Check Point - Credential Leak Validation and Response

Validates and responds to leaked employee or customer credentials reported by Cyberint Argos. The playbook looks up leaked credentials for the configured company domain (or, when no domain is configured, uses the exposed credentials embedded in the triggering Cyberint alert), escalates the incident when exposed credentials are found, and drives an automated or semi-automated remediation flow (reset sessions, force password reset, or disable the account in the identity provider), followed by user and SOC notification. Identity-provider validation and remediation steps are modeled as manual tasks so the playbook works out of the box; connect them to your Active Directory, Microsoft Entra ID or Okta integration to fully automate the response.

Pack
Cyberint
Tasks
19

Inputs

Outputs

Commands used