<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Looking for a comprehensive guide to forensics interpretation in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Looking-for-a-comprehensive-guide-to-forensics-interpretation/m-p/254587#M10731</link>
    <description>&lt;P&gt;THIS is genuinely helpful. THANK YOU!&lt;/P&gt;&lt;P&gt;To be clear, I am not concered about "official". Anything that sheds more light is getting me further along than I was before.&lt;/P&gt;</description>
    <pubDate>Tue, 05 Aug 2025 16:07:11 GMT</pubDate>
    <dc:creator>OneITguy</dc:creator>
    <dc:date>2025-08-05T16:07:11Z</dc:date>
    <item>
      <title>Looking for a comprehensive guide to forensics interpretation</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Looking-for-a-comprehensive-guide-to-forensics-interpretation/m-p/253319#M10661</link>
      <description>&lt;P&gt;Greetings. I am posting this request for references to any guides pertaining to the review and interpretation of results in Harmony Endpoint forensics results.&lt;/P&gt;&lt;P&gt;I am a relative novice when it comes to deciphering the significance of events being reported by Endpoint, and although I would enthusiastically say that it is in a whole nother galaxy compared to my previous platform (Datto AV/EDR), there is a LOT of information presented and I am unsure about how to put some of the details in context. I have been using Endpoint now for a few months, and am happy with the performance of detection and remediation, but I feel like there is more to understand about the various elements of a forensics report than the documentation provides.&lt;/P&gt;&lt;P&gt;What I need is a more complete walk through of the forensics report that breaks down each of the details in each section, ideally with some examples of events and remediation. My goal is to be able to identify what, if any, further action should be taken based on results. As an example, there have been a couple of events that clearly required restoring files from quarantine, such as components of our remote desktop broker product, TSPlus, that was effectively crippled as a result of the various triggers Endpoint executed. This also led to a hands on real time training on the ways to use Smart Exceptions. I am gradually getting a better understanding of what I am looking at in forensics, but it would be helpful to have a protocol to follow for reviewing all the info.&lt;/P&gt;&lt;P&gt;If there are videos or other resources available to admins that provide some guidance about proper Endpoint forensics review and follow up, I would be eternally grateful to whoever could point me in the right direction. In the mean time, I will continue to muddle through and hope that I am not missing something.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;-That One IT guy&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jul 2025 15:49:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Looking-for-a-comprehensive-guide-to-forensics-interpretation/m-p/253319#M10661</guid>
      <dc:creator>OneITguy</dc:creator>
      <dc:date>2025-07-16T15:49:55Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for a comprehensive guide to forensics interpretation</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Looking-for-a-comprehensive-guide-to-forensics-interpretation/m-p/254565#M10725</link>
      <description>&lt;P&gt;I recommend the&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://training-certifications.checkpoint.com/#/courses/Harmony%20Endpoint%20Specialist%20R81.20%20(CCES)" target="_self"&gt;Harmony Endpoint Specialist R81.20 (CCES)&lt;/A&gt; course.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2025 14:45:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Looking-for-a-comprehensive-guide-to-forensics-interpretation/m-p/254565#M10725</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2025-08-05T14:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for a comprehensive guide to forensics interpretation</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Looking-for-a-comprehensive-guide-to-forensics-interpretation/m-p/254571#M10726</link>
      <description>&lt;P&gt;OK, thanks for replying.&lt;/P&gt;&lt;P&gt;I suppose I should have further qualified my inquiry by explicitly stating that I am NOT interested in paying an obscene amount of money for a 2 day course that may or may not cover what I would consider far more information than can reasonably be included in a 2 day course, and for information that should be covered in documentation right out of the gate.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, if you have any OTHER information that meets the parameters, I would love to hear about it.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2025 15:25:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Looking-for-a-comprehensive-guide-to-forensics-interpretation/m-p/254571#M10726</guid>
      <dc:creator>OneITguy</dc:creator>
      <dc:date>2025-08-05T15:25:46Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for a comprehensive guide to forensics interpretation</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Looking-for-a-comprehensive-guide-to-forensics-interpretation/m-p/254573#M10727</link>
      <description>&lt;P&gt;Then you might want to contact your Check Point representative and ask for an individual session based on your demand.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2025 15:31:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Looking-for-a-comprehensive-guide-to-forensics-interpretation/m-p/254573#M10727</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2025-08-05T15:31:43Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for a comprehensive guide to forensics interpretation</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Looking-for-a-comprehensive-guide-to-forensics-interpretation/m-p/254576#M10728</link>
      <description>&lt;P&gt;Did. And was then advised to come here to seek insight from the community. So far, goose eggs.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2025 15:37:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Looking-for-a-comprehensive-guide-to-forensics-interpretation/m-p/254576#M10728</guid>
      <dc:creator>OneITguy</dc:creator>
      <dc:date>2025-08-05T15:37:19Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for a comprehensive guide to forensics interpretation</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Looking-for-a-comprehensive-guide-to-forensics-interpretation/m-p/254579#M10729</link>
      <description>&lt;P&gt;For anyone else trying to find specific content related to insight about Endpoint forensics, this YT search brought up a few relevant vids.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/results?search_query=harmony+endpoint+forensics" target="_blank"&gt;https://www.youtube.com/results?search_query=harmony+endpoint+forensics&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2025 15:51:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Looking-for-a-comprehensive-guide-to-forensics-interpretation/m-p/254579#M10729</guid>
      <dc:creator>OneITguy</dc:creator>
      <dc:date>2025-08-05T15:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for a comprehensive guide to forensics interpretation</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Looking-for-a-comprehensive-guide-to-forensics-interpretation/m-p/254586#M10730</link>
      <description>&lt;P&gt;Have a look at the links in this collection of links (multiple collections in some).&lt;/P&gt;
&lt;P&gt;The ATRG is more architectural but may hold some valuable info.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am not sure if anything more comprehensive was ever created to fully cover the Forensics report.&lt;/P&gt;
&lt;P&gt;Maybe they assumed it was enough but there's a gap that needs to be filled and we can look for help on that since you've identified the gap here.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me know what you think.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can put something together in the meantime but it wouldn't be an official guide from Check Point as such.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk164695" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk164695&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Endpoint/Collection-of-Harmony-Endpoint-links-resources/td-p/226342" target="_blank"&gt;https://community.checkpoint.com/t5/Endpoint/Collection-of-Harmony-Endpoint-links-resources/td-p/226342&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Jump to around 1/3 into this video to see info on forensics&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Endpoint/Advanced-Investigation-amp-Remediation-Using-Harmony-Endpoint/td-p/114510" target="_blank"&gt;https://community.checkpoint.com/t5/Endpoint/Advanced-Investigation-amp-Remediation-Using-Harmony-Endpoint/td-p/114510&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2025 16:04:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Looking-for-a-comprehensive-guide-to-forensics-interpretation/m-p/254586#M10730</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2025-08-05T16:04:33Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for a comprehensive guide to forensics interpretation</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Looking-for-a-comprehensive-guide-to-forensics-interpretation/m-p/254587#M10731</link>
      <description>&lt;P&gt;THIS is genuinely helpful. THANK YOU!&lt;/P&gt;&lt;P&gt;To be clear, I am not concered about "official". Anything that sheds more light is getting me further along than I was before.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2025 16:07:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Looking-for-a-comprehensive-guide-to-forensics-interpretation/m-p/254587#M10731</guid>
      <dc:creator>OneITguy</dc:creator>
      <dc:date>2025-08-05T16:07:11Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for a comprehensive guide to forensics interpretation</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Looking-for-a-comprehensive-guide-to-forensics-interpretation/m-p/254591#M10732</link>
      <description>&lt;P&gt;ACK&lt;/P&gt;
&lt;P&gt;Understood&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's still good feedback for the vendor here. Part of the reason for CheckMates.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'll put the other info in here, when I can put it together, and try to have more good reference info available.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2025 16:12:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Looking-for-a-comprehensive-guide-to-forensics-interpretation/m-p/254591#M10732</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2025-08-05T16:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for a comprehensive guide to forensics interpretation</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Looking-for-a-comprehensive-guide-to-forensics-interpretation/m-p/254593#M10733</link>
      <description>&lt;P&gt;Awesome. I appreciate your efforts and willingness to share your knowledge and experience.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2025 16:16:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Looking-for-a-comprehensive-guide-to-forensics-interpretation/m-p/254593#M10733</guid>
      <dc:creator>OneITguy</dc:creator>
      <dc:date>2025-08-05T16:16:05Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for a comprehensive guide to forensics interpretation</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Looking-for-a-comprehensive-guide-to-forensics-interpretation/m-p/254594#M10734</link>
      <description>&lt;P&gt;You are welcome. Glad I can help.&lt;/P&gt;
&lt;P&gt;Let me know if the attached is along the right lines of what you would have expected to find, if you have time.&lt;/P&gt;
&lt;P&gt;It's a first draft, a skeleton of a document, something Check Point might be able to use as a new SK or to contribute to an Admin Guide, e.g.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/SmartEndpoint_OLH/EN/Content/Topics-EPSG-R81.20/SandBlast-Agent-Use-Case.htm?tocpath=Harmony%20Endpoint%20Anti-Ransomware%252C%20Behavioral%20Guard%20and%20Forensics%7C_____7" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/SmartEndpoint_OLH/EN/Content/Topics-EPSG-R81.20/SandBlast-Agent-Use-Case.htm?tocpath=Harmony%20Endpoint%20Anti-Ransomware%252C%20Behavioral%20Guard%20and%20Forensics%7C_____7&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Otherwise I can just add to it and keep it in my library and in here for reference &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2025 16:54:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Looking-for-a-comprehensive-guide-to-forensics-interpretation/m-p/254594#M10734</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2025-08-05T16:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for a comprehensive guide to forensics interpretation</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Looking-for-a-comprehensive-guide-to-forensics-interpretation/m-p/254627#M10737</link>
      <description>&lt;P&gt;I don't think this is in any of the collections but might be useful for insights into logging, event analysis (reports) and forensics in general.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk167102" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk167102&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Aug 2025 07:38:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Looking-for-a-comprehensive-guide-to-forensics-interpretation/m-p/254627#M10737</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2025-08-06T07:38:51Z</dc:date>
    </item>
  </channel>
</rss>

