Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Gherghi
Explorer
Jump to solution

hashed updates of malware signatures

is is anywhere in check point documentation a reference to the fact that when updating the databases of the security gateways with the new malware signatures the hash values of those files are also made available in order to check the integrity of those files? or is it any other method made available by check point in order to verify/ensure integrity of the feeds? But I'd need anyway a document/link where is stated that...

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

There isn't any public documentation about what the PTC Download Agent does in terms of storing the offline signatures, much less confirming integrity.
Best to reach out to your local office where the specific requirements can be discussed, possibly requiring an RFE.

View solution in original post

3 Replies
PhoneBoy
Admin
Admin

Malware hashes are checked via ThreatCloud, not from a local file.
Unless, of course, you are using your own Custom Intelligence Feeds.

0 Kudos
Gherghi
Explorer

Yes, but what if the customer wants offline updates via Private ThreatCloud? How the customer could check the integrity of the updates downloaded from the Check Point Public Threat Cloud?

0 Kudos
PhoneBoy
Admin
Admin

There isn't any public documentation about what the PTC Download Agent does in terms of storing the offline signatures, much less confirming integrity.
Best to reach out to your local office where the specific requirements can be discussed, possibly requiring an RFE.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events