⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Publisher | Check Point |
| Support Tier | Partner |
| Support Link | https://www.checkpoint.com/support-services/contact-support/ |
| Categories | Security - Threat Intelligence |
| Version | 3.0.0 |
| Author | Check Point - support@checkpoint.com |
| First Published | 2026-04-26 |
| Solution Folder | Check Point EM ThreatCloud Intelligence Feed |
Cyberint, a Check Point company, provides Microsoft Sentinel integration to streamline premium IOC ingestion and bring enriched threat intelligence from the Infinity External Risk Management solution into Microsoft Sentinel. The ThreatCloud Intelligence Feed connector incrementally pulls high-fidelity indicators — IPs, domains, URLs, and file hashes — enriched with confidence, severity, malicious classification, kill-chain stage, blocking and uniqueness flags, malware types, and CVE/campaign associations.
Underlying Microsoft Technologies used:
This solution depends on the following technologies, and some of which may be in Preview state or may incur additional ingestion or operational costs:
a. Codeless Connector Framework (used by the ThreatCloud Intelligence Feed data connector to poll the Check Point Exposure Management API)
b. Log Analytics custom logs via Data Collection Rules (DCR)
c. Azure Logic Apps (used by the Check_Point_EM_IOCIntelligenceEnrichment playbook)
This solution provides 1 data connector(s):
This solution uses 1 table(s):
| Table | Used By Connectors | Used By Content |
|---|---|---|
emiocintel_CL |
Check Point EM ThreatCloud Intelligence Feed Connector | - |
This solution includes 1 content item(s):
| Content Type | Count |
|---|---|
| Playbooks | 1 |
| Name | Description | Tables Used |
|---|---|---|
| Check Point EM - ThreatCloud Intelligence Feed Enrichment and Triage | When a new Microsoft Sentinel incident is created, this playbook enriches IOC entities (IPs, domains... | - |
📄 Source: Check Point EM ThreatCloud Intelligence Feed/README.md
This solution streams the Check Point Exposure Management (Infinity External Risk Management / Argos) ThreatCloud Intelligence Feed into Microsoft Sentinel and provides an out-of-the-box (OOTB) enrichment playbook for Sentinel incident entities.
| Component | Description |
|---|---|
| Data Connector (CCP) | Polls the Check Point EM ThreatCloud Intelligence Feed API on a recurrence and ingests indicators (IPs, domains, URLs, file hashes) with confidence, severity, malicious classification, kill-chain stage, blocking and uniqueness flags, malware types, and CVE/campaign associations into emiocintel_CL. |
Playbook CPEM_IOCIntelligenceEnrichment |
Triggers on Microsoft Sentinel incident webhook; enriches IP / FileHash / Domain / URL entities against the same API and appends a structured enrichment comment to the incident. |
Before deploying this solution:
Microsoft Sentinel must be enabled on the target Log Analytics workspace. Enabling Sentinel auto-provisions the Data Collection Endpoint (DCE) that this solution's CCP data connector relies on. Without Sentinel enabled, the Microsoft.Insights/dataCollectionRules resource in this template fails to deploy with a "DCE not found" error.
Check Point Exposure Management API access: a valid Argos URL (e.g. https://your-tenant.cyberint.io), API access token, and the Customer Name registered with your Cyberint account.
Permissions: the deploying principal needs Microsoft Sentinel Contributor (or equivalent) on the workspace and the resource group.
Two supported paths:
Package/mainTemplate.json against a Sentinel-enabled workspace. The DCE referenced by the DCR is the workspace's auto-provisioned endpoint, so it must exist before deployment (see Prerequisite #1).| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.0.0 | 02-06-2026 | Initial Solution release. |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊