↳ Source GitHubSolution

Check Point EM ThreatCloud Intelligence Feed

Description

Cyberint, a Check Point company, provides Microsoft Sentinel integration to streamline premium IOC ingestion and bring enriched threat intelligence from the Infinity External Risk Management solution into Microsoft Sentinel. The ThreatCloud Intelligence Feed connector incrementally pulls high-fidelity indicators — IPs, domains, URLs, and file hashes — enriched with confidence, severity, malicious classification, kill-chain stage, blocking and uniqueness flags, malware types, and CVE/campaign associations. **Underlying Microsoft Technologies used:** This solution depends on the following technologies, and some of which may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or may incur additional ingestion or operational costs: a. [Codeless Connector Framework](https://learn.microsoft.com/azure/sentinel/create-codeless-connector) (used by the ThreatCloud Intelligence Feed data connector to poll the Check Point Exposure Management API) b. [Log Analytics custom logs](https://learn.microsoft.com/azure/azure-monitor/logs/custom-logs-overview) via [Data Collection Rules (DCR)](https://learn.microsoft.com/azure/azure-monitor/essentials/data-collection-rule-overview) c. [Azure Logic Apps](https://azure.microsoft.com/services/logic-apps/) (used by the Check_Point_EM_IOCIntelligenceEnrichment playbook)
Version
3.0.1
Auteur / éditeur déclaré
Check Point - support@checkpoint.com
Niveau de support
Partner

Contenus associés

Liens établis à partir des identifiants déclarés et des manifests des solutions.

Traçabilité de la source

GitHub

Les valeurs affichées proviennent des fichiers du dépôt Azure/Azure-Sentinel. Elles décrivent le modèle publié, pas la configuration de votre workspace.

Identifiant source
azure-sentinel-checkpoint-em-threatcloud-feed
Autres fichiers source 2Solutions/Check Point EM ThreatCloud Intelligence Feed/Data/Solution_CPEMIOCIntelligence.jsonsolution-manifest ↗Solutions/Check Point EM ThreatCloud Intelligence Feed/SolutionMetadata.jsonsolution-metadata ↗
GSTEP / SUIVI DU CATALOGUE

Ajouté au catalogue : 16 sept. 2026 · 05:49 UTC
Dernier changement observé : 16 sept. 2026 · 05:49 UTC

Dates de synchronisation GSTEP, distinctes des dates de publication du contenu source.