Check Point - IOC Enrichment and Triage

Enriches IOC entities (IP, domain, URL, file hash) found in an incident with Cyberint threat intelligence, then applies triage decision logic. The playbook routes each indicator to the matching Cyberint IOC enrichment endpoint, appends the returned maliciousness score and detected activities to the incident, and escalates the incident severity when a malicious indicator is found. Requires the Check Point EM Feed (Cyberint Feed) integration to be configured.

Pack
Cyberint
Tasks
16

Inputs

Outputs

Commands used