<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Looking for clarification on Threat Emulation Custom Password Configs in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Looking-for-clarification-on-Threat-Emulation-Custom-Password/m-p/69542#M13325</link>
    <description>&lt;P&gt;We are looking to create a custom password list using the SK below based on intel and active threats we've seen.&amp;nbsp; What I'm having trouble understanding though is why we need to add phrases as well given that threat emulation already knows what inbound emails to look at based on the extensions you have defined.&amp;nbsp; What value do we get out of this?&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112821" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112821&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 06 Dec 2019 13:43:25 GMT</pubDate>
    <dc:creator>Gregory_Link</dc:creator>
    <dc:date>2019-12-06T13:43:25Z</dc:date>
    <item>
      <title>Looking for clarification on Threat Emulation Custom Password Configs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Looking-for-clarification-on-Threat-Emulation-Custom-Password/m-p/69542#M13325</link>
      <description>&lt;P&gt;We are looking to create a custom password list using the SK below based on intel and active threats we've seen.&amp;nbsp; What I'm having trouble understanding though is why we need to add phrases as well given that threat emulation already knows what inbound emails to look at based on the extensions you have defined.&amp;nbsp; What value do we get out of this?&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112821" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112821&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2019 13:43:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Looking-for-clarification-on-Threat-Emulation-Custom-Password/m-p/69542#M13325</guid>
      <dc:creator>Gregory_Link</dc:creator>
      <dc:date>2019-12-06T13:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for clarification on Threat Emulation Custom Password Configs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Looking-for-clarification-on-Threat-Emulation-Custom-Password/m-p/69557#M13326</link>
      <description>The phrases are keywords that might indicate a password is encoded in the email for an end user to type in to decrypt the file.</description>
      <pubDate>Fri, 06 Dec 2019 20:15:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Looking-for-clarification-on-Threat-Emulation-Custom-Password/m-p/69557#M13326</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-12-06T20:15:15Z</dc:date>
    </item>
  </channel>
</rss>

