跳到主要內容
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/checkpoint.azure-sentinel-checkpoint-cyberint-ioc-6275d4b7-5630-4e6d-83ce-70a2b45d9336/image1_Large.png

Check Point Exposure Management Threat Intelligence IoC for Microsoft Sentinel

作者 Check Point

Check Point's Logic Apps Connector and Sentinel External Risk Management (ERM) - IOC

The Check Point Exposure Management Threat Intelligence IoC Connector ingests Indicators of Compromise (IoCs) from the Check Point Infinity External Risk Management platform (formerly Cyberint) into Microsoft Sentinel. The connector automatically pulls the daily IoC feed, including malicious IP addresses, domains, URLs, and file hashes, enriched with threat context such as severity, confidence, and detected activity.
With this integration, security teams get a continuously updated stream of high-confidence threat intelligence directly in their Sentinel workspace. Ingested IoCs can be correlated against existing logs through analytics rules, hunting queries, and watchlists to surface matches with real-world external threats, reducing the manual effort of importing and maintaining threat intelligence, accelerating detection, and helping SOC analysts, IT teams, and security personnel focus on strategic threat analysis and strengthen their overall security posture.

概覽

https://catalogartifact.azureedge.net/publicartifacts/checkpoint.azure-sentinel-checkpoint-cyberint-ioc-6275d4b7-5630-4e6d-83ce-70a2b45d9336/image4_IOC.png
中文(台灣)
您的隱私權選擇退出圖示 您的隱私選擇
消費者健康情況隱私權 網站地圖 Contact Us 隱私權與 Cookie 使用條款 商標 關於我們的廣告 管理 Cookie