- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: How to check ThreatCloud URL Reputation?
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to check ThreatCloud URL Reputation?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
1. Create a .doc file containing the URL as a link.
2. Upload it for emulation at https://threatpoint.checkpoint.com/ThreatPortal/emulation
3. Check the report
A dedicated service for URL reputation check would be certainly much better.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Nice Tip!,
but it would definitely be great if Check Point enable a service to quickly validate the reputation assigned to an URL/domain/IP by ThreatCloud, especially for TS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Frank_Yao1, thank you for your response.
The two link you mentioned not currently show the URL Reputation that Check Point ThreathCloud defines or handles for a given URL/domain/IP in real time.
with https://threatpoint.checkpoint.com/ThreatPortal/emulation you need to upload a file and with https://www.checkpoint.com/urlcat/main.htm you only get the categorization of a given domain/URL.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
1. Create a .doc file containing the URL as a link.
2. Upload it for emulation at https://threatpoint.checkpoint.com/ThreatPortal/emulation
3. Check the report
A dedicated service for URL reputation check would be certainly much better.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Nice Tip!,
but it would definitely be great if Check Point enable a service to quickly validate the reputation assigned to an URL/domain/IP by ThreatCloud, especially for TS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you visit the Check point Research site, under Tools, there are a few other tools you can utilize.
https://research.checkpoint.com/
So you are looking for domain or IP reputation lookup?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Im looking for IP/domain/URL "REPUTATION" assigned by ThreatCloud. This info is very important for the behavior of the Threat Prevention policy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Team,
Still i can find the website for IP reputation checking.
Please share the Web link if any available.
Thanks,
Harsha S.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There are internal tools for employees that can't be discussed here, another option would be a Horizon (Infinity) SOC trial.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi all, I realize this is an older post, but this caught my eye. Can anyone else confirm it works this way? I wasn't sure if you upload a document to the emulation if it sees if the document itself is malicious, or if there are any malicious links included in the document if it will scan the links themselves too. As an example, I created a Word doc including a link to a "simulated" malicious download link from eicar.org the emulation did not find anything malicious (unless Check Point happens to know it's not "really" malicious, but I don't know).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How are you uploading the document exactly?
From memory with the TP API for example you specify if the request type is TE vs AV, typically the latter would be most appropriate for Eicar detection.
Documents containing Links (URLs) - reputation will be checked using Check Point ThreatCloud per sk95235 / sk112312.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
I was using this URL: https://threatpoint.checkpoint.com/ThreatPortal/emulation
The only option is to upload a file, no granularity beyond that. Is there a better URL or tool to use for something like Eicar?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Anything else on my last reply?
