Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Dor_Marcovitch
Advisor

Indicator Files

hey, 

i have seen it is possible to use indicator files on threat prevention blade.

i want to load on only IP indicator file, which blade i must have enabled to use it?

for example to use sha1 indicator file for files, i must have AV blade enabled on the FW, but for IP i could not find resource for it.

 

thanks

0 Kudos
2 Replies
Vladimir
Champion
Champion

Please read: https://sc1.checkpoint.com/documents/R80.30/SmartConsole_OLH/EN/html_frameset.htm?topic=-_ktjOvSNsVD...

But note that you can only use MD5 as a valid hash source.

0 Kudos
PhoneBoy
Admin
Admin

You can specify which blade is required in the IOC file, which can either be Anti-Bot or Anti-Virus.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events