- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Re: ThreatPrevention public API
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ThreatPrevention public API
Hi Checkmates
For Threat Prevention private cloud deployments, does the solution support 3rd party integrations via a Public API?
Does it also support the following techniques?
VM detection, time delays , shut-down, re-start VM detection, user interaction?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I think you are trying to answer an RFC for another product 🙂
Threat Prevention API allows you to integrate with third-party feeds. You can find more details here.
If I misunderstood the nature of your request, please elaborate.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I think you are trying to answer an RFC for another product 🙂
Threat Prevention API allows you to integrate with third-party feeds. You can find more details here.
If I misunderstood the nature of your request, please elaborate.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Val
This is actually for Check Point, customer had this specific requirement.
Thanks for your response appreciate it.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Uh, so these are the requirements for Threat Extraction Emulation, is that correct? On the second read, I think you mention multiple evasion techniques detection.
There are a couple of documents covering Threat Emulation:
1. https://support.checkpoint.com/results/sk/sk114806
2. https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_ThreatPrevention_AdminGuide/...
AFAIK, most of what you are looking for is present. For an official answer, please reach ou to your local CP representatives.
Hope this helps.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Val, this is correct. It's for threat emulation.
Basically an on-prem sandbox solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Documentation about the Threat Prevention API for on-prem are here: https://support.checkpoint.com/results/sk/sk137032
