<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Endpoint Security / SandBlast Agent Newsletter - Version E83.20 in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-SandBlast-Agent-Newsletter-Version-E83-20/m-p/97779#M3080</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1015"&gt;@MikeB&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The extension is being uploaded only to Chrome store and not to Microsoft&amp;nbsp;store.&lt;/P&gt;
&lt;P&gt;Edge&amp;nbsp;is configured to take it from Chrome store but only if it is in a domain.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So currently this is a limitation and a must for Edge to be part of a domain.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We do consider having the extension also uploaded to the Microsoft-store&amp;nbsp;but it’s still not final.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Guy&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 09:57:36 GMT</pubDate>
    <dc:creator>Guy_Avnet</dc:creator>
    <dc:date>2020-09-29T09:57:36Z</dc:date>
    <item>
      <title>Endpoint Security / SandBlast Agent Newsletter - Version E83.20</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-SandBlast-Agent-Newsletter-Version-E83-20/m-p/95422#M3078</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are happy to announce the release of Endpoint Security Client &lt;STRONG&gt;E83.20&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The complete list of improvements can be found in the version release’s Secure Knowledge &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk168081" target="_blank"&gt;sk168081&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;But here are the most exciting ones…&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;New windows support&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;E83.20 &lt;/STRONG&gt;has full support (all blades and packages) for&amp;nbsp;Windows&amp;nbsp;10&amp;nbsp;20H1 (version&amp;nbsp;2004)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Browser Extension support Microsoft Edge (Chromium) &amp;amp; Chrome for Mac&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;SandBlast Agent Browser Extension now supports Microsoft Edge (Chromium) and Chrome for Mac with the following capabilities:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;URL Filtering (WebUI only)&lt;/LI&gt;
&lt;LI&gt;File Download Protection&lt;/LI&gt;
&lt;LI&gt;Credential Theft protection including Zero-Phishing and Corporate-password-reuse protection&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The extension is installed automatically together with the new version&lt;/P&gt;
&lt;P&gt;&lt;U&gt;Supported &amp;amp; Next To Come:&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Guy_Avnet_0-1598542587961.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7802i43BDAF049C467A19/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Guy_Avnet_0-1598542587961.png" alt="Guy_Avnet_0-1598542587961.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;E83.20 for macOS &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Guy_Avnet_1-1598542587964.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7801i7F28DF1251B01B84/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Guy_Avnet_1-1598542587964.png" alt="Guy_Avnet_1-1598542587964.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The version supports the following capabilities:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Anti-Malware blade is now GA&lt;/LI&gt;
&lt;LI&gt;URL Filtering with SandBlast Agent Chrome Browser Extension&lt;/LI&gt;
&lt;LI&gt;Advanced VPN features are now also available on Mac:&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;Multiple Factor Authentication&lt;/LI&gt;
&lt;LI&gt;Multiple Entry Point&lt;/LI&gt;
&lt;LI&gt;Implicit Mode&lt;/LI&gt;
&lt;LI&gt;Secondary Connect&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P&gt;Follow &lt;SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk166955" target="_blank"&gt;sk166955&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;for more information on the E83.20 release for macOS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;New advanced protections&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;"Pass The Hash" detection &lt;/STRONG&gt;in Behavioral Guard has been enhanced, to recognize more “Pass The Hash” attempts. &lt;BR /&gt;Pass The Hash is used by an attacker to do remote authentication by utilizing the hash of an account password. In other words, the attacker does not need the actual plaintext password. &lt;BR /&gt;This technique in essence allows for lateral movement in an organization.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Improved malicious LNK files detection&lt;BR /&gt;&lt;/STRONG&gt;Behavioral Guard was enhanced, to detect malicious LNK files (windows shortcut / direct link to a file). It analyzes the target of a LNK file to determine if the LNK file itself is malicious. &lt;BR /&gt;LNK files are mostly though not exclusively utilized maliciously to start LOLBins (Living Off The Land Binaries) like Windows OS executables. Some common targets for malicious LNK files include CMD, powershell, and wscript.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In addition, the&amp;nbsp;Forensics Analysis now can determine whether the attack originated from an LNK file and the Forensics Report shows the targets of all LNK files in an incident.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Content view in the Forensics report&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The Forensics Report now has been enhanced to show all AMSI content and LNK targets in a new single view called the Content View. This view is accessible under the Incident Details Menu option.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Guy_Avnet_2-1598542587972.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7803i5F3B1C347C505D1B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Guy_Avnet_2-1598542587972.png" alt="Guy_Avnet_2-1598542587972.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Full Disk Encryption – pre-boot screen&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The Full Disk Encryption pre–boot has a modernized look and feel along with updates to the color-theme and background images.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Guy_Avnet_3-1598542587975.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7804iDB241DB37C8AF72A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Guy_Avnet_3-1598542587975.png" alt="Guy_Avnet_3-1598542587975.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Stay safe,&lt;/P&gt;
&lt;P&gt;Guy A.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2020 15:38:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-SandBlast-Agent-Newsletter-Version-E83-20/m-p/95422#M3078</guid>
      <dc:creator>Guy_Avnet</dc:creator>
      <dc:date>2020-08-27T15:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security / SandBlast Agent Newsletter - Version E83.20</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-SandBlast-Agent-Newsletter-Version-E83-20/m-p/97648#M3079</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9013"&gt;@Guy_Avnet&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;According to&amp;nbsp;&lt;SPAN&gt;sk169216 and&amp;nbsp;sk108695, SBA4B "is installed on the Edge Chromium browser only on machines that are joined to the Organization Domain Controller (DC)."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;What about non-AD clients?? It is possible to manually install Edge Chromium SBA4B on this machines?&lt;/P&gt;</description>
      <pubDate>Sun, 27 Sep 2020 15:30:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-SandBlast-Agent-Newsletter-Version-E83-20/m-p/97648#M3079</guid>
      <dc:creator>MikeB</dc:creator>
      <dc:date>2020-09-27T15:30:49Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security / SandBlast Agent Newsletter - Version E83.20</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-SandBlast-Agent-Newsletter-Version-E83-20/m-p/97779#M3080</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1015"&gt;@MikeB&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The extension is being uploaded only to Chrome store and not to Microsoft&amp;nbsp;store.&lt;/P&gt;
&lt;P&gt;Edge&amp;nbsp;is configured to take it from Chrome store but only if it is in a domain.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So currently this is a limitation and a must for Edge to be part of a domain.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We do consider having the extension also uploaded to the Microsoft-store&amp;nbsp;but it’s still not final.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Guy&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:57:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-SandBlast-Agent-Newsletter-Version-E83-20/m-p/97779#M3080</guid>
      <dc:creator>Guy_Avnet</dc:creator>
      <dc:date>2020-09-29T09:57:36Z</dc:date>
    </item>
  </channel>
</rss>

