<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MITRE ATT&amp;amp;CK Extension in SmartConsole Extensions</title>
    <link>https://community.checkpoint.com/t5/SmartConsole-Extensions/MITRE-ATT-amp-CK-Extension/m-p/118306#M192</link>
    <description>&lt;P&gt;Hey Mike,&lt;/P&gt;
&lt;P&gt;it is not working for now on the raw logs of the agent.&lt;/P&gt;
&lt;P&gt;we are extracting all the MITRE content from our agent to the Forensics but in the agent side we are mainly focused on the threat hunting and full MITRE coverage in the cloud deployment.&lt;/P&gt;</description>
    <pubDate>Thu, 13 May 2021 06:56:02 GMT</pubDate>
    <dc:creator>Oren_Koren</dc:creator>
    <dc:date>2021-05-13T06:56:02Z</dc:date>
    <item>
      <title>MITRE ATT&amp;CK Extension</title>
      <link>https://community.checkpoint.com/t5/SmartConsole-Extensions/MITRE-ATT-amp-CK-Extension/m-p/118273#M190</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MITRE-ATTACK-CheckMates.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11676i8CDBCCFEC9787D54/image-size/large?v=v2&amp;amp;px=999" role="button" title="MITRE-ATTACK-CheckMates.jpg" alt="MITRE-ATTACK-CheckMates.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;in today world of emerging threat, MITRE ATT&amp;amp;CK allows us to understand better the attacker intent and take actions upon the threats that has been detected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the MITRE ATT&amp;amp;CK extension to SmartConsole (R80.30 version and above) expose the attackers intent by analyzing automatically your logs and use them to expose your own ATT&amp;amp;CK landscape and the Mitigations you need to take.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The extension is focus on analyzing IPS &amp;amp; AB logs and have a dependency on SmartEvent that needed to be enabled.&lt;/LI&gt;
&lt;LI&gt;The report capability is available from R81.10 and will be ported to older versions after R81.10 GA release.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The community version can be downloaded from this link:&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;A href="https://secureupdates.checkpoint.com/appi/mitre/mitre_network/extension.json" target="_blank"&gt;https://secureupdates.checkpoint.com/appi/mitre/mitre_network/extension.json&lt;/A&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;if you have any questions, inputs, challenges&amp;nbsp; - please update us or send a direct email to orenkor@checkpoint.com&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 16:15:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartConsole-Extensions/MITRE-ATT-amp-CK-Extension/m-p/118273#M190</guid>
      <dc:creator>Oren_Koren</dc:creator>
      <dc:date>2021-05-12T16:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: MITRE ATT&amp;CK Extension</title>
      <link>https://community.checkpoint.com/t5/SmartConsole-Extensions/MITRE-ATT-amp-CK-Extension/m-p/118292#M191</link>
      <description>&lt;P&gt;Thanks Oren!&amp;nbsp;&lt;/P&gt;&lt;P&gt;This also can work for Sandblast Agent?? I know we can see a special view under Threat Hunting but we are unable to generate a report based on Threat Hunting querys&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 21:09:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartConsole-Extensions/MITRE-ATT-amp-CK-Extension/m-p/118292#M191</guid>
      <dc:creator>MikeB</dc:creator>
      <dc:date>2021-05-12T21:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: MITRE ATT&amp;CK Extension</title>
      <link>https://community.checkpoint.com/t5/SmartConsole-Extensions/MITRE-ATT-amp-CK-Extension/m-p/118306#M192</link>
      <description>&lt;P&gt;Hey Mike,&lt;/P&gt;
&lt;P&gt;it is not working for now on the raw logs of the agent.&lt;/P&gt;
&lt;P&gt;we are extracting all the MITRE content from our agent to the Forensics but in the agent side we are mainly focused on the threat hunting and full MITRE coverage in the cloud deployment.&lt;/P&gt;</description>
      <pubDate>Thu, 13 May 2021 06:56:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartConsole-Extensions/MITRE-ATT-amp-CK-Extension/m-p/118306#M192</guid>
      <dc:creator>Oren_Koren</dc:creator>
      <dc:date>2021-05-13T06:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: MITRE ATT&amp;CK Extension</title>
      <link>https://community.checkpoint.com/t5/SmartConsole-Extensions/MITRE-ATT-amp-CK-Extension/m-p/118505#M193</link>
      <description>&lt;P&gt;Why is it not possible to use this extension without approving CP to use metadata and application usage?&lt;/P&gt;&lt;P&gt;Internal policies disallow me to use such applications&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":face_with_rolling_eyes:"&gt;🙄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 May 2021 09:49:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartConsole-Extensions/MITRE-ATT-amp-CK-Extension/m-p/118505#M193</guid>
      <dc:creator>Daniel_</dc:creator>
      <dc:date>2021-05-17T09:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: MITRE ATT&amp;CK Extension</title>
      <link>https://community.checkpoint.com/t5/SmartConsole-Extensions/MITRE-ATT-amp-CK-Extension/m-p/118768#M194</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;the extension is complementary to our customers.&lt;/P&gt;
&lt;P&gt;we have just released it and the main goal is to understand if there are errors and what is the customer flow of usage to improve it.&lt;/P&gt;
&lt;P&gt;we do not collect any info on the network of the customer, just the usage (where he clicked and what are the errors) - thats how we can improve a web application that is a complementary and without any payment for.&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 08:24:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartConsole-Extensions/MITRE-ATT-amp-CK-Extension/m-p/118768#M194</guid>
      <dc:creator>Oren_Koren</dc:creator>
      <dc:date>2021-05-19T08:24:50Z</dc:date>
    </item>
    <item>
      <title>Re: MITRE ATT&amp;CK Extension</title>
      <link>https://community.checkpoint.com/t5/SmartConsole-Extensions/MITRE-ATT-amp-CK-Extension/m-p/120274#M195</link>
      <description>&lt;P&gt;Hi Oren,&lt;/P&gt;&lt;P&gt;I'm trying to run extension and I have just error "Sorry, there was a problem loading the page...".&lt;/P&gt;&lt;P&gt;Any idea to solve ?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 09:42:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartConsole-Extensions/MITRE-ATT-amp-CK-Extension/m-p/120274#M195</guid>
      <dc:creator>Peter_Roth</dc:creator>
      <dc:date>2021-06-03T09:42:19Z</dc:date>
    </item>
    <item>
      <title>Re: MITRE ATT&amp;CK Extension</title>
      <link>https://community.checkpoint.com/t5/SmartConsole-Extensions/MITRE-ATT-amp-CK-Extension/m-p/145363#M229</link>
      <description>&lt;P&gt;Das it work with MDM?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 12:33:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartConsole-Extensions/MITRE-ATT-amp-CK-Extension/m-p/145363#M229</guid>
      <dc:creator>mkuehn</dc:creator>
      <dc:date>2022-04-04T12:33:16Z</dc:date>
    </item>
  </channel>
</rss>

