↳ GitHub sourceSolution
Check Point EM ThreatCloud Intelligence Feed
Description
Cyberint, a Check Point company, provides Microsoft Sentinel integration to streamline premium IOC ingestion and bring enriched threat intelligence from the Infinity External Risk Management solution into Microsoft Sentinel. The ThreatCloud Intelligence Feed connector incrementally pulls high-fidelity indicators — IPs, domains, URLs, and file hashes — enriched with confidence, severity, malicious classification, kill-chain stage, blocking and uniqueness flags, malware types, and CVE/campaign associations.
**Underlying Microsoft Technologies used:**
This solution depends on the following technologies, and some of which may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or may incur additional ingestion or operational costs:
a. [Codeless Connector Framework](https://learn.microsoft.com/azure/sentinel/create-codeless-connector) (used by the ThreatCloud Intelligence Feed data connector to poll the Check Point Exposure Management API)
b. [Log Analytics custom logs](https://learn.microsoft.com/azure/azure-monitor/logs/custom-logs-overview) via [Data Collection Rules (DCR)](https://learn.microsoft.com/azure/azure-monitor/essentials/data-collection-rule-overview)
c. [Azure Logic Apps](https://azure.microsoft.com/services/logic-apps/) (used by the Check_Point_EM_IOCIntelligenceEnrichment playbook)
- Version
- 3.0.1
- Declared author / publisher
- Check Point - support@checkpoint.com
- Support tier
- Partner
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
9800e51↗- Source identifier
azure-sentinel-checkpoint-em-threatcloud-feed
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC