https://catalogartifact.azureedge.net/publicartifacts/checkpoint.checkpoint-cyberint-solutions-alerts-c539eae4-9d6a-4aaa-baf1-ec1588134ecd/image3_Large.png
Check Point Exposure Management Alerts for Microsoft Sentinel
by Check Point
Just a moment, logging you in...
Check Point's Logic Apps Connector and Sentinel External Risk Management (ERM)
The Check Point Exposure Management Alerts integration brings alerts from the Check Point Exposure Management platform (formerly Cyberint) into Microsoft Sentinel and keeps the two systems in
sync. The data connector continuously polls for new alerts, filtered by severity and environment, and ingests them into the Sentinel workspace, where they can be automatically turned into incidents complete with severity, threat context, and attachments.
The solution includes bi-directional synchronization: status changes made in Microsoft Sentinel are reflected back in Check Point Exposure Management, and updates on the Check Point side flow into Sentinel, so analysts can work in either console without tickets drifting apart. A set of ready-made SOAR playbooks extends this foundation with automated enrichment (IoC lookups, alert attachments), takedown requests for phishing sites, credential-leak response, and vulnerability monitoring, alongside a workbook for alert overview and sync health.
This automation reduces manual effort, accelerates response times, and helps IT teams, network administrators, and security personnel focus on strategic threat analysis and strengthen their overall security posture.
sync. The data connector continuously polls for new alerts, filtered by severity and environment, and ingests them into the Sentinel workspace, where they can be automatically turned into incidents complete with severity, threat context, and attachments.
The solution includes bi-directional synchronization: status changes made in Microsoft Sentinel are reflected back in Check Point Exposure Management, and updates on the Check Point side flow into Sentinel, so analysts can work in either console without tickets drifting apart. A set of ready-made SOAR playbooks extends this foundation with automated enrichment (IoC lookups, alert attachments), takedown requests for phishing sites, credential-leak response, and vulnerability monitoring, alongside a workbook for alert overview and sync health.
This automation reduces manual effort, accelerates response times, and helps IT teams, network administrators, and security personnel focus on strategic threat analysis and strengthen their overall security posture.
At a glance
https://catalogartifact.azureedge.net/publicartifacts/checkpoint.checkpoint-cyberint-solutions-alerts-c539eae4-9d6a-4aaa-baf1-ec1588134ecd/image4_Alerts.png