#0DUGO!2Zj=7>F^E5frvw$^GnnJhP2Hgb>z#!5bqH^1ANCU%oa+vaW;PKT+o
zjFi>re%c-$m+Y82UM(9LTw#mhLV-}LwWMv==MK~qxN=+9`BAZbkNECH@G`yuRG$dE
z{NkxiL<%A#{1X8Fsp*LH^EV{?(SNhWKlLA;_}l(}nB&h9e}_RTUNYMP2+Ge}1KG7N
QiQxg7YPzb`P}_)q0mm|KLjV8(
literal 0
HcmV?d00001
diff --git a/Solutions/Torq/ReleaseNotes.md b/Solutions/Torq/ReleaseNotes.md
new file mode 100644
index 00000000000..3ca4764b9eb
--- /dev/null
+++ b/Solutions/Torq/ReleaseNotes.md
@@ -0,0 +1,4 @@
+| **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** |
+|-------------|--------------------------------|--------------------------------------------------------------------|
+| 1.0.0 | 06-11-2023 | New **Playbook** Torq_Sentinel_Incident_Trigger |
+
diff --git a/Solutions/Torq/SolutionMetadata.json b/Solutions/Torq/SolutionMetadata.json
new file mode 100644
index 00000000000..a1e4c6151f0
--- /dev/null
+++ b/Solutions/Torq/SolutionMetadata.json
@@ -0,0 +1,15 @@
+{
+ "publisherId": "azuresentinel",
+ "offerId": "azure-sentinel-solution-torq",
+ "firstPublishDate": "2024-11-06",
+ "providers": ["Torq"],
+ "categories": {
+ "domains" : ["Application"]
+ },
+ "support": {
+ "name": "Microsoft Corporation",
+ "email": "support@microsoft.com",
+ "tier": "Microsoft",
+ "link": "https://support.microsoft.com"
+ }
+}
\ No newline at end of file
From a097fc60dfc6110da7a90927713425a5bee06f9f Mon Sep 17 00:00:00 2001
From: PrasadBoke
Date: Tue, 19 Nov 2024 11:43:42 +0530
Subject: [PATCH 02/10] Update Torq.svg
---
Logos/Torq.svg | 18 ++++++++----------
1 file changed, 8 insertions(+), 10 deletions(-)
diff --git a/Logos/Torq.svg b/Logos/Torq.svg
index 8d3e5cc77c4..e0383fc1e44 100644
--- a/Logos/Torq.svg
+++ b/Logos/Torq.svg
@@ -1,22 +1,20 @@
-
-
-