<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Find a IOC in checkpoint database (malicious IP, domain) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Find-a-IOC-in-checkpoint-database-malicious-IP-domain/m-p/234009#M45327</link>
    <description>&lt;P&gt;Hi everyone. I have a question about IOC&lt;/P&gt;&lt;P&gt;Is there have any tool to check a IOC(like malicious IP, domain ) in database of Checkpoint Firewall. It is like virustotal check. The input is a malicious IP and the output will show this malicious IP already have in database or not.&lt;/P&gt;&lt;P&gt;Note: My goal is check malicious IP is exists or not and add them to custom policy if they not exist.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks !!!&lt;/P&gt;</description>
    <pubDate>Thu, 28 Nov 2024 05:30:51 GMT</pubDate>
    <dc:creator>rozkie20</dc:creator>
    <dc:date>2024-11-28T05:30:51Z</dc:date>
    <item>
      <title>Find a IOC in checkpoint database (malicious IP, domain)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Find-a-IOC-in-checkpoint-database-malicious-IP-domain/m-p/234009#M45327</link>
      <description>&lt;P&gt;Hi everyone. I have a question about IOC&lt;/P&gt;&lt;P&gt;Is there have any tool to check a IOC(like malicious IP, domain ) in database of Checkpoint Firewall. It is like virustotal check. The input is a malicious IP and the output will show this malicious IP already have in database or not.&lt;/P&gt;&lt;P&gt;Note: My goal is check malicious IP is exists or not and add them to custom policy if they not exist.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks !!!&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2024 05:30:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Find-a-IOC-in-checkpoint-database-malicious-IP-domain/m-p/234009#M45327</guid>
      <dc:creator>rozkie20</dc:creator>
      <dc:date>2024-11-28T05:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: Find a IOC in checkpoint database (malicious IP, domain)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Find-a-IOC-in-checkpoint-database-malicious-IP-domain/m-p/234012#M45329</link>
      <description>&lt;P&gt;If you have our XDR offering, you can query our database to get details about specific IPs/domains.&lt;BR /&gt;Outside of that, I don't believe we offer a mechanism.&lt;/P&gt;
&lt;P&gt;In any case, if you have other sources you trust say something is malicious, you can add it to your own &lt;A href="https://support.checkpoint.com/results/sk/sk132193" target="_self"&gt;IoC Feed&lt;/A&gt; or &lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Network_Feed.htm" target="_self"&gt;Network Feed&lt;/A&gt; object, irrespective if it is in ThreatCloud.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2024 06:50:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Find-a-IOC-in-checkpoint-database-malicious-IP-domain/m-p/234012#M45329</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-11-28T06:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: Find a IOC in checkpoint database (malicious IP, domain)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Find-a-IOC-in-checkpoint-database-malicious-IP-domain/m-p/236667#M45904</link>
      <description>&lt;P&gt;fetched external IOC feeds are stored in&amp;nbsp;/opt/CPsuite-R81.20/fw1/external_ioc/&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Dec 2024 10:05:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Find-a-IOC-in-checkpoint-database-malicious-IP-domain/m-p/236667#M45904</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2024-12-23T10:05:40Z</dc:date>
    </item>
  </channel>
</rss>

