- Products
- Learn
- Local User Groups
- Partners
- More
The State of Ransomware Q1 2026
Key Trends and Their Impact
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hey CheckMates!
We’re kicking off a new Playblocks Highlights series. These are short, practical posts that surface useful insights across automations, connectors, and pro tips you can put to work immediately. First up: predefined automations you might not have tried yet.
💡 Playblocks makes automation accessible. No scripts - just ready‑to‑run workflows that strengthen your defenses and save your team time.
What it does: Removes isolation from a Defender machine that is now assessed as clean - streamlining recovery and minimizing downtime.
Supported product: Microsoft Defender connector
Trigger: When a potentially clean isolated machine is detected.
Approval step: Runs upon administrator approval to avoid premature de‑isolation
What it does: Adds malicious file indicators identified by Threat Extraction (Harmony Endpoint) into an IOC feed to update threat intel and block propagation.
Supported products: Harmony Endpoint; Infinity IoC Management (IoC Enforcement connector)
Trigger: Match on malicious file indicator with high confidence.
What it does: Automatically blocks IP addresses flagged as attackers, ensuring immediate protection across your environment.
Supported product: Quantum Enforcement connector
Trigger: Attacking IP identified through security logs.
What it does: Proactively alerts (and can open a ticket) when VPN certificates are about to expire or have expired, so you can renew before downtime.
Supported product: Quantum
Trigger: VPN certificate is expired or within your warning window.
Key parameters:
What it does: Auto‑isolates CrowdStrike‑flagged devices with high‑severity infections to prevent lateral movement.
Supported product: CrowdStrike connector
Trigger: High‑severity infection (for example malware/virus) detected by CrowdStrike.
What it does: Isolates SentinelOne‑flagged devices with high‑severity threats to stop spread quickly.
Supported product: SentinelOne connector
Trigger: High‑severity infection detected by SentinelOne
If you can think it - you can build it. Simply describe the outcome you want, and AI Copilot will propose a ready‑to‑run flow you can edit and refine.
This series will keep shining a light on value across Playblocks - more automations, connectors more tips. What would you like to see?
Feedback & requests: PlayBlocks-Feedback@checkpoint.com
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY