<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic [EN] Check Point XDR/XPR: An Overview of Extended Detection and Prevention in XDR</title>
    <link>https://community.checkpoint.com/t5/XDR/EN-Check-Point-XDR-XPR-An-Overview-of-Extended-Detection-and/m-p/283350#M52</link>
    <description>&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Scope note:&lt;/STRONG&gt; Check Point XDR (formerly Infinity XDR/XPR) is a cloud service in the Check Point Infinity Portal. This overview is written from the official Check Point XDR Administration Guide.&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Purpose&lt;/H2&gt;
&lt;P&gt;Every product in the stack already raises its own alerts, and that is exactly the problem: too many alerts, no single story. XDR takes the events from all of them, correlates across products and time, and hands the analyst a short list of prioritized incidents with recommended actions, plus the ability to push a response back out to every connected product. This overview explains what XDR and XPR are, how an event becomes an incident, and how the enforcement loop closes.&lt;/P&gt;
&lt;H2&gt;Audience&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;[x] SOC Analysts&lt;/LI&gt;
&lt;LI&gt;[x] Security Engineers&lt;/LI&gt;
&lt;LI&gt;[x] Incident Responders&lt;/LI&gt;
&lt;LI&gt;[x] Beginners&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;What It Is&lt;/H2&gt;
&lt;P&gt;Check Point XDR is an &lt;STRONG&gt;Extended Detection Response (XDR)&lt;/STRONG&gt; and &lt;STRONG&gt;Extended Prevention Response (XPR)&lt;/STRONG&gt; tool. It gives a unified view across onboarded products and helps you detect, respond to, and prevent attacks. Three benefits define it:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Operator efficiency.&lt;/STRONG&gt; It processes large volumes of events and alerts into a small, prioritized set of incidents that actually need attention.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Unique detections.&lt;/STRONG&gt; With a view across the network and over time, it uses AI, ML and correlation to find threats that no single product would catch on its own, including Correlation and User and Entity Behavior Analytics (UEBA).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Collaborative enforcement.&lt;/STRONG&gt; It coordinates and automates response across every connected product, using Indicators of Compromise (IoCs) as the shared currency.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The difference between XDR and XPR is the verb: XDR detects and responds, XPR adds the automated prevention.&lt;/P&gt;
&lt;H2&gt;Events, Alerts and Incidents&lt;/H2&gt;
&lt;P&gt;The whole model is a funnel of three levels, and keeping them straight is the key to using XDR:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Events (logs)&lt;/STRONG&gt; are records of normal or noteworthy activity, such as a login or a file access. Most are benign, and they are the raw material.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Alerts&lt;/STRONG&gt; are notifications raised when a rule or an AI model sees something worth attention. Not every alert is a real problem, but each warrants a look.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Incidents&lt;/STRONG&gt; are confirmed or suspected threats that need containment and resolution. An incident is built from one or more alerts and is the primary unit the analyst works with: assign it, comment on it, and close it with a status.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="background-color: #fff3cd; padding: 10px;"&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="diag1-events-to-incident.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35492i07BBF49C442E3013/image-size/large?v=v2&amp;amp;px=999" role="button" title="diag1-events-to-incident.png" alt="diag1-events-to-incident.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Each incident is built from &lt;STRONG&gt;Assets&lt;/STRONG&gt; (the users and devices at stake), &lt;STRONG&gt;Artifacts&lt;/STRONG&gt; (evidence like files, processes, IPs, URLs) and &lt;STRONG&gt;Indicators&lt;/STRONG&gt; (the artifacts that signal a real threat).&lt;/P&gt;
&lt;H2&gt;How an Alert Becomes an Incident&lt;/H2&gt;
&lt;P&gt;Alerts, whether they come from a connected product or from XDR's own AI and UEBA, go through four steps:&lt;/P&gt;
&lt;P&gt;1. &lt;STRONG&gt;Grouping&lt;/STRONG&gt; collapses near-identical alerts that differ only by time.&lt;/P&gt;
&lt;P&gt;2. &lt;STRONG&gt;Enrichment&lt;/STRONG&gt; adds context and threat intelligence, such as geolocation and reputation.&lt;/P&gt;
&lt;P&gt;3. &lt;STRONG&gt;Validation&lt;/STRONG&gt; scores the alert and its indicators and assigns a verdict with a short justification.&lt;/P&gt;
&lt;P&gt;4. &lt;STRONG&gt;Correlation&lt;/STRONG&gt; stitches alerts together across products when they share a user, an IP or another common component, turning scattered signals into one incident.&lt;/P&gt;
&lt;P&gt;Each alert carries an Action status of &lt;STRONG&gt;Detected&lt;/STRONG&gt; or &lt;STRONG&gt;Blocked&lt;/STRONG&gt;, and each incident carries a Prevented status of &lt;STRONG&gt;Detected&lt;/STRONG&gt; (Action Required) or &lt;STRONG&gt;Prevented&lt;/STRONG&gt; (blocked and the source addressed).&lt;/P&gt;
&lt;H2&gt;Collaborative Enforcement: the Closed Loop&lt;/H2&gt;
&lt;P&gt;Detection is half the value. The other half is pushing a response back out:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;IoC Management&lt;/STRONG&gt; is a central platform that collects IoCs through feeds (manual or live) and publishes output feeds that other products consume. When the same IoC appears in multiple feeds, feed priority resolves the conflict. A built-in &lt;STRONG&gt;XDR Feed&lt;/STRONG&gt; holds IoCs created inside XDR.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Policy Automation&lt;/STRONG&gt; can, when an incident meets a chosen confidence and severity, automatically add indicators to IoC Management, either disabled for review or enabled immediately.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;An IoC blocked here is blocked everywhere that consumes the feed, which is what makes the response collaborative rather than product-by-product.&lt;/P&gt;
&lt;P style="background-color: #fff3cd; padding: 10px;"&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="diag2-collaborative-enforcement.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35493iBE5023B0265BED18/image-size/large?v=v2&amp;amp;px=999" role="button" title="diag2-collaborative-enforcement.png" alt="diag2-collaborative-enforcement.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;What Connects to It&lt;/H2&gt;
&lt;P&gt;XDR widens its view through three integration types, each with log, response and IoC aspects:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Check Point products&lt;/STRONG&gt; integrate with no extra configuration: Endpoint Security (EPMaaS), Quantum Security Gateway and Cloud Firewall, Email Security, and Mobile Security.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Identity sources&lt;/STRONG&gt; (Active Directory, Okta, the Endpoint Identity Connector) enrich alerts with device and user names and enable login-anomaly detection.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Third-party products&lt;/STRONG&gt; connect by Syslog (pushed) or API (pulled), with response via an API token. Supported names include Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne, FortiGate, Palo Alto, Trend Vision One and Cisco Firepower.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;The Main Areas&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Incident Management&lt;/STRONG&gt; with an Incident List and an asset-centric Asset Incident Priority, shown as a Kanban board by status.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Alert Table&lt;/STRONG&gt; for visibility into every processed alert, its verdict and its justification.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Prevention Center&lt;/STRONG&gt; showing prevention status and the executions behind each action.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Assets&lt;/STRONG&gt; for a user and device centric view.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Threat Hunting&lt;/STRONG&gt; for advanced querying over forensic events from Endpoint and Quantum Gateway.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Events&lt;/STRONG&gt; for the raw logs, and &lt;STRONG&gt;Notifications&lt;/STRONG&gt; by email, Slack or Microsoft Teams when a new incident is created.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Licensing and Reach&lt;/H2&gt;
&lt;P&gt;Licensing has two dials worth knowing up front:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Connected product entitlement&lt;/STRONG&gt; is either &lt;STRONG&gt;Endpoint Security only&lt;/STRONG&gt;, where XDR operates as EDR, or &lt;STRONG&gt;All Products&lt;/STRONG&gt;, which lets any supported product connect.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Data processing entitlement&lt;/STRONG&gt; is per-user or by volume in GB, summed across active licenses.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Raw events are retained for 3 months by default, extendable to 6 or 12. XDR runs for tenants in the EU, US, India and UAE, with AI Copilot and Playblocks not available in India and the UAE. For interaction and automation there are the XDR/XPR API, the Threat Hunting API and the Infinity Events API.&lt;/P&gt;
&lt;H2&gt;Best Practices&lt;/H2&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; connect identity sources early, since mapping IPs to real users and devices is what makes correlation and UEBA actually useful.&lt;/P&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; start Policy Automation creating IoCs in the disabled state, review them, then move to enabled once you trust the confidence and severity thresholds.&lt;/P&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; match the XDR account region to the region your other Check Point products send data to, or the data will not line up.&lt;/P&gt;
&lt;H2&gt;Common Mistakes&lt;/H2&gt;
&lt;TABLE style="border-collapse: collapse;" border="1" cellpadding="8"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #d9e2f3;"&gt;
&lt;TD&gt;&lt;STRONG&gt;Mistake&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Impact&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Solution&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;Treating alerts and incidents as the same thing&lt;/TD&gt;
&lt;TD&gt;Analysts drown in alerts&lt;/TD&gt;
&lt;TD&gt;Work the prioritized incident list, use the Alert Table for audit&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Creating XDR in a different region than the products&lt;/TD&gt;
&lt;TD&gt;Data does not correlate&lt;/TD&gt;
&lt;TD&gt;Match the XDR region to the products' region&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Enabling automation straight to enabled IoCs&lt;/TD&gt;
&lt;TD&gt;Risk of auto-blocking on a weak verdict&lt;/TD&gt;
&lt;TD&gt;Create IoCs disabled first, review, then enable&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Expecting full XDR with an Endpoint-only license&lt;/TD&gt;
&lt;TD&gt;Only EDR scope is active&lt;/TD&gt;
&lt;TD&gt;Add an All Products license to connect more&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;H2&gt;FAQ&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Q: What is the difference between XDR and XPR?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;A: XDR is detection and response. XPR adds automated prevention, pushing enforcement out across connected products.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q: Does connecting Check Point products need extra setup?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;A: No. Endpoint, Quantum, Email and Mobile integrate without additional configuration.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q: What is the smallest unit I should work with?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;A: The incident. It is built from alerts and carries the assets, artifacts and indicators you act on.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q: How are responses shared across products?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;A: Through IoC Management. An IoC in an output feed is enforced by every product that consumes it.&lt;/P&gt;
&lt;H2&gt;Related Articles&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.checkpoint.com/../32-xdr-xpr-in-practice/README.md" target="_blank"&gt;XDR/XPR in Practice: From Telemetry to Incident, and Back to an IOC&lt;/A&gt; (the API and automation view)&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;References&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;Check Point XDR Administration Guide: Introduction to Check Point XDR (Events/Alerts/Incidents, Alert Processing, Collaborative Enforcement, Product Integrations, Key Application Components, XDR Detections, Licensing, Data Retention, Supported Regions, API Support)&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Revision History&lt;/H2&gt;
&lt;TABLE style="border-collapse: collapse;" border="1" cellpadding="8"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #d9e2f3;"&gt;
&lt;TD&gt;&lt;STRONG&gt;Date&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Version&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Author&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Changes&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;2026-10-07&lt;/TD&gt;
&lt;TD&gt;1.0&lt;/TD&gt;
&lt;TD&gt;Jorge Luiz&lt;/TD&gt;
&lt;TD&gt;Initial overview from the XDR Administration Guide&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;HR /&gt;&lt;HR /&gt;
&lt;P&gt;&lt;STRONG&gt;Supported Versions:&lt;/STRONG&gt; Check Point XDR/XPR (cloud, Infinity Portal)&lt;BR /&gt;&lt;STRONG&gt;Last Updated:&lt;/STRONG&gt; 2026-10-07&lt;/P&gt;</description>
    <pubDate>Wed, 07 Oct 2026 12:55:51 GMT</pubDate>
    <dc:creator>jorgeluiznim</dc:creator>
    <dc:date>2026-10-07T12:55:51Z</dc:date>
    <item>
      <title>[EN] Check Point XDR/XPR: An Overview of Extended Detection and Prevention</title>
      <link>https://community.checkpoint.com/t5/XDR/EN-Check-Point-XDR-XPR-An-Overview-of-Extended-Detection-and/m-p/283350#M52</link>
      <description>&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Scope note:&lt;/STRONG&gt; Check Point XDR (formerly Infinity XDR/XPR) is a cloud service in the Check Point Infinity Portal. This overview is written from the official Check Point XDR Administration Guide.&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Purpose&lt;/H2&gt;
&lt;P&gt;Every product in the stack already raises its own alerts, and that is exactly the problem: too many alerts, no single story. XDR takes the events from all of them, correlates across products and time, and hands the analyst a short list of prioritized incidents with recommended actions, plus the ability to push a response back out to every connected product. This overview explains what XDR and XPR are, how an event becomes an incident, and how the enforcement loop closes.&lt;/P&gt;
&lt;H2&gt;Audience&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;[x] SOC Analysts&lt;/LI&gt;
&lt;LI&gt;[x] Security Engineers&lt;/LI&gt;
&lt;LI&gt;[x] Incident Responders&lt;/LI&gt;
&lt;LI&gt;[x] Beginners&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;What It Is&lt;/H2&gt;
&lt;P&gt;Check Point XDR is an &lt;STRONG&gt;Extended Detection Response (XDR)&lt;/STRONG&gt; and &lt;STRONG&gt;Extended Prevention Response (XPR)&lt;/STRONG&gt; tool. It gives a unified view across onboarded products and helps you detect, respond to, and prevent attacks. Three benefits define it:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Operator efficiency.&lt;/STRONG&gt; It processes large volumes of events and alerts into a small, prioritized set of incidents that actually need attention.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Unique detections.&lt;/STRONG&gt; With a view across the network and over time, it uses AI, ML and correlation to find threats that no single product would catch on its own, including Correlation and User and Entity Behavior Analytics (UEBA).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Collaborative enforcement.&lt;/STRONG&gt; It coordinates and automates response across every connected product, using Indicators of Compromise (IoCs) as the shared currency.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The difference between XDR and XPR is the verb: XDR detects and responds, XPR adds the automated prevention.&lt;/P&gt;
&lt;H2&gt;Events, Alerts and Incidents&lt;/H2&gt;
&lt;P&gt;The whole model is a funnel of three levels, and keeping them straight is the key to using XDR:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Events (logs)&lt;/STRONG&gt; are records of normal or noteworthy activity, such as a login or a file access. Most are benign, and they are the raw material.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Alerts&lt;/STRONG&gt; are notifications raised when a rule or an AI model sees something worth attention. Not every alert is a real problem, but each warrants a look.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Incidents&lt;/STRONG&gt; are confirmed or suspected threats that need containment and resolution. An incident is built from one or more alerts and is the primary unit the analyst works with: assign it, comment on it, and close it with a status.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="background-color: #fff3cd; padding: 10px;"&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="diag1-events-to-incident.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35492i07BBF49C442E3013/image-size/large?v=v2&amp;amp;px=999" role="button" title="diag1-events-to-incident.png" alt="diag1-events-to-incident.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Each incident is built from &lt;STRONG&gt;Assets&lt;/STRONG&gt; (the users and devices at stake), &lt;STRONG&gt;Artifacts&lt;/STRONG&gt; (evidence like files, processes, IPs, URLs) and &lt;STRONG&gt;Indicators&lt;/STRONG&gt; (the artifacts that signal a real threat).&lt;/P&gt;
&lt;H2&gt;How an Alert Becomes an Incident&lt;/H2&gt;
&lt;P&gt;Alerts, whether they come from a connected product or from XDR's own AI and UEBA, go through four steps:&lt;/P&gt;
&lt;P&gt;1. &lt;STRONG&gt;Grouping&lt;/STRONG&gt; collapses near-identical alerts that differ only by time.&lt;/P&gt;
&lt;P&gt;2. &lt;STRONG&gt;Enrichment&lt;/STRONG&gt; adds context and threat intelligence, such as geolocation and reputation.&lt;/P&gt;
&lt;P&gt;3. &lt;STRONG&gt;Validation&lt;/STRONG&gt; scores the alert and its indicators and assigns a verdict with a short justification.&lt;/P&gt;
&lt;P&gt;4. &lt;STRONG&gt;Correlation&lt;/STRONG&gt; stitches alerts together across products when they share a user, an IP or another common component, turning scattered signals into one incident.&lt;/P&gt;
&lt;P&gt;Each alert carries an Action status of &lt;STRONG&gt;Detected&lt;/STRONG&gt; or &lt;STRONG&gt;Blocked&lt;/STRONG&gt;, and each incident carries a Prevented status of &lt;STRONG&gt;Detected&lt;/STRONG&gt; (Action Required) or &lt;STRONG&gt;Prevented&lt;/STRONG&gt; (blocked and the source addressed).&lt;/P&gt;
&lt;H2&gt;Collaborative Enforcement: the Closed Loop&lt;/H2&gt;
&lt;P&gt;Detection is half the value. The other half is pushing a response back out:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;IoC Management&lt;/STRONG&gt; is a central platform that collects IoCs through feeds (manual or live) and publishes output feeds that other products consume. When the same IoC appears in multiple feeds, feed priority resolves the conflict. A built-in &lt;STRONG&gt;XDR Feed&lt;/STRONG&gt; holds IoCs created inside XDR.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Policy Automation&lt;/STRONG&gt; can, when an incident meets a chosen confidence and severity, automatically add indicators to IoC Management, either disabled for review or enabled immediately.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;An IoC blocked here is blocked everywhere that consumes the feed, which is what makes the response collaborative rather than product-by-product.&lt;/P&gt;
&lt;P style="background-color: #fff3cd; padding: 10px;"&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="diag2-collaborative-enforcement.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35493iBE5023B0265BED18/image-size/large?v=v2&amp;amp;px=999" role="button" title="diag2-collaborative-enforcement.png" alt="diag2-collaborative-enforcement.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;What Connects to It&lt;/H2&gt;
&lt;P&gt;XDR widens its view through three integration types, each with log, response and IoC aspects:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Check Point products&lt;/STRONG&gt; integrate with no extra configuration: Endpoint Security (EPMaaS), Quantum Security Gateway and Cloud Firewall, Email Security, and Mobile Security.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Identity sources&lt;/STRONG&gt; (Active Directory, Okta, the Endpoint Identity Connector) enrich alerts with device and user names and enable login-anomaly detection.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Third-party products&lt;/STRONG&gt; connect by Syslog (pushed) or API (pulled), with response via an API token. Supported names include Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne, FortiGate, Palo Alto, Trend Vision One and Cisco Firepower.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;The Main Areas&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Incident Management&lt;/STRONG&gt; with an Incident List and an asset-centric Asset Incident Priority, shown as a Kanban board by status.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Alert Table&lt;/STRONG&gt; for visibility into every processed alert, its verdict and its justification.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Prevention Center&lt;/STRONG&gt; showing prevention status and the executions behind each action.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Assets&lt;/STRONG&gt; for a user and device centric view.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Threat Hunting&lt;/STRONG&gt; for advanced querying over forensic events from Endpoint and Quantum Gateway.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Events&lt;/STRONG&gt; for the raw logs, and &lt;STRONG&gt;Notifications&lt;/STRONG&gt; by email, Slack or Microsoft Teams when a new incident is created.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Licensing and Reach&lt;/H2&gt;
&lt;P&gt;Licensing has two dials worth knowing up front:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Connected product entitlement&lt;/STRONG&gt; is either &lt;STRONG&gt;Endpoint Security only&lt;/STRONG&gt;, where XDR operates as EDR, or &lt;STRONG&gt;All Products&lt;/STRONG&gt;, which lets any supported product connect.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Data processing entitlement&lt;/STRONG&gt; is per-user or by volume in GB, summed across active licenses.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Raw events are retained for 3 months by default, extendable to 6 or 12. XDR runs for tenants in the EU, US, India and UAE, with AI Copilot and Playblocks not available in India and the UAE. For interaction and automation there are the XDR/XPR API, the Threat Hunting API and the Infinity Events API.&lt;/P&gt;
&lt;H2&gt;Best Practices&lt;/H2&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; connect identity sources early, since mapping IPs to real users and devices is what makes correlation and UEBA actually useful.&lt;/P&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; start Policy Automation creating IoCs in the disabled state, review them, then move to enabled once you trust the confidence and severity thresholds.&lt;/P&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; match the XDR account region to the region your other Check Point products send data to, or the data will not line up.&lt;/P&gt;
&lt;H2&gt;Common Mistakes&lt;/H2&gt;
&lt;TABLE style="border-collapse: collapse;" border="1" cellpadding="8"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #d9e2f3;"&gt;
&lt;TD&gt;&lt;STRONG&gt;Mistake&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Impact&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Solution&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;Treating alerts and incidents as the same thing&lt;/TD&gt;
&lt;TD&gt;Analysts drown in alerts&lt;/TD&gt;
&lt;TD&gt;Work the prioritized incident list, use the Alert Table for audit&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Creating XDR in a different region than the products&lt;/TD&gt;
&lt;TD&gt;Data does not correlate&lt;/TD&gt;
&lt;TD&gt;Match the XDR region to the products' region&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Enabling automation straight to enabled IoCs&lt;/TD&gt;
&lt;TD&gt;Risk of auto-blocking on a weak verdict&lt;/TD&gt;
&lt;TD&gt;Create IoCs disabled first, review, then enable&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Expecting full XDR with an Endpoint-only license&lt;/TD&gt;
&lt;TD&gt;Only EDR scope is active&lt;/TD&gt;
&lt;TD&gt;Add an All Products license to connect more&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;H2&gt;FAQ&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Q: What is the difference between XDR and XPR?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;A: XDR is detection and response. XPR adds automated prevention, pushing enforcement out across connected products.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q: Does connecting Check Point products need extra setup?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;A: No. Endpoint, Quantum, Email and Mobile integrate without additional configuration.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q: What is the smallest unit I should work with?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;A: The incident. It is built from alerts and carries the assets, artifacts and indicators you act on.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q: How are responses shared across products?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;A: Through IoC Management. An IoC in an output feed is enforced by every product that consumes it.&lt;/P&gt;
&lt;H2&gt;Related Articles&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.checkpoint.com/../32-xdr-xpr-in-practice/README.md" target="_blank"&gt;XDR/XPR in Practice: From Telemetry to Incident, and Back to an IOC&lt;/A&gt; (the API and automation view)&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;References&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;Check Point XDR Administration Guide: Introduction to Check Point XDR (Events/Alerts/Incidents, Alert Processing, Collaborative Enforcement, Product Integrations, Key Application Components, XDR Detections, Licensing, Data Retention, Supported Regions, API Support)&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Revision History&lt;/H2&gt;
&lt;TABLE style="border-collapse: collapse;" border="1" cellpadding="8"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #d9e2f3;"&gt;
&lt;TD&gt;&lt;STRONG&gt;Date&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Version&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Author&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Changes&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;2026-10-07&lt;/TD&gt;
&lt;TD&gt;1.0&lt;/TD&gt;
&lt;TD&gt;Jorge Luiz&lt;/TD&gt;
&lt;TD&gt;Initial overview from the XDR Administration Guide&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;HR /&gt;&lt;HR /&gt;
&lt;P&gt;&lt;STRONG&gt;Supported Versions:&lt;/STRONG&gt; Check Point XDR/XPR (cloud, Infinity Portal)&lt;BR /&gt;&lt;STRONG&gt;Last Updated:&lt;/STRONG&gt; 2026-10-07&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2026 12:55:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/XDR/EN-Check-Point-XDR-XPR-An-Overview-of-Extended-Detection-and/m-p/283350#M52</guid>
      <dc:creator>jorgeluiznim</dc:creator>
      <dc:date>2026-10-07T12:55:51Z</dc:date>
    </item>
  </channel>
</rss>

