<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Endpoint visibility -- favorite queries in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-visibility-favorite-queries/m-p/156991#M6059</link>
    <description>&lt;P&gt;Hello CheckMates,&lt;/P&gt;
&lt;P&gt;Recently we were reviewing some endpoint logs for a white hat phishing campaign that was being performed on one of our customers.&amp;nbsp; Apparently the group was able to acquire a lot of domain credentials even though anti-phishing was on in prevent.&amp;nbsp; Upon further research the endpoint performed flawlessly because everything that was protected by Check Point was prevented.&amp;nbsp; However, this didn't stop the users from going to their mobile phone and entering their domain creds.&amp;nbsp; That was an eye-opener for the client.&lt;/P&gt;
&lt;P&gt;However, while we were in there investigating we noticed a few users that were reusing corporate credentials.&amp;nbsp; We get a weekly report from Check Point that shows critical blocks/detects, the noisiest systems how many times this or that happened and a lot of "high risk" stuff.&amp;nbsp; But what about the other things that slide under the radar?&lt;/P&gt;
&lt;P&gt;My question is this.&amp;nbsp; If you paste&amp;nbsp;("Corporate password%") into the endpoint log, you will see all of the people that attempted to or actually did use internal credentials on external sites.&amp;nbsp; This clearly would draw some concern and maybe even require a chat with the end user about best practices, additional training, etc.&amp;nbsp; What other valuable queries like that are there that provide visibility and value to an endpoint administrator other than the TOP10 or the most critical....canned reports.&lt;/P&gt;
&lt;P&gt;Does anyone else have any favorites they use for endpoint?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Paul&lt;/P&gt;</description>
    <pubDate>Sun, 11 Sep 2022 17:07:58 GMT</pubDate>
    <dc:creator>Paul_Warnagiris</dc:creator>
    <dc:date>2022-09-11T17:07:58Z</dc:date>
    <item>
      <title>Endpoint visibility -- favorite queries</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-visibility-favorite-queries/m-p/156991#M6059</link>
      <description>&lt;P&gt;Hello CheckMates,&lt;/P&gt;
&lt;P&gt;Recently we were reviewing some endpoint logs for a white hat phishing campaign that was being performed on one of our customers.&amp;nbsp; Apparently the group was able to acquire a lot of domain credentials even though anti-phishing was on in prevent.&amp;nbsp; Upon further research the endpoint performed flawlessly because everything that was protected by Check Point was prevented.&amp;nbsp; However, this didn't stop the users from going to their mobile phone and entering their domain creds.&amp;nbsp; That was an eye-opener for the client.&lt;/P&gt;
&lt;P&gt;However, while we were in there investigating we noticed a few users that were reusing corporate credentials.&amp;nbsp; We get a weekly report from Check Point that shows critical blocks/detects, the noisiest systems how many times this or that happened and a lot of "high risk" stuff.&amp;nbsp; But what about the other things that slide under the radar?&lt;/P&gt;
&lt;P&gt;My question is this.&amp;nbsp; If you paste&amp;nbsp;("Corporate password%") into the endpoint log, you will see all of the people that attempted to or actually did use internal credentials on external sites.&amp;nbsp; This clearly would draw some concern and maybe even require a chat with the end user about best practices, additional training, etc.&amp;nbsp; What other valuable queries like that are there that provide visibility and value to an endpoint administrator other than the TOP10 or the most critical....canned reports.&lt;/P&gt;
&lt;P&gt;Does anyone else have any favorites they use for endpoint?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Paul&lt;/P&gt;</description>
      <pubDate>Sun, 11 Sep 2022 17:07:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-visibility-favorite-queries/m-p/156991#M6059</guid>
      <dc:creator>Paul_Warnagiris</dc:creator>
      <dc:date>2022-09-11T17:07:58Z</dc:date>
    </item>
  </channel>
</rss>

