TrustRadius: an HG Insights company

What is Check Point XDR?

Check Point XDR is a cloud-delivered extended detection and response platform for security operations teams. It consolidates security events from connected Check Point and third-party products to identify, prioritize, investigate, and respond to incidents across endpoints, networks, mobile devices, cloud services, and email.

Key Capabilities

  • Event correlation: Correlates events and alerts from connected security products to identify related activity and create prioritized incidents.
  • Threat detection: Uses artificial intelligence (AI), machine learning, behavioral analytics, and threat intelligence to identify suspicious activity and multi-stage attacks.
  • Incident investigation: Provides incident context, recommended response actions, asset information, and forensic event data for security analysis.
  • Threat hunting: Supports advanced queries across collected endpoint and gateway forensic events.
  • Automated response: Uses Playblocks automation workflows to coordinate containment and enforcement actions across connected security controls.
  • Third-party integrations: Connects with third-party security products, including endpoint protection, firewalls, and identity platforms.
  • Indicator management: Supports centralized management of indicators of compromise (IoCs) from Check Point, third-party, and external intelligence sources.

Audience & Use Cases

  • Audience: Security operations center analysts, incident responders, threat hunters, and security administrators.
  • Use cases: Cross-environment threat detection, incident triage, investigation of correlated alerts, automated containment, and threat hunting.

Technical Specifications

  • Deployment model: Cloud-delivered security operations platform.
  • Covered environments: Endpoints, networks, mobile devices, cloud services, and email.
  • Data retention: Standard retention is 90 days; Check Point offers longer retention options.
  • Related capabilities: Playblocks automation, event management, threat intelligence, and managed detection and response services.

According to Check Point, the platform can prioritize a large volume of events into a smaller set of incidents requiring analyst attention and automate selected enforcement actions across monitored environments.

Videos

Product Demos

Technical Details

Technical Details
Mobile ApplicationNo

FAQs

What is Check Point XDR?
Check Point XDR is a cloud-delivered extended detection and response platform for security operations teams. It consolidates security events from connected Check Point and third-party products to identify, prioritize, investigate, and respond to incidents across endpoints, networks, mobile devices, cloud services, and email.