Threat Hunting

Threat Hunting is an investigative tool which allows for advanced querying on all malicious and benign forensics events collected from the organization's endpoints with Check Point Endpoint Security installed.

The information collected lets you to:

  • Investigate the full scope of an attack.

  • Discover stealth attack by observation of a suspicious activity.

  • Remediate the attack before it causes further damage.

  • Proactively hunt for advanced attacks by searching for anomalies, and using hunting leads and enrichment.

Threat Hunting supports:

  • Data collection and enrichment - All events are collected through multiple sensors and sent to a unified repository and enhanced by ThreatCloud, MITRE mapping and alerts from all the prevention engines.

  • Rich toolset for custom queries, drill down and pivoting to suspicious activity.

  • Predefined queries and a MITRE dashboard which map all activity and allow a quick start to proactive hunting.

  • Remediation actions per result or a bulk operation integrated in the Threat Hunting flow (such as file quarantine and kill process).

Prerequisites

Before Threat Hunting is enabled, confirm that:

  • The management and client versions meet the minimum supported versions (see Supported Versions).
  • The tenant resides in a supported region (see Supported Regions).
  • These blades are active: Forensics, Behavioral Guard, and Anti-Ransomware.

Supported Regions

Threat Hunting is supported only for the Check Point Portal tenants (accounts) residing in these regions:

  • Australia

  • EU

  • India

  • United Kingdom

  • United Arab Emirates

  • US

Supported Versions

  • Endpoint Security Client version:

    • Recommended version - E84.40 and higher.
    • Minimum supported version - E84.10.
  • Management version:

    • Cloud-only, web management.