Check Point Exposure Management Threat Intelligence IoC for Microsoft Sentinel
by Check Point
Check Point's Logic Apps Connector and Sentinel External Risk Management (ERM) - IOC
The Check Point Exposure Management Threat Intelligence IoC Connector ingests Indicators of Compromise (IoCs) from the Check Point Infinity External Risk Management platform (formerly Cyberint) into Microsoft Sentinel. The connector automatically pulls the daily IoC feed, including malicious IP addresses, domains, URLs, and file hashes, enriched with threat context such as severity, confidence, and detected activity.
With this integration, security teams get a continuously updated stream of high-confidence threat intelligence directly in their Sentinel workspace. Ingested IoCs can be correlated against existing logs through analytics rules, hunting queries, and watchlists to surface matches with real-world external threats, reducing the manual effort of importing and maintaining threat intelligence, accelerating detection, and helping SOC analysts, IT teams, and security personnel focus on strategic threat analysis and strengthen their overall security posture.