Check Point Quantum Smart-1 Cloud Integration

Note: This integration requires Cisco XDR Advantage or Cisco XDR Premier licensing tier.

Check Point Quantum Smart-1 Cloud is a unified network security policy management platform for firewalls, applications, users, and workloads. With real-time threat visibility, large-scale event logging, and rich Management API.

This integration uses the Management API to access Check Point NGFW alerts. Check Point NGFW is built on the basic concept of traditional firewalls but additionally includes deep packet inspection, application-level inspection, intrusion prevention, and advanced malware prevention capabilities like sandboxing. It also brings in threat intelligence from outside the firewall.

Integration with Check Point Quantum Smart-1 Cloud allows Cisco XDR to incorporate NGFW alerts in investigations. These alerts provide detailed visibility into network traffic and malicious activity. Use this integration to query for security detections of observables including IP, hostname, domain, process name, file name, URL, MD5, and SHA-256.

This integration also provides an automatic target in Cisco XDR automation which can be used for various firewall-related workflow use cases.