<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Severity and Confidence Levels for Security Incident on Harmony Endpoint in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Severity-and-Confidence-Levels-for-Security-Incident-on-Harmony/m-p/124885#M4582</link>
    <description>&lt;P&gt;I opened a new tack case.&lt;/P&gt;&lt;P&gt;Thanks for your advice.&lt;/P&gt;</description>
    <pubDate>Mon, 26 Jul 2021 07:59:03 GMT</pubDate>
    <dc:creator>TSOL</dc:creator>
    <dc:date>2021-07-26T07:59:03Z</dc:date>
    <item>
      <title>Severity and Confidence Levels for Security Incident on Harmony Endpoint</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Severity-and-Confidence-Levels-for-Security-Incident-on-Harmony/m-p/123581#M4499</link>
      <description>&lt;P&gt;How is the severity and confidence assigned to all blades for Harmony Endpoint(Anti Malware/Anti Bot /URL Filtering/ Anti Ransomware/ Behavioral Guard /&amp;nbsp;Threat Emulation / Anti Exploit/Firewall / Application Control/Compliance ).?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I found&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;sk116254 but just regarding information of Quantum IPS /AV/AB.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And I found almost the same question in the Checkmates thread.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;However, the result ends with the technical team contacting the questioner.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 08:25:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Severity-and-Confidence-Levels-for-Security-Incident-on-Harmony/m-p/123581#M4499</guid>
      <dc:creator>TSOL</dc:creator>
      <dc:date>2021-07-12T08:25:49Z</dc:date>
    </item>
    <item>
      <title>Re: Severity and Confidence Levels for Security Incident on Harmony Endpoint</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Severity-and-Confidence-Levels-for-Security-Incident-on-Harmony/m-p/123641#M4502</link>
      <description>&lt;P&gt;I assume you’re referring to this thread:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Endpoint/Severity-and-Confidence-Levels-for-Security-Incidents/m-p/106355#M3048" target="_blank"&gt;https://community.checkpoint.com/t5/Endpoint/Severity-and-Confidence-Levels-for-Security-Incidents/m-p/106355#M3048&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Like I said in that thread, the guidelines for IPS also generally apply for Harmony Endpoint.&lt;BR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9013"&gt;@Guy_Avnet&lt;/a&gt;&amp;nbsp;can we produce something similar to sk116254 but geared at Harmony Endpoint?&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 18:57:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Severity-and-Confidence-Levels-for-Security-Incident-on-Harmony/m-p/123641#M4502</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-12T18:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: Severity and Confidence Levels for Security Incident on Harmony Endpoint</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Severity-and-Confidence-Levels-for-Security-Incident-on-Harmony/m-p/123692#M4507</link>
      <description>&lt;P&gt;Thank you for your reply.&lt;BR /&gt;I wanted to check the URL and see the severity details.&lt;BR /&gt;Here's what I want to know:&lt;BR /&gt;For example, if severity is critical, under what conditions does it occur?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2021 07:54:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Severity-and-Confidence-Levels-for-Security-Incident-on-Harmony/m-p/123692#M4507</guid>
      <dc:creator>TSOL</dc:creator>
      <dc:date>2021-07-13T07:54:50Z</dc:date>
    </item>
    <item>
      <title>Re: Severity and Confidence Levels for Security Incident on Harmony Endpoint</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Severity-and-Confidence-Levels-for-Security-Incident-on-Harmony/m-p/123739#M4510</link>
      <description>&lt;P&gt;Again, the guidance in sk116254 applies here.&lt;BR /&gt;That means the URL has something on it that generally involves remote code execution, is widely exploited, has no patch, is in wide use in Enterprises, etc.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2021 20:04:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Severity-and-Confidence-Levels-for-Security-Incident-on-Harmony/m-p/123739#M4510</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-13T20:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: Severity and Confidence Levels for Security Incident on Harmony Endpoint</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Severity-and-Confidence-Levels-for-Security-Incident-on-Harmony/m-p/123742#M4511</link>
      <description>&lt;P&gt;It would be best to have an SK reference all blades/protections present in Harmony Endpoint. Many customers ask me about this and are not very convinced when I point to an SK that is focused on another product or protection not present in HE.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2021 20:43:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Severity-and-Confidence-Levels-for-Security-Incident-on-Harmony/m-p/123742#M4511</guid>
      <dc:creator>MikeB</dc:creator>
      <dc:date>2021-07-13T20:43:51Z</dc:date>
    </item>
    <item>
      <title>Re: Severity and Confidence Levels for Security Incident on Harmony Endpoint</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Severity-and-Confidence-Levels-for-Security-Incident-on-Harmony/m-p/124882#M4580</link>
      <description>&lt;P&gt;Thanks for your reply.&lt;BR /&gt;And I'm sorry for the late reply.&lt;/P&gt;&lt;P&gt;The SK is written "Severity is currently only set to distinguish between adware (assigned low severity) and malware (assigned medium or high severity).&amp;nbsp;"&lt;BR /&gt;The harmony EN log also lists the severity of zero phishing blades and smart event clients.&lt;BR /&gt;I don't think there will be adware in the "Smart Event Client", but it will show a medium severity.&lt;BR /&gt;In addition, the content of events that occur with a critical severity in the "Endpoint Compliance Blade" includes signature update failures and so on.I don't think everything is malware or adware.&lt;/P&gt;&lt;P&gt;Is there a document explaining the severity of the harmony EN log?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 07:30:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Severity-and-Confidence-Levels-for-Security-Incident-on-Harmony/m-p/124882#M4580</guid>
      <dc:creator>TSOL</dc:creator>
      <dc:date>2021-07-26T07:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: Severity and Confidence Levels for Security Incident on Harmony Endpoint</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Severity-and-Confidence-Levels-for-Security-Incident-on-Harmony/m-p/124883#M4581</link>
      <description>&lt;P&gt;Specifically, no.&lt;BR /&gt;In general, the logs should comply with that SK, which now specifically mentions Harmony Endpoint.&lt;BR /&gt;There is probably a few cases where it doesn't exactly match what it says there.&lt;BR /&gt;For that, I recommend a TAC case.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 07:35:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Severity-and-Confidence-Levels-for-Security-Incident-on-Harmony/m-p/124883#M4581</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-26T07:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: Severity and Confidence Levels for Security Incident on Harmony Endpoint</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Severity-and-Confidence-Levels-for-Security-Incident-on-Harmony/m-p/124885#M4582</link>
      <description>&lt;P&gt;I opened a new tack case.&lt;/P&gt;&lt;P&gt;Thanks for your advice.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 07:59:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Severity-and-Confidence-Levels-for-Security-Incident-on-Harmony/m-p/124885#M4582</guid>
      <dc:creator>TSOL</dc:creator>
      <dc:date>2021-07-26T07:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: Severity and Confidence Levels for Security Incident on Harmony Endpoint</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Severity-and-Confidence-Levels-for-Security-Incident-on-Harmony/m-p/132312#M4761</link>
      <description>&lt;P&gt;Actually, Harmony Endpoint is mentioned as one of the products in the SK now (wasn't before).&lt;BR /&gt;If you have specific feedback about what you feel is missing there, I recommend leaving it in the SK.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 05:10:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Severity-and-Confidence-Levels-for-Security-Incident-on-Harmony/m-p/132312#M4761</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-10-21T05:10:01Z</dc:date>
    </item>
  </channel>
</rss>

