Threat Prevention - Infinity SOC
The Check Point Infinity SOC (sk164332) is supported from R80.20.40 in the Locally managed mode. Infinity SOC enables cybersecurity teams to effectively and efficiently prevent, detect and respond to all threats. Infinity SOC doubles the effectiveness of SOC teams by automating time-consuming tasks, allowing security teams to focus on remediation and attack prevention.
You can enable the Infinity SOC feature in the WebUI or through clish commands.
To enable the Infinity SOC feature in the WebUI:
-
Click Device > Advanced Settings.
-
In the Privacy Settings Attribute section, select the attribute Help Check Point improve its products by sending data.
-
Click Edit.
-
Select Help us improve product experience by sending data to Check Point.
-
Click Apply.
-
-
In the Threat Prevention Policy Attribute section, select the attribute Allow me to view attack statistics in my User Center account.
-
Click Edit.
-
Select Allow me to view attack statistics in my User Center Account.
-
Click Apply.
-
-
Optional: In the Threat Prevention Policy section, select the attribute Allow IP address information in attack statistics.
-
Click Edit.
-
Select Allow IP address information in attack statistics (see sk164332 - section "De-obfuscate the real IP of the victim").
-
Click Apply.
-
To enable the Infinity SOC feature in Gaia Clish, run these commands:
-
Allow the appliance to send data to Check Point:
set privacy-settings advanced-settings customer-consent true
-
Allow viewing attack statistics in your User Center Account:
set threat-prevention policy advanced-settings allow-attack-stats true
-
Optional: Enable the real IP address information in the attack reports (see sk164332 - section "De-obfuscate the real IP of the victim"):
set threat-prevention policy advanced-settings allow-ipaddr-in-stats true