- CheckMates
- :
- Products
- :
- Developers
- :
- API / CLI Discussion
- :
- API for ThreatCloud
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
API for ThreatCloud
Hi Guys,
I have some questions on ThreatCloud API,
1. Do we have a public API that we can use to connect Threat Cloud ? The idea is to get Threat feeds into our local application/threat DB.
2. Is it possible to send data back into Threat cloud from our local threat application / DB ?
Or is ThreatCloud limited to only CP products ?
Thanks in advance!
Best regards
Srini
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Srini,
There is a Threat Cloud API offering that lets you send files to Threat Cloud via API calls without having to use a CP appliance. It doesn't give you a local copy of the feeds but we have customers integrating the TE API into web applications to scan files from customers for threats and to perform threat extraction too. It contributes to Threat Cloud by providing an unknown file to run through threat emulation and any malicious behaviours detected will generate signatures - but you can't upload your own IOCs. I believe you would need an appliance (physical or virtual) to be able to apply your own IOCs to scans.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
HI Stuart,
Thank you for your response,
Is the below link the one you are referring to ?
Best regards
Srini
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
close, that's the API to use if you had a CP gateway to send the requests to. The TP API is actually linked in the guide though - https://sc1.checkpoint.com/documents/TPAPI/CP_1.0_ThreatPreventionAPI_APIRefGuide/html_frameset.htm
They're both quite similar to use but one goes directly to Threat Cloud instead of via a gateway.
