<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need Confirmation on Correct IOC CSV Format for Threat Prevention Policy in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Need-Confirmation-on-Correct-IOC-CSV-Format-for-Threat/m-p/222674#M37076</link>
    <description>&lt;P&gt;Hello Check Point Community,&lt;/P&gt;
&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;Sir.&lt;/P&gt;
&lt;P&gt;I recently encountered an issue with the installation of the Check Point Threat Prevention Policy and wanted to share the steps taken to resolve it. This might help others facing similar issues.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Issue:&amp;nbsp;&lt;/STRONG&gt;The Threat Prevention Policy installation failed due to incorrect formatting and unsupported types in our Custom Intelligence Feeds CSV file.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Solution&lt;/STRONG&gt;: Through thorough review and correction, we successfully resolved the issue. Below are the detailed steps and technical explanations.&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Step 1: Identify the Correct Order of Columns:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Correct Order:&lt;/STRONG&gt;&lt;BR /&gt;Based on the Check Point R81.20 Threat Prevention Administration Guide, the CSV file must follow this column order:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;UNIQ-NAME&lt;/LI&gt;
&lt;LI&gt;VALUE&lt;/LI&gt;
&lt;LI&gt;TYPE&lt;/LI&gt;
&lt;LI&gt;CONFIDENCE&lt;/LI&gt;
&lt;LI&gt;SEVERITY&lt;/LI&gt;
&lt;LI&gt;PRODUCT&lt;/LI&gt;
&lt;LI&gt;COMMENT&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;U&gt;S&lt;STRONG&gt;tep 2: Supported Indicators and Types:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;Supported Formats for Indicators:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;URL&lt;/LI&gt;
&lt;LI&gt;Domain&lt;/LI&gt;
&lt;LI&gt;IP&lt;/LI&gt;
&lt;LI&gt;IP Range&lt;/LI&gt;
&lt;LI&gt;MD5&lt;/LI&gt;
&lt;LI&gt;Mail-subject&lt;/LI&gt;
&lt;LI&gt;Mail-from&lt;/LI&gt;
&lt;LI&gt;Mail-to&lt;/LI&gt;
&lt;LI&gt;Mail-cc&lt;/LI&gt;
&lt;LI&gt;Mail-reply-to&lt;/LI&gt;
&lt;LI&gt;SHA1 (in Security Gateway versions R80.40 and higher)&lt;/LI&gt;
&lt;LI&gt;SHA256 (in Security Gateway versions R80.40 and higher)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Supported Types: (In my Issue)&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;URL&lt;/LI&gt;
&lt;LI&gt;MD5&lt;/LI&gt;
&lt;LI&gt;SHA1&lt;/LI&gt;
&lt;LI&gt;SHA256&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Unsupported Types: (In my Issue)&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;HASH&lt;/LI&gt;
&lt;LI&gt;Mutex&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Step 3: Review and Correct CSV File:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Corrections Made:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Ensured the columns followed the correct order.&lt;/LI&gt;
&lt;LI&gt;Removed unsupported types (e.g., HASH and Mutex).&lt;/LI&gt;
&lt;LI&gt;Verified that all indicators use supported types and formats.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Corrected Format:&lt;/STRONG&gt;&lt;/P&gt;
&lt;TABLE width="946"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="90"&gt;UNIQ-NAME&lt;/TD&gt;
&lt;TD width="474"&gt;VALUE&lt;/TD&gt;
&lt;TD width="64"&gt;TYPE&lt;/TD&gt;
&lt;TD width="87"&gt;CONFIDENCE&lt;/TD&gt;
&lt;TD width="64"&gt;SEVERITY&lt;/TD&gt;
&lt;TD width="67"&gt;PRODUCT&lt;/TD&gt;
&lt;TD width="100"&gt;COMMENT&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;observ1&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;A href="https://file.io/M9ofMokBC1TN" target="_blank" rel="noopener"&gt;https://file.io/M9ofMokBC1TN&lt;/A&gt;&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;URL&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;High&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;High&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;AV&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;Malicious URL&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;observ2&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;A href="http://117.253.14.152:57028/Mozi.a" target="_blank" rel="noopener"&gt;http://117.253.14.152:57028/Mozi.a&lt;/A&gt;&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;URL&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;High&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;High&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;AV&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;Malicious URL&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;observ3&lt;/TD&gt;
&lt;TD&gt;866a9452ac62e73773c09a1e0209142a&lt;/TD&gt;
&lt;TD&gt;MD5&lt;/TD&gt;
&lt;TD&gt;high&lt;/TD&gt;
&lt;TD&gt;high&lt;/TD&gt;
&lt;TD&gt;AV&lt;/TD&gt;
&lt;TD&gt;Malicious Hash&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;observ4&lt;/TD&gt;
&lt;TD&gt;4d50315e3841aeee6bb05f7529489939&lt;/TD&gt;
&lt;TD&gt;MD5&lt;/TD&gt;
&lt;TD&gt;high&lt;/TD&gt;
&lt;TD&gt;high&lt;/TD&gt;
&lt;TD&gt;AV&lt;/TD&gt;
&lt;TD&gt;Malicious Hash&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;observ5&lt;/TD&gt;
&lt;TD&gt;8f609f60dd82dc13878b1d82ebc56e5056cb9274234df1510ee737e62ba22aaa&lt;/TD&gt;
&lt;TD&gt;SHA256&lt;/TD&gt;
&lt;TD&gt;high&lt;/TD&gt;
&lt;TD&gt;high&lt;/TD&gt;
&lt;TD&gt;AV&lt;/TD&gt;
&lt;TD&gt;Malicious Hash&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;observ6&lt;/TD&gt;
&lt;TD&gt;90f7d3f354a1637d7467962fe87449532881d06ed76acaae696cc286cba02de7&lt;/TD&gt;
&lt;TD&gt;SHA256&lt;/TD&gt;
&lt;TD&gt;high&lt;/TD&gt;
&lt;TD&gt;high&lt;/TD&gt;
&lt;TD&gt;AV&lt;/TD&gt;
&lt;TD&gt;Malicious Hash&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;observ7&lt;/TD&gt;
&lt;TD&gt;5186eb42f2d1a652f9fee0cdf3788b492582aca0&lt;/TD&gt;
&lt;TD&gt;SHA1&lt;/TD&gt;
&lt;TD&gt;high&lt;/TD&gt;
&lt;TD&gt;high&lt;/TD&gt;
&lt;TD&gt;AV&lt;/TD&gt;
&lt;TD&gt;Malicious Hash&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;observ8&lt;/TD&gt;
&lt;TD&gt;2faff8718f8f0ee4dcd0be5eb987b77e47961742&lt;/TD&gt;
&lt;TD&gt;SHA1&lt;/TD&gt;
&lt;TD&gt;high&lt;/TD&gt;
&lt;TD&gt;high&lt;/TD&gt;
&lt;TD&gt;AV&lt;/TD&gt;
&lt;TD&gt;Malicious Hash&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;PRE&gt;&amp;nbsp;&lt;/PRE&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;Step 4: Import Corrected CSV File:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;After making the necessary corrections, we imported the CSV file into the Check Point Threat Prevention system. The policy installation was successful without any errors.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Conclusion:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Ensuring the CSV file is formatted correctly and only includes supported indicator types is crucial for the successful installation of the Check Point Threat Prevention Policy. This process has strengthened our security posture and streamlined our threat prevention measures.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25509"&gt;@Chinmaya_Naik&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Aug 2024 05:59:34 GMT</pubDate>
    <dc:creator>Chinmaya_Naik</dc:creator>
    <dc:date>2024-08-05T05:59:34Z</dc:date>
    <item>
      <title>Need Confirmation on Correct IOC CSV Format for Threat Prevention Policy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Need-Confirmation-on-Correct-IOC-CSV-Format-for-Threat/m-p/221513#M36935</link>
      <description>&lt;P&gt;Dear Community Team,&lt;/P&gt;
&lt;P&gt;We are currently facing an issue with installing the Threat Prevention policy and require your assistance to confirm the correct format for our IOC CSV file.&lt;/P&gt;
&lt;P&gt;Here is the context of our current situation and the formats we are using:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial black,avant garde"&gt;&lt;STRONG&gt;Existing Format:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial black,avant garde"&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CSV format 1.jpg" style="width: 738px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26915i9CDA966C110DE296/image-size/large?v=v2&amp;amp;px=999" role="button" title="CSV format 1.jpg" alt="CSV format 1.jpg" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;FONT face="arial black,avant garde"&gt;&lt;STRONG&gt;Wrong Format (Not sure):&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CSV Format 3.jpg" style="width: 759px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26914iECD65A88F97AE9BE/image-size/large?v=v2&amp;amp;px=999" role="button" title="CSV Format 3.jpg" alt="CSV Format 3.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;We are particularly concerned about the formats for different types of indicators such as &lt;CODE&gt;FILENAME&lt;/CODE&gt;, &lt;CODE&gt;Mutex&lt;/CODE&gt;, and &lt;CODE&gt;Email&lt;/CODE&gt;. Furthermore, we want to ensure we are using the correct order of columns in our CSV file. Which of the following orders is correct?&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;CODE&gt;UNIQ-NAME, VALUE, TYPE, PRODUCT, CONFIDENCE, SEVERITY, COMMENT&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;CODE&gt;UNIQ-NAME, VALUE, TYPE, CONFIDENCE, SEVERITY, PRODUCT, COMMENT&lt;/CODE&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Your assistance in confirming the correct format and order for the indicators will help ensure our configuration is compliant with the Checkpoint SmartConsole GUI client requirements.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25509"&gt;@Chinmaya_Naik&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 05:35:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Need-Confirmation-on-Correct-IOC-CSV-Format-for-Threat/m-p/221513#M36935</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2024-07-22T05:35:52Z</dc:date>
    </item>
    <item>
      <title>Re: Need Confirmation on Correct IOC CSV Format for Threat Prevention Policy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Need-Confirmation-on-Correct-IOC-CSV-Format-for-Threat/m-p/221557#M36944</link>
      <description>&lt;P&gt;The exact format is in the Product Documentation:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_ThreatPrevention_AdminGuide/Content/Topics-TPG/Supported-Indicator-Files-Custom.htm?tocpath=Custom%20Threat%20Prevention%7CConfiguring%20Advanced%20Threat%20Prevention%20Settings%7CConfiguring%20Threat%20Indicators%7C_____1" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_ThreatPrevention_AdminGuide/Content/Topics-TPG/Supported-Indicator-Files-Custom.htm?tocpath=Custom%20Threat%20Prevention%7CConfiguring%20Advanced%20Threat%20Prevention%20Settings%7CConfiguring%20Threat%20Indicators%7C_____1&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 12:56:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Need-Confirmation-on-Correct-IOC-CSV-Format-for-Threat/m-p/221557#M36944</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-22T12:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: Need Confirmation on Correct IOC CSV Format for Threat Prevention Policy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Need-Confirmation-on-Correct-IOC-CSV-Format-for-Threat/m-p/222674#M37076</link>
      <description>&lt;P&gt;Hello Check Point Community,&lt;/P&gt;
&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;Sir.&lt;/P&gt;
&lt;P&gt;I recently encountered an issue with the installation of the Check Point Threat Prevention Policy and wanted to share the steps taken to resolve it. This might help others facing similar issues.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Issue:&amp;nbsp;&lt;/STRONG&gt;The Threat Prevention Policy installation failed due to incorrect formatting and unsupported types in our Custom Intelligence Feeds CSV file.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Solution&lt;/STRONG&gt;: Through thorough review and correction, we successfully resolved the issue. Below are the detailed steps and technical explanations.&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Step 1: Identify the Correct Order of Columns:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Correct Order:&lt;/STRONG&gt;&lt;BR /&gt;Based on the Check Point R81.20 Threat Prevention Administration Guide, the CSV file must follow this column order:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;UNIQ-NAME&lt;/LI&gt;
&lt;LI&gt;VALUE&lt;/LI&gt;
&lt;LI&gt;TYPE&lt;/LI&gt;
&lt;LI&gt;CONFIDENCE&lt;/LI&gt;
&lt;LI&gt;SEVERITY&lt;/LI&gt;
&lt;LI&gt;PRODUCT&lt;/LI&gt;
&lt;LI&gt;COMMENT&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;U&gt;S&lt;STRONG&gt;tep 2: Supported Indicators and Types:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;Supported Formats for Indicators:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;URL&lt;/LI&gt;
&lt;LI&gt;Domain&lt;/LI&gt;
&lt;LI&gt;IP&lt;/LI&gt;
&lt;LI&gt;IP Range&lt;/LI&gt;
&lt;LI&gt;MD5&lt;/LI&gt;
&lt;LI&gt;Mail-subject&lt;/LI&gt;
&lt;LI&gt;Mail-from&lt;/LI&gt;
&lt;LI&gt;Mail-to&lt;/LI&gt;
&lt;LI&gt;Mail-cc&lt;/LI&gt;
&lt;LI&gt;Mail-reply-to&lt;/LI&gt;
&lt;LI&gt;SHA1 (in Security Gateway versions R80.40 and higher)&lt;/LI&gt;
&lt;LI&gt;SHA256 (in Security Gateway versions R80.40 and higher)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Supported Types: (In my Issue)&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;URL&lt;/LI&gt;
&lt;LI&gt;MD5&lt;/LI&gt;
&lt;LI&gt;SHA1&lt;/LI&gt;
&lt;LI&gt;SHA256&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Unsupported Types: (In my Issue)&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;HASH&lt;/LI&gt;
&lt;LI&gt;Mutex&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Step 3: Review and Correct CSV File:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Corrections Made:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Ensured the columns followed the correct order.&lt;/LI&gt;
&lt;LI&gt;Removed unsupported types (e.g., HASH and Mutex).&lt;/LI&gt;
&lt;LI&gt;Verified that all indicators use supported types and formats.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Corrected Format:&lt;/STRONG&gt;&lt;/P&gt;
&lt;TABLE width="946"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="90"&gt;UNIQ-NAME&lt;/TD&gt;
&lt;TD width="474"&gt;VALUE&lt;/TD&gt;
&lt;TD width="64"&gt;TYPE&lt;/TD&gt;
&lt;TD width="87"&gt;CONFIDENCE&lt;/TD&gt;
&lt;TD width="64"&gt;SEVERITY&lt;/TD&gt;
&lt;TD width="67"&gt;PRODUCT&lt;/TD&gt;
&lt;TD width="100"&gt;COMMENT&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;observ1&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;A href="https://file.io/M9ofMokBC1TN" target="_blank" rel="noopener"&gt;https://file.io/M9ofMokBC1TN&lt;/A&gt;&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;URL&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;High&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;High&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;AV&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;Malicious URL&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;observ2&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;A href="http://117.253.14.152:57028/Mozi.a" target="_blank" rel="noopener"&gt;http://117.253.14.152:57028/Mozi.a&lt;/A&gt;&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;URL&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;High&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;High&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;AV&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;Malicious URL&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;observ3&lt;/TD&gt;
&lt;TD&gt;866a9452ac62e73773c09a1e0209142a&lt;/TD&gt;
&lt;TD&gt;MD5&lt;/TD&gt;
&lt;TD&gt;high&lt;/TD&gt;
&lt;TD&gt;high&lt;/TD&gt;
&lt;TD&gt;AV&lt;/TD&gt;
&lt;TD&gt;Malicious Hash&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;observ4&lt;/TD&gt;
&lt;TD&gt;4d50315e3841aeee6bb05f7529489939&lt;/TD&gt;
&lt;TD&gt;MD5&lt;/TD&gt;
&lt;TD&gt;high&lt;/TD&gt;
&lt;TD&gt;high&lt;/TD&gt;
&lt;TD&gt;AV&lt;/TD&gt;
&lt;TD&gt;Malicious Hash&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;observ5&lt;/TD&gt;
&lt;TD&gt;8f609f60dd82dc13878b1d82ebc56e5056cb9274234df1510ee737e62ba22aaa&lt;/TD&gt;
&lt;TD&gt;SHA256&lt;/TD&gt;
&lt;TD&gt;high&lt;/TD&gt;
&lt;TD&gt;high&lt;/TD&gt;
&lt;TD&gt;AV&lt;/TD&gt;
&lt;TD&gt;Malicious Hash&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;observ6&lt;/TD&gt;
&lt;TD&gt;90f7d3f354a1637d7467962fe87449532881d06ed76acaae696cc286cba02de7&lt;/TD&gt;
&lt;TD&gt;SHA256&lt;/TD&gt;
&lt;TD&gt;high&lt;/TD&gt;
&lt;TD&gt;high&lt;/TD&gt;
&lt;TD&gt;AV&lt;/TD&gt;
&lt;TD&gt;Malicious Hash&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;observ7&lt;/TD&gt;
&lt;TD&gt;5186eb42f2d1a652f9fee0cdf3788b492582aca0&lt;/TD&gt;
&lt;TD&gt;SHA1&lt;/TD&gt;
&lt;TD&gt;high&lt;/TD&gt;
&lt;TD&gt;high&lt;/TD&gt;
&lt;TD&gt;AV&lt;/TD&gt;
&lt;TD&gt;Malicious Hash&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;observ8&lt;/TD&gt;
&lt;TD&gt;2faff8718f8f0ee4dcd0be5eb987b77e47961742&lt;/TD&gt;
&lt;TD&gt;SHA1&lt;/TD&gt;
&lt;TD&gt;high&lt;/TD&gt;
&lt;TD&gt;high&lt;/TD&gt;
&lt;TD&gt;AV&lt;/TD&gt;
&lt;TD&gt;Malicious Hash&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;PRE&gt;&amp;nbsp;&lt;/PRE&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;Step 4: Import Corrected CSV File:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;After making the necessary corrections, we imported the CSV file into the Check Point Threat Prevention system. The policy installation was successful without any errors.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Conclusion:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Ensuring the CSV file is formatted correctly and only includes supported indicator types is crucial for the successful installation of the Check Point Threat Prevention Policy. This process has strengthened our security posture and streamlined our threat prevention measures.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25509"&gt;@Chinmaya_Naik&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2024 05:59:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Need-Confirmation-on-Correct-IOC-CSV-Format-for-Threat/m-p/222674#M37076</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2024-08-05T05:59:34Z</dc:date>
    </item>
  </channel>
</rss>

