⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Connector ID | CheckPointEMIOCIntelligence |
| Publisher | Check Point |
| Used in Solutions | Check Point EM ThreatCloud Intelligence Feed |
| Collection Method | CCF |
| Connector Definition Files | CPEMIOCIntelligenceLogs_connectorDefinition.json |
| DCR Definition Files | CPEMIOCIntelligenceLogs_DCR.json |
| CCF Configuration | CPEMIOCIntelligenceLogs_PollingConfig.json |
| CCF Capabilities | APIKey, POST |
Check Point provides a Microsoft Sentinel integration to ingest high-fidelity Indicators of Compromise (IoCs) from the Infinity External Risk Management solution into Microsoft Sentinel. This connector incrementally pulls the premium IOC feed — including malicious IPs, domains, URLs, and file hashes — enriched with confidence, severity, malicious classification, kill chain stage, blocking and uniqueness flags, malware types, and CVE/campaign associations.
This connector ingests data into the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
emiocintel_CL |
? | ✓ | ? |
💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.
Resource Provider Permissions:
Custom Permissions:
⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.
1. Connect Check Point EM ThreatCloud Intelligence Feed to Microsoft Sentinel
To enable the connector provide the required information below and click on Connect.
Argos URL — Cyberint API URL for your tenant (e.g. https://your_tenant.cyberint.io)
API Token — Cyberint API access token
Customer Name — Company (client) name associated with your Cyberint instance
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊