- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I worked with Checkpoint security gateways for quite a few years and the technical documentation is usually quite complete (especially thanks to the ATRG pages), however I recently started setting up Sandblast agents for a client and I find the documentation very lacking, it is mostly a "black box" and the documentation tells you it will protect against this threat but without any technical details on how it will do it.
For example if I take the anti-ransomware feature I cannot find the following information:
This is only for anti-ransomware but I can give a similar list for nearly every sandblast feature.
Did I miss an ATRG or SK for all this somewhere ?
Thanks
There is a lot of documention and SKs for SandBlast already, so we have a lot to study already
! But your question:
I see in the documentation that the agent is supposed to create some random files in My Documents, etc. I cannot find these files however I see folders such as "CheckPoint!FrameworkDirectoryDon'tDiscard" and "Sandblast Zero-Day-SystemFolder-Do notDiscard" but again no information on what they are
for me seem not relevant at all - the random files are in the folders you see, but how could information on "what they are" help you in any way ?
If you need these answer to make customer(s) happy, you can always involve TAC and ask for information.
Günther W. Albrecht wrote:
the random files are in the folders you see
If that's the case the admin guide (page 187) is both wrong about the file names and the file locations:

Günther W. Albrecht wrote:
but how could information on "what they are" help you in any way ?
I assumed the documentation is correct and they were not anti-ransomware files, in that case yes I want to know and the client will ask what are these files in their My Documents.
Günther W. Albrecht wrote:
If you need these answer to make customer(s) happy, you can always involve TAC and ask for information.
I don't see how "opening a ticket to understand their product" is a good documentation strategy for CheckPoint.
The main thing for me is that on Gateway side the documentation is usually quite good so I would just expect the same level for Endpoints.
For my understanding, you are looking for tech reference, not an admin guide, correct?
I would indeed love a tech reference on Sandblast agent the same way and level of details there is ATRG for ClusterXL or CoreXL.
But I even believe some of these questions and other should actually be in the admin guide as they are quite "basic" and quite important for the administration of the product (which is what an admin guide should be about isn't it
).
Let me see if I can answer the questions you've asked:
How does the agent decides which file to backup
Any file modified by a user gets backed up.
You can exclude certain directories if you prefer.
Are the files backed up when accessed by a process (does that mean the process have to wait the backup is completed before running) or is the agent actively looking for these files (and if so how - only local or also remote on file servers?)
As stated above, files that get modified get backed up.
I believe that also includes remote fileshares as well.
- How long is each file kept in the backup
- I can configure a backup size limit in the Endpoint Management but what happens when the client reaches the limit (I assume some files will be deleted, but which one)
Think of it as a first in, first-out buffer.
I see in the documentation that the agent is supposed to create some random files in My Documents, etc. I cannot find these files however I see folders such as "CheckPoint!FrameworkDirectoryDon'tDiscard" and "Sandblast Zero-Day-SystemFolder-Do notDiscard" but again no information on what they are
I assume these exist for similar reasons to the ones documented above, but will admit I don't know exactly what these folders are for.
How is the anti-ransomware agent "constantly monitoring suspicious activities", I understand for this one that details might be restricted to not have other vendors copying it but at least some high level description would be useful
Basically anything that would be inconsistent with normal user activity is flagged.
Modifying a large number of files at once is certainly suspicious, as is modifying our random files.
Thanks a lot Dameon that's useful.
If I may ask two more questions on the other modules of Sandblast
:
Threat Emulation is specifically looking at files downloaded, not necessarily existing files on the PC.
Zero Phishing is looking for a combination of:
My guess is based on IP/Domain Reputation or use of multiple TLDs, it could still find phishing sites.
Regardless, if corporate credentials are used on the site, it would block it (since presumably the phishing site would be outside your domain).
Unless I'm mistaken Threat Emulation on Sandblast Agent also looks for files on the PC, what is called "File System Emulation" in the admin guide / Endpoint console. However I think this answer was actually in the admin guide
, as it says "Emulate files written to file system".
Thank you for your answer regarding zero phishing.
There are a few different components to SandBlast, and yes I missed the SBA-specific functionality (versus the browser plugin) ![]()
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY