Skip to main content
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/checkpoint.azure-sentinel-checkpoint-cyberint-ioc-6275d4b7-5630-4e6d-83ce-70a2b45d9336/image1_Large.png

Check Point Exposure Management Threat Intelligence IoC for Microsoft Sentinel

by Check Point

Check Point's Logic Apps Connector and Sentinel External Risk Management (ERM) - IOC

The Check Point Exposure Management Threat Intelligence IoC Connector ingests Indicators of Compromise (IoCs) from the Check Point Infinity External Risk Management platform (formerly Cyberint) into Microsoft Sentinel. The connector automatically pulls the daily IoC feed, including malicious IP addresses, domains, URLs, and file hashes, enriched with threat context such as severity, confidence, and detected activity.
With this integration, security teams get a continuously updated stream of high-confidence threat intelligence directly in their Sentinel workspace. Ingested IoCs can be correlated against existing logs through analytics rules, hunting queries, and watchlists to surface matches with real-world external threats, reducing the manual effort of importing and maintaining threat intelligence, accelerating detection, and helping SOC analysts, IT teams, and security personnel focus on strategic threat analysis and strengthen their overall security posture.

At a glance

https://catalogartifact.azureedge.net/publicartifacts/checkpoint.azure-sentinel-checkpoint-cyberint-ioc-6275d4b7-5630-4e6d-83ce-70a2b45d9336/image4_IOC.png
English (New Zealand)
Your Privacy Choices Opt-Out Icon Your Privacy Choices
Consumer Health Privacy Sitemap Contact Us Privacy & Cookies Terms of Use Trademarks About our ads Manage cookies