Check Point XDR
What is Check Point XDR?
Check Point XDR is a cloud-delivered extended detection and response platform for security operations teams. It consolidates security events from connected Check Point and third-party products to identify, prioritize, investigate, and respond to incidents across endpoints, networks, mobile devices, cloud services, and email.
Key Capabilities
- Event correlation: Correlates events and alerts from connected security products to identify related activity and create prioritized incidents.
- Threat detection: Uses artificial intelligence (AI), machine learning, behavioral analytics, and threat intelligence to identify suspicious activity and multi-stage attacks.
- Incident investigation: Provides incident context, recommended response actions, asset information, and forensic event data for security analysis.
- Threat hunting: Supports advanced queries across collected endpoint and gateway forensic events.
- Automated response: Uses Playblocks automation workflows to coordinate containment and enforcement actions across connected security controls.
- Third-party integrations: Connects with third-party security products, including endpoint protection, firewalls, and identity platforms.
- Indicator management: Supports centralized management of indicators of compromise (IoCs) from Check Point, third-party, and external intelligence sources.
Audience & Use Cases
- Audience: Security operations center analysts, incident responders, threat hunters, and security administrators.
- Use cases: Cross-environment threat detection, incident triage, investigation of correlated alerts, automated containment, and threat hunting.
Technical Specifications
- Deployment model: Cloud-delivered security operations platform.
- Covered environments: Endpoints, networks, mobile devices, cloud services, and email.
- Data retention: Standard retention is 90 days; Check Point offers longer retention options.
- Related capabilities: Playblocks automation, event management, threat intelligence, and managed detection and response services.
According to Check Point, the platform can prioritize a large volume of events into a smaller set of incidents requiring analyst attention and automate selected enforcement actions across monitored environments.
Categories & Use Cases
Videos
Product Demos
Technical Details
| Mobile Application | No |
|---|
FAQs
What is Check Point XDR?
Check Point XDR is a cloud-delivered extended detection and response platform for security operations teams. It consolidates security events from connected Check Point and third-party products to identify, prioritize, investigate, and respond to incidents across endpoints, networks, mobile devices, cloud services, and email.