<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Saved Query Optimization in External Risk Management</title>
    <link>https://community.checkpoint.com/t5/External-Risk-Management/Saved-Query-Optimization/m-p/270045#M23</link>
    <description>&lt;P&gt;Hi!&lt;BR /&gt;&lt;BR /&gt;We have a saved query for a client for their application. The goal is to generate alerts for the client regarding their application for any mentions/attacks on the deep+dark+surface. The question is, how can we optimize the search so that there should be less noise, currently it generates a lot of false positives.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
    <pubDate>Mon, 09 Feb 2026 12:02:30 GMT</pubDate>
    <dc:creator>MarcEsc</dc:creator>
    <dc:date>2026-02-09T12:02:30Z</dc:date>
    <item>
      <title>Saved Query Optimization</title>
      <link>https://community.checkpoint.com/t5/External-Risk-Management/Saved-Query-Optimization/m-p/270045#M23</link>
      <description>&lt;P&gt;Hi!&lt;BR /&gt;&lt;BR /&gt;We have a saved query for a client for their application. The goal is to generate alerts for the client regarding their application for any mentions/attacks on the deep+dark+surface. The question is, how can we optimize the search so that there should be less noise, currently it generates a lot of false positives.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 09 Feb 2026 12:02:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/External-Risk-Management/Saved-Query-Optimization/m-p/270045#M23</guid>
      <dc:creator>MarcEsc</dc:creator>
      <dc:date>2026-02-09T12:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: Saved Query Optimization</title>
      <link>https://community.checkpoint.com/t5/External-Risk-Management/Saved-Query-Optimization/m-p/270437#M24</link>
      <description>&lt;P&gt;Hi Marc, thank you for your inquiry.&lt;/P&gt;
&lt;P&gt;There are various parameters you can apply to reduce false positives and noise for most queries:&lt;BR /&gt;&lt;BR /&gt;1. Ensure your query includes a &lt;STRONG&gt;textual string&lt;/STRONG&gt;, where any 2 words or more are preceded by a &lt;STRONG&gt;+&lt;/STRONG&gt; (plus) and are inside quotation marks. For example, if the app name is &lt;EM&gt;Fantastic Mobile&lt;/EM&gt;, you should type &lt;STRONG&gt;+"&lt;/STRONG&gt;Fantastic Mobile&lt;STRONG&gt;"&lt;/STRONG&gt; in the free text field, otherwise you'll get all results for "Fantastic", "Mobile", and their combination, leading to a lot of false positives. To reduce further, you can use different operators to combine with other search terms such as "attack". Click the &lt;STRONG&gt;[i]&lt;/STRONG&gt; next to the search field to view a list of available operators.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. Filter by &lt;STRONG&gt;Source Category&lt;/STRONG&gt;, and select the categories that best fit your query, such as App Store, Forum etc&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;3. Filter by &lt;STRONG&gt;Source&lt;/STRONG&gt;, if you'd like to limit the search to&amp;nbsp;&lt;STRONG&gt;specific&lt;/STRONG&gt; stores, forums etc. For example, type&amp;nbsp;"apk" under Source to view suggested stores. &lt;STRONG&gt;Note:&lt;/STRONG&gt;&amp;nbsp;this can considerably limit results.&lt;/P&gt;
&lt;P&gt;4. Filter by &lt;STRONG&gt;Assets:&lt;/STRONG&gt;&amp;nbsp;if the app is a configured&amp;nbsp;&lt;STRONG&gt;asset&lt;/STRONG&gt;, search for it. For example, if the asset is an apk name with format com.brand.appname, e.g.,&amp;nbsp;&lt;EM&gt;com.azure.authenticator&lt;/EM&gt;, start typing "com&lt;STRONG&gt;.&lt;/STRONG&gt;" under Assets, and if it's configured, it displays. Select it. If it's not configured, type it in the search field instead in this format&amp;nbsp;&lt;STRONG&gt;+"&lt;/STRONG&gt;com.azure.authenticator&lt;STRONG&gt;"&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;5. Limit the &lt;STRONG&gt;timeframe&lt;/STRONG&gt; under Created or Published if you'd only like to see items from the Last Week, Last Month etc.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If this still doesn't reduce false positives and you need further assistance with your query, kindly open a ticket with &lt;STRONG&gt;Check Point Support&lt;/STRONG&gt; and select the &lt;STRONG&gt;Threat Intelligence Request&lt;/STRONG&gt; to consult an ERM expert. In some cases the service might consume coins, and you will be advised accordingly.&lt;BR /&gt;&lt;BR /&gt;Hope this helps.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Noa Peleg&lt;BR /&gt;Knowledge &amp;amp; Enablement Lead&lt;/P&gt;</description>
      <pubDate>Wed, 11 Feb 2026 19:39:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/External-Risk-Management/Saved-Query-Optimization/m-p/270437#M24</guid>
      <dc:creator>NoaPeleg</dc:creator>
      <dc:date>2026-02-11T19:39:43Z</dc:date>
    </item>
  </channel>
</rss>

