<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Playblocks Highlights: IOC Enforcement Connector - Why You Should Enable It ⚡ in Playblocks</title>
    <link>https://community.checkpoint.com/t5/Playblocks/Playblocks-Highlights-IOC-Enforcement-Connector-Why-You-Should/m-p/258996#M71</link>
    <description>&lt;H1 class="p1"&gt;&lt;FONT color="#000000"&gt;Playblocks Highlights: IOC Enforcement Connector - Why You Should Enable It &lt;span class="lia-unicode-emoji" title=":high_voltage:"&gt;⚡&lt;/span&gt;&lt;/FONT&gt;&lt;/H1&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;Hey CheckMates! &lt;span class="lia-unicode-emoji" title=":direct_hit:"&gt;🎯&lt;/span&gt;&lt;/P&gt;
&lt;P class="p1"&gt;In this edition of &lt;STRONG&gt;Playblocks Highlights&lt;/STRONG&gt;, we’re diving deep into the &lt;STRONG&gt;IOC Enforcement connector&lt;/STRONG&gt; - how it links your threat detection to prevention, the enforcement options, and some powerful automations you can enable right away.&lt;/P&gt;
&lt;P class="p1"&gt;&lt;span class="lia-unicode-emoji" title=":locked_with_key:"&gt;🔐&lt;/span&gt; &lt;STRONG&gt;IOC Enforcement bridges detection and enforcement.&lt;/STRONG&gt; Instead of just adding IOCs to a list, this connector ensures they are automatically enforced across supported platforms.&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 class="p1"&gt;&lt;STRONG&gt;What is the IOC Enforcement Connector?&lt;/STRONG&gt;&lt;/H4&gt;
&lt;UL class="ul1"&gt;
&lt;LI class="li1"&gt;The IOC Enforcement connector &lt;STRONG&gt;synchronizes Infinity Playblocks with your enforcement platforms&lt;/STRONG&gt;, ensuring that indicators detected (by automations or manually) are pushed out to your security products.&lt;/LI&gt;
&lt;LI class="li1"&gt;When enabled, a new list called &lt;STRONG&gt;Playblocks IOCs&lt;/STRONG&gt; is created and synced with the Infinity IOC Management feed. New indicators (from Playblocks automations or manual additions) flow into that feed and are distributed.&lt;/LI&gt;
&lt;LI class="li1"&gt;It replaces the manual, error-prone process of creating indicator objects in each product. With the connector on, your infrastructures automatically &lt;STRONG&gt;fetch and enforce&lt;/STRONG&gt; the indicators.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Tal_Ben_Bassat_0-1759592463146.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31620i608D1D25437A901A/image-size/large?v=v2&amp;amp;px=999" role="button" title="Tal_Ben_Bassat_0-1759592463146.png" alt="Tal_Ben_Bassat_0-1759592463146.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 class="p1"&gt;&lt;STRONG&gt;Enforcement Options &amp;amp; Platforms&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P class="p1"&gt;When configuring the connector, you decide which platforms should enforce the IOCs:&lt;/P&gt;
&lt;UL class="ul1"&gt;
&lt;LI class="li1"&gt;&lt;STRONG&gt;Quantum IOC Enforcement&lt;/STRONG&gt;&lt;/LI&gt;
&lt;UL class="ul1"&gt;
&lt;LI class="li1"&gt;&lt;SPAN class="s2"&gt;Y&lt;/SPAN&gt;ou can enable enforcement on &lt;STRONG&gt;all Quantum Managements&lt;/STRONG&gt; or pick specific ones.&lt;/LI&gt;
&lt;LI class="li1"&gt;Once enabled, any gateway under those managements with Anti-Bot or Anti-Virus blades will start enforcing the IOCs upon policy push.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;CrowdStrike IOC Enforcement&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL class="ul1"&gt;
&lt;UL class="ul1"&gt;
&lt;LI class="li1"&gt;Requires that the &lt;STRONG&gt;CrowdStrike connector&lt;/STRONG&gt; is already enabled.&lt;/LI&gt;
&lt;LI class="li1"&gt;Hash indicators (e.g. MD5, SHA256) are added with &lt;STRONG&gt;Prevent&lt;/STRONG&gt; actions; IP indicators are added with &lt;STRONG&gt;Detect&lt;/STRONG&gt; actions (since CrowdStrike does not support IP prevention).&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;SentinelOne IOC Enforcement&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL class="ul1"&gt;
&lt;UL class="ul1"&gt;
&lt;LI class="li1"&gt;Requires the &lt;STRONG&gt;SentinelOne connector&lt;/STRONG&gt; active.&lt;/LI&gt;
&lt;LI class="li1"&gt;SentinelOne enforces automatic expiration limits:&lt;/LI&gt;
&lt;UL class="ul1"&gt;
&lt;LI class="li1"&gt;IP indicators expire in 30 days&lt;/LI&gt;
&lt;LI class="li1"&gt;URLs, domains, and file hashes expire in 180 days&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft Defender IOC Enforcement&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL class="ul1"&gt;
&lt;UL class="ul1"&gt;
&lt;LI class="li1"&gt;Requires the &lt;STRONG&gt;Microsoft Defender connector&lt;/STRONG&gt; active.&lt;/LI&gt;
&lt;LI class="li1"&gt;Once enabled, new indicators flow into Defender’s IOC engine for enforcement.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Harmony Endpoint IOC Enforcement&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL class="ul1"&gt;
&lt;UL class="ul1"&gt;
&lt;LI class="li1"&gt;Requires Harmony Endpoint service and connector enabled.&lt;/LI&gt;
&lt;LI class="li1"&gt;Harmony Endpoint supports file hashes (MD5, SHA1), IPv4, URLs, and domains. It doesn’t expire IOCs automatically - but Playblocks periodically removes expired indicators from Harmony.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P class="p1"&gt;&lt;STRONG&gt;How to Enable &amp;amp; Configure&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL class="ol1"&gt;
&lt;OL class="ol1"&gt;
&lt;LI class="li1"&gt;In &lt;STRONG&gt;Playblocks → Connectors&lt;/STRONG&gt;, locate and enable &lt;STRONG&gt;IOC Enforcement&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI class="li1"&gt;Toggle on &lt;STRONG&gt;Quantum IOC Enforcement&lt;/STRONG&gt;, &lt;STRONG&gt;CrowdStrike IOC Enforcement&lt;/STRONG&gt;, &lt;STRONG&gt;SentinelOne IOC Enforcement&lt;/STRONG&gt;, &lt;STRONG&gt;Microsoft Defender IOC Enforcement&lt;/STRONG&gt;, and &lt;STRONG&gt;Harmony Endpoint IOC Enforcement&lt;/STRONG&gt; as required.&lt;/LI&gt;
&lt;LI class="li1"&gt;For Quantum, choose whether to apply enforcement to &lt;I&gt;all&lt;/I&gt; managements or select specific ones.&lt;/LI&gt;
&lt;LI class="li1"&gt;Save and install the updated Threat Prevention policy on the affected gateways.&lt;/LI&gt;
&lt;/OL&gt;
&lt;/OL&gt;
&lt;P class="p1"&gt;Once configured, existing indicators in the Playblocks feed are automatically synchronized into the enforcement platforms.&lt;/P&gt;
&lt;DIV id="tinyMceEditorTal_Ben_Bassat_3" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Tal_Ben_Bassat_0-1759592281231.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31617i9139FAEE67D36B66/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Tal_Ben_Bassat_0-1759592281231.png" alt="Tal_Ben_Bassat_0-1759592281231.png" /&gt;&lt;/span&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Tal_Ben_Bassat_2-1759592372805.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31622i1B71BE9E251B6BDC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Tal_Ben_Bassat_2-1759592372805.png" alt="Tal_Ben_Bassat_2-1759592372805.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 class="p1"&gt;&lt;STRONG&gt;Examples for predefined automations that use IOC Enforcement&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P class="p1"&gt;These predefined automations automatically add malicious files or URLs into the Playblocks IOC feed for enforcement:&lt;/P&gt;
&lt;TABLE class="t1" cellspacing="0" cellpadding="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;&lt;STRONG&gt;Automation&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;&lt;STRONG&gt;What It Does&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;&lt;STRONG&gt;Notes / Parameters&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;&lt;STRONG&gt;Block malicious file indicator identified by Threat Extraction (Harmony Endpoint)&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;Adds file indicators from Threat Extraction to the IOC feed and enforces them&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;Requires IOC Enforcement to propagate these indicators&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;&lt;STRONG&gt;Add malicious file indicator identified by CrowdStrike to IOC feed&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;Adds file hashes flagged by CrowdStrike into the IOC feed&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;Includes &lt;I&gt;Expiration in days&lt;/I&gt; parameter; ensures consistent blocking&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;&lt;STRONG&gt;Add malicious file indicator identified by Microsoft Defender to IOC feed&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;Adds file hash and source URL flagged by Defender into IOC feed&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;Shares Defender detections with your broader enforcement&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;&lt;STRONG&gt;Add malicious file indicator identified by SentinelOne to IOC feed&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;Adds file hash indicators flagged by SentinelOne into the IOC feed&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;Integrates SentinelOne detections across your stack&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;&lt;STRONG&gt;Block malicious indicator identified by Anti-Bot&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;Pushes malicious URLs detected by Anti-Bot into the IOC feed for automatic blocking&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;Great for reinforcing Quantum and Harmony layers&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;&lt;STRONG&gt;Block malicious indicator identified by Zero Phishing (Quantum)&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;Ingests malicious URL indicators flagged by Zero Phishing into the IOC feed for enforcement&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;Often paired with URL/domain blocking via Anti-Bot and AV blades&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;span class="lia-unicode-emoji" title=":light_bulb:"&gt;💡&lt;/span&gt; &lt;STRONG&gt;Pro Tip:&lt;/STRONG&gt; Filter the &lt;A href="https://portal.checkpoint.com/dashboard/playblocks#/automations" target="_blank" rel="noopener"&gt;&lt;SPAN class="s4"&gt;Automations page&lt;/SPAN&gt;&lt;/A&gt; by &lt;STRONG&gt;IOC Enforcement connector&lt;/STRONG&gt; to discover even more automations that add URLs and file indicators to your threat feed - &lt;STRONG&gt;there are many more to explore!&lt;/STRONG&gt;&lt;/P&gt;
&lt;H4 class="p1"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 class="p1"&gt;&lt;STRONG&gt;Why You Should Connect It Today&lt;/STRONG&gt;&lt;/H4&gt;
&lt;UL class="ul1"&gt;
&lt;UL class="ul1"&gt;
&lt;LI class="li1"&gt;&lt;STRONG&gt;Closes the loop:&lt;/STRONG&gt; Automatically turns threat detections into enforced protections.&lt;/LI&gt;
&lt;LI class="li1"&gt;&lt;STRONG&gt;Unified control:&lt;/STRONG&gt; Your entire stack - Quantum, Endpoint, Defender, and more - enforces IOCs consistently.&lt;/LI&gt;
&lt;LI class="li1"&gt;&lt;STRONG&gt;Hands-free scaling:&lt;/STRONG&gt; Once connected, every new indicator flows to all enabled products automatically.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;H4 class="p6"&gt;&lt;SPAN class="s5"&gt;&lt;span class="lia-unicode-emoji" title=":link:"&gt;🔗&lt;/span&gt; &lt;STRONG&gt;Connect now:&lt;/STRONG&gt; &lt;A href="https://portal.checkpoint.com/dashboard/playblocks#/connectors?selected=IOCEnforcement" target="_blank" rel="noopener"&gt;&lt;SPAN class="s6"&gt;Enable IOC Enforcement Connector&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;U&gt;&lt;STRONG&gt;Continue the Journey&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P class="p1"&gt;Did you miss our previous highlight on powerful Playblocks automations?&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":backhand_index_pointing_right:"&gt;👉&lt;/span&gt; &lt;A href="https://community.checkpoint.com/t5/Playblocks/Playblocks-Highlights-Powerful-Automations-You-Might-ve-Missed/m-p/258297#M69" target="_blank" rel="noopener"&gt;&lt;SPAN class="s4"&gt;Check out the first Playblocks Highlights post&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;span class="lia-unicode-emoji" title=":sparkles:"&gt;✨&lt;/span&gt; Stay tuned for the next &lt;STRONG&gt;Playblocks Highlights&lt;/STRONG&gt; - where we’ll keep uncovering connectors, automations, and AI-powered workflows that make security smarter and faster.&lt;/P&gt;</description>
    <pubDate>Tue, 07 Oct 2025 16:14:48 GMT</pubDate>
    <dc:creator>Tal_Ben_Bassat</dc:creator>
    <dc:date>2025-10-07T16:14:48Z</dc:date>
    <item>
      <title>Playblocks Highlights: IOC Enforcement Connector - Why You Should Enable It ⚡</title>
      <link>https://community.checkpoint.com/t5/Playblocks/Playblocks-Highlights-IOC-Enforcement-Connector-Why-You-Should/m-p/258996#M71</link>
      <description>&lt;H1 class="p1"&gt;&lt;FONT color="#000000"&gt;Playblocks Highlights: IOC Enforcement Connector - Why You Should Enable It &lt;span class="lia-unicode-emoji" title=":high_voltage:"&gt;⚡&lt;/span&gt;&lt;/FONT&gt;&lt;/H1&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;Hey CheckMates! &lt;span class="lia-unicode-emoji" title=":direct_hit:"&gt;🎯&lt;/span&gt;&lt;/P&gt;
&lt;P class="p1"&gt;In this edition of &lt;STRONG&gt;Playblocks Highlights&lt;/STRONG&gt;, we’re diving deep into the &lt;STRONG&gt;IOC Enforcement connector&lt;/STRONG&gt; - how it links your threat detection to prevention, the enforcement options, and some powerful automations you can enable right away.&lt;/P&gt;
&lt;P class="p1"&gt;&lt;span class="lia-unicode-emoji" title=":locked_with_key:"&gt;🔐&lt;/span&gt; &lt;STRONG&gt;IOC Enforcement bridges detection and enforcement.&lt;/STRONG&gt; Instead of just adding IOCs to a list, this connector ensures they are automatically enforced across supported platforms.&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 class="p1"&gt;&lt;STRONG&gt;What is the IOC Enforcement Connector?&lt;/STRONG&gt;&lt;/H4&gt;
&lt;UL class="ul1"&gt;
&lt;LI class="li1"&gt;The IOC Enforcement connector &lt;STRONG&gt;synchronizes Infinity Playblocks with your enforcement platforms&lt;/STRONG&gt;, ensuring that indicators detected (by automations or manually) are pushed out to your security products.&lt;/LI&gt;
&lt;LI class="li1"&gt;When enabled, a new list called &lt;STRONG&gt;Playblocks IOCs&lt;/STRONG&gt; is created and synced with the Infinity IOC Management feed. New indicators (from Playblocks automations or manual additions) flow into that feed and are distributed.&lt;/LI&gt;
&lt;LI class="li1"&gt;It replaces the manual, error-prone process of creating indicator objects in each product. With the connector on, your infrastructures automatically &lt;STRONG&gt;fetch and enforce&lt;/STRONG&gt; the indicators.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Tal_Ben_Bassat_0-1759592463146.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31620i608D1D25437A901A/image-size/large?v=v2&amp;amp;px=999" role="button" title="Tal_Ben_Bassat_0-1759592463146.png" alt="Tal_Ben_Bassat_0-1759592463146.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 class="p1"&gt;&lt;STRONG&gt;Enforcement Options &amp;amp; Platforms&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P class="p1"&gt;When configuring the connector, you decide which platforms should enforce the IOCs:&lt;/P&gt;
&lt;UL class="ul1"&gt;
&lt;LI class="li1"&gt;&lt;STRONG&gt;Quantum IOC Enforcement&lt;/STRONG&gt;&lt;/LI&gt;
&lt;UL class="ul1"&gt;
&lt;LI class="li1"&gt;&lt;SPAN class="s2"&gt;Y&lt;/SPAN&gt;ou can enable enforcement on &lt;STRONG&gt;all Quantum Managements&lt;/STRONG&gt; or pick specific ones.&lt;/LI&gt;
&lt;LI class="li1"&gt;Once enabled, any gateway under those managements with Anti-Bot or Anti-Virus blades will start enforcing the IOCs upon policy push.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;CrowdStrike IOC Enforcement&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL class="ul1"&gt;
&lt;UL class="ul1"&gt;
&lt;LI class="li1"&gt;Requires that the &lt;STRONG&gt;CrowdStrike connector&lt;/STRONG&gt; is already enabled.&lt;/LI&gt;
&lt;LI class="li1"&gt;Hash indicators (e.g. MD5, SHA256) are added with &lt;STRONG&gt;Prevent&lt;/STRONG&gt; actions; IP indicators are added with &lt;STRONG&gt;Detect&lt;/STRONG&gt; actions (since CrowdStrike does not support IP prevention).&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;SentinelOne IOC Enforcement&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL class="ul1"&gt;
&lt;UL class="ul1"&gt;
&lt;LI class="li1"&gt;Requires the &lt;STRONG&gt;SentinelOne connector&lt;/STRONG&gt; active.&lt;/LI&gt;
&lt;LI class="li1"&gt;SentinelOne enforces automatic expiration limits:&lt;/LI&gt;
&lt;UL class="ul1"&gt;
&lt;LI class="li1"&gt;IP indicators expire in 30 days&lt;/LI&gt;
&lt;LI class="li1"&gt;URLs, domains, and file hashes expire in 180 days&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft Defender IOC Enforcement&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL class="ul1"&gt;
&lt;UL class="ul1"&gt;
&lt;LI class="li1"&gt;Requires the &lt;STRONG&gt;Microsoft Defender connector&lt;/STRONG&gt; active.&lt;/LI&gt;
&lt;LI class="li1"&gt;Once enabled, new indicators flow into Defender’s IOC engine for enforcement.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Harmony Endpoint IOC Enforcement&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL class="ul1"&gt;
&lt;UL class="ul1"&gt;
&lt;LI class="li1"&gt;Requires Harmony Endpoint service and connector enabled.&lt;/LI&gt;
&lt;LI class="li1"&gt;Harmony Endpoint supports file hashes (MD5, SHA1), IPv4, URLs, and domains. It doesn’t expire IOCs automatically - but Playblocks periodically removes expired indicators from Harmony.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P class="p1"&gt;&lt;STRONG&gt;How to Enable &amp;amp; Configure&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL class="ol1"&gt;
&lt;OL class="ol1"&gt;
&lt;LI class="li1"&gt;In &lt;STRONG&gt;Playblocks → Connectors&lt;/STRONG&gt;, locate and enable &lt;STRONG&gt;IOC Enforcement&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI class="li1"&gt;Toggle on &lt;STRONG&gt;Quantum IOC Enforcement&lt;/STRONG&gt;, &lt;STRONG&gt;CrowdStrike IOC Enforcement&lt;/STRONG&gt;, &lt;STRONG&gt;SentinelOne IOC Enforcement&lt;/STRONG&gt;, &lt;STRONG&gt;Microsoft Defender IOC Enforcement&lt;/STRONG&gt;, and &lt;STRONG&gt;Harmony Endpoint IOC Enforcement&lt;/STRONG&gt; as required.&lt;/LI&gt;
&lt;LI class="li1"&gt;For Quantum, choose whether to apply enforcement to &lt;I&gt;all&lt;/I&gt; managements or select specific ones.&lt;/LI&gt;
&lt;LI class="li1"&gt;Save and install the updated Threat Prevention policy on the affected gateways.&lt;/LI&gt;
&lt;/OL&gt;
&lt;/OL&gt;
&lt;P class="p1"&gt;Once configured, existing indicators in the Playblocks feed are automatically synchronized into the enforcement platforms.&lt;/P&gt;
&lt;DIV id="tinyMceEditorTal_Ben_Bassat_3" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Tal_Ben_Bassat_0-1759592281231.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31617i9139FAEE67D36B66/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Tal_Ben_Bassat_0-1759592281231.png" alt="Tal_Ben_Bassat_0-1759592281231.png" /&gt;&lt;/span&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Tal_Ben_Bassat_2-1759592372805.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31622i1B71BE9E251B6BDC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Tal_Ben_Bassat_2-1759592372805.png" alt="Tal_Ben_Bassat_2-1759592372805.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 class="p1"&gt;&lt;STRONG&gt;Examples for predefined automations that use IOC Enforcement&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P class="p1"&gt;These predefined automations automatically add malicious files or URLs into the Playblocks IOC feed for enforcement:&lt;/P&gt;
&lt;TABLE class="t1" cellspacing="0" cellpadding="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;&lt;STRONG&gt;Automation&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;&lt;STRONG&gt;What It Does&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;&lt;STRONG&gt;Notes / Parameters&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;&lt;STRONG&gt;Block malicious file indicator identified by Threat Extraction (Harmony Endpoint)&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;Adds file indicators from Threat Extraction to the IOC feed and enforces them&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;Requires IOC Enforcement to propagate these indicators&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;&lt;STRONG&gt;Add malicious file indicator identified by CrowdStrike to IOC feed&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;Adds file hashes flagged by CrowdStrike into the IOC feed&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;Includes &lt;I&gt;Expiration in days&lt;/I&gt; parameter; ensures consistent blocking&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;&lt;STRONG&gt;Add malicious file indicator identified by Microsoft Defender to IOC feed&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;Adds file hash and source URL flagged by Defender into IOC feed&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;Shares Defender detections with your broader enforcement&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;&lt;STRONG&gt;Add malicious file indicator identified by SentinelOne to IOC feed&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;Adds file hash indicators flagged by SentinelOne into the IOC feed&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;Integrates SentinelOne detections across your stack&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;&lt;STRONG&gt;Block malicious indicator identified by Anti-Bot&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;Pushes malicious URLs detected by Anti-Bot into the IOC feed for automatic blocking&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;Great for reinforcing Quantum and Harmony layers&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;&lt;STRONG&gt;Block malicious indicator identified by Zero Phishing (Quantum)&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;Ingests malicious URL indicators flagged by Zero Phishing into the IOC feed for enforcement&lt;/P&gt;
&lt;/TD&gt;
&lt;TD valign="top" class="td1"&gt;
&lt;P class="p1"&gt;Often paired with URL/domain blocking via Anti-Bot and AV blades&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;span class="lia-unicode-emoji" title=":light_bulb:"&gt;💡&lt;/span&gt; &lt;STRONG&gt;Pro Tip:&lt;/STRONG&gt; Filter the &lt;A href="https://portal.checkpoint.com/dashboard/playblocks#/automations" target="_blank" rel="noopener"&gt;&lt;SPAN class="s4"&gt;Automations page&lt;/SPAN&gt;&lt;/A&gt; by &lt;STRONG&gt;IOC Enforcement connector&lt;/STRONG&gt; to discover even more automations that add URLs and file indicators to your threat feed - &lt;STRONG&gt;there are many more to explore!&lt;/STRONG&gt;&lt;/P&gt;
&lt;H4 class="p1"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 class="p1"&gt;&lt;STRONG&gt;Why You Should Connect It Today&lt;/STRONG&gt;&lt;/H4&gt;
&lt;UL class="ul1"&gt;
&lt;UL class="ul1"&gt;
&lt;LI class="li1"&gt;&lt;STRONG&gt;Closes the loop:&lt;/STRONG&gt; Automatically turns threat detections into enforced protections.&lt;/LI&gt;
&lt;LI class="li1"&gt;&lt;STRONG&gt;Unified control:&lt;/STRONG&gt; Your entire stack - Quantum, Endpoint, Defender, and more - enforces IOCs consistently.&lt;/LI&gt;
&lt;LI class="li1"&gt;&lt;STRONG&gt;Hands-free scaling:&lt;/STRONG&gt; Once connected, every new indicator flows to all enabled products automatically.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;H4 class="p6"&gt;&lt;SPAN class="s5"&gt;&lt;span class="lia-unicode-emoji" title=":link:"&gt;🔗&lt;/span&gt; &lt;STRONG&gt;Connect now:&lt;/STRONG&gt; &lt;A href="https://portal.checkpoint.com/dashboard/playblocks#/connectors?selected=IOCEnforcement" target="_blank" rel="noopener"&gt;&lt;SPAN class="s6"&gt;Enable IOC Enforcement Connector&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;U&gt;&lt;STRONG&gt;Continue the Journey&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P class="p1"&gt;Did you miss our previous highlight on powerful Playblocks automations?&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":backhand_index_pointing_right:"&gt;👉&lt;/span&gt; &lt;A href="https://community.checkpoint.com/t5/Playblocks/Playblocks-Highlights-Powerful-Automations-You-Might-ve-Missed/m-p/258297#M69" target="_blank" rel="noopener"&gt;&lt;SPAN class="s4"&gt;Check out the first Playblocks Highlights post&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;span class="lia-unicode-emoji" title=":sparkles:"&gt;✨&lt;/span&gt; Stay tuned for the next &lt;STRONG&gt;Playblocks Highlights&lt;/STRONG&gt; - where we’ll keep uncovering connectors, automations, and AI-powered workflows that make security smarter and faster.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2025 16:14:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Playblocks/Playblocks-Highlights-IOC-Enforcement-Connector-Why-You-Should/m-p/258996#M71</guid>
      <dc:creator>Tal_Ben_Bassat</dc:creator>
      <dc:date>2025-10-07T16:14:48Z</dc:date>
    </item>
    <item>
      <title>Re: Playblocks Highlights: IOC Enforcement Connector - Why You Should Enable It ⚡</title>
      <link>https://community.checkpoint.com/t5/Playblocks/Playblocks-Highlights-IOC-Enforcement-Connector-Why-You-Should/m-p/259005#M72</link>
      <description>&lt;P&gt;Great!&lt;/P&gt;</description>
      <pubDate>Sat, 04 Oct 2025 16:03:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Playblocks/Playblocks-Highlights-IOC-Enforcement-Connector-Why-You-Should/m-p/259005#M72</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-04T16:03:02Z</dc:date>
    </item>
    <item>
      <title>Re: Playblocks Highlights: IOC Enforcement Connector - Why You Should Enable It ⚡</title>
      <link>https://community.checkpoint.com/t5/Playblocks/Playblocks-Highlights-IOC-Enforcement-Connector-Why-You-Should/m-p/259093#M73</link>
      <description>&lt;P&gt;Great article,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/39167"&gt;@Tal_Ben_Bassat&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Oct 2025 10:45:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Playblocks/Playblocks-Highlights-IOC-Enforcement-Connector-Why-You-Should/m-p/259093#M73</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-10-06T10:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: Playblocks Highlights: IOC Enforcement Connector - Why You Should Enable It ⚡</title>
      <link>https://community.checkpoint.com/t5/Playblocks/Playblocks-Highlights-IOC-Enforcement-Connector-Why-You-Should/m-p/259434#M74</link>
      <description>&lt;P&gt;You rock! So great achievements! Congrats to all the team for these continuous efforts.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Oct 2025 13:19:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Playblocks/Playblocks-Highlights-IOC-Enforcement-Connector-Why-You-Should/m-p/259434#M74</guid>
      <dc:creator>XavierBens</dc:creator>
      <dc:date>2025-10-08T13:19:19Z</dc:date>
    </item>
  </channel>
</rss>

