{
  "Name": "Check Point EM ThreatCloud Intelligence Feed",
  "Author": "Check Point - support@checkpoint.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/checkpoint.svg\" width=\"75px\" height=\"75px\">",
  "Description": "Cyberint, a Check Point company, provides Microsoft Sentinel integration to streamline premium IOC ingestion and bring enriched threat intelligence from the Infinity External Risk Management solution into Microsoft Sentinel. The ThreatCloud Intelligence Feed connector incrementally pulls high-fidelity indicators \u2014 IPs, domains, URLs, and file hashes \u2014 enriched with confidence, severity, malicious classification, kill-chain stage, blocking and uniqueness flags, malware types, and CVE/campaign associations.\n\n**Underlying Microsoft Technologies used:**\n\nThis solution depends on the following technologies, and some of which may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or may incur additional ingestion or operational costs:\n\na. [Codeless Connector Framework](https://learn.microsoft.com/azure/sentinel/create-codeless-connector) (used by the ThreatCloud Intelligence Feed data connector to poll the Check Point Exposure Management API)\n\nb. [Log Analytics custom logs](https://learn.microsoft.com/azure/azure-monitor/logs/custom-logs-overview) via [Data Collection Rules (DCR)](https://learn.microsoft.com/azure/azure-monitor/essentials/data-collection-rule-overview)\n\nc. [Azure Logic Apps](https://azure.microsoft.com/services/logic-apps/) (used by the Check_Point_EM_IOCIntelligenceEnrichment playbook)",
  "Data Connectors": [
    "Data Connectors/CPEMIOCIntelligenceLogs_ccp/CPEMIOCIntelligenceLogs_connectorDefinition.json"
  ],
  "Playbooks": [
    "Playbooks/CPEM_IOCIntelligenceEnrichment/azuredeploy.json"
  ],
  "BasePath": "Solutions/Check Point EM ThreatCloud Intelligence Feed",
  "Version": "3.0.1",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": true,
  "Is1PConnector": false
}