White Paper | Check Point XDR - Threat Prevention & Response

White Paper | Check Point XDR - Threat Prevention & Response

Discover how Check Point XDR enhances threat detection, response, and prevention with AI-driven insights to stop cyber attacks across your security estate.

White Paper | Check Point XDR - Threat Prevention & Response

CHECK POINT XDR THREAT PREVENTION & RESPONSE Comprehensive threat prevention across the entire security

estate, powered by collaborative AI-driven correlations

2INFINIT Y XDR/

Executive Summary 3

Introduction 4

The threat landscape 4

What the SOC needs to mitigate the risk 5

The traditional XDR approach & why it falls short 5

6

Comprehensive threat prevention 7

Collaborative, intelligence and AI-based threat & event correlation 9

9

9

9

10

10

10

10

Consolidated user and entity behavior analytics 10

Automated response 11

Use cases 12

12

12

13

13

14

Conclusion 14

CONTENTS

Paul Ardoin Rectangle

3 CHECK POINT XDR THREAT PREVENTION & RESPONSE

Executive Summary According to Check Point Research, the rate of global weekly cyberattacks is growing at 32% year-over-year, with the annual increase in ransomware exploits coming in at 41%1.

To improve detection and response capabilities against the ever-rising threat of attack, security teams seek tools to consolidate data and gain a wider view of everything across the security estate.

Extended detection and response (XDR) aims to address the need. But can it deliver on the promise?

In this paper we will discuss the current threat landscape and why standard XDR may improve visibility, detection, and response, but it stops short of providing the preventive protection organizations need.

We will also introduce Check Point XDR, part of the AI-powered, cloud-delivered Check Point cyber security platform.

Check Point XDR empowers security operations center (SOC) teams to quickly uncover, prevent, and mitigate cyberattacks by correlating events across the security estate, leveraging ThreatCloud AI, Check Point Research, and third-party threat intelligence, along with on-demand guidance from Check Point's built-in generative AI-powered virtual assistant.

And we will share how four different organizations around the world are leveraging Check Point XDR to make previously unattainable correlations, detecting and preventing the damage of malware, phishing,

and other attacks.

1 Check Point Research, July 26, 2022

https://blog.checkpoint.com/2022/07/26/check-point-research-weekly-cyber-attacks-increased-by-32-year-over-year-1-out-of-40-organizations-impacted-by-ransomware-2/ https://protect.checkpoint.com/v2/___https://www.checkpoint.com/infinity/xdr-xpr/___.YzJlOmNwYWxsOmM6bzo0ZmMxODU1MzE2Y2ZkOWZkMjZkNWIyOTVhZDhmZjhhNDo2Ojg4ZDA6YTJiMmM4MjM3ZWYzOGM3MGMyYjJmMjBmZTA1NGY1OTBlNDQ3YmNmNDc2MzQ1NTVmZGE4MTVlZDgxZDhlMjU1MTpwOlQ6Tg https://protect.checkpoint.com/v2/___https://www.checkpoint.com/ai/threatcloud/___.YzJlOmNwYWxsOmM6bzo0ZmMxODU1MzE2Y2ZkOWZkMjZkNWIyOTVhZDhmZjhhNDo2OmU3MTQ6YTViYzMwN2I4ZmUyOTZjZmMzMWYxMDkwMzRjN2FhNGI5ZTU0M2EzZDJkYjRlZjNlY2UzNDViMGE2YmQ5YWZhZDpwOlQ6Tg https://protect.checkpoint.com/v2/___https://research.checkpoint.com/___.YzJlOmNwYWxsOmM6bzo0ZmMxODU1MzE2Y2ZkOWZkMjZkNWIyOTVhZDhmZjhhNDo2OmNiNDE6YzM4YjY3YjY2MDQ1YzhhMWRhZDJhNDA5YWQwZGE1NGJiMGIwNTZlY2E5NjQ0Yjg2YTEyYjg0OGY1N2Y2NzJkNjpwOlQ6Tg

4CHECK POINT XDR THREAT PREVENTION & RESPONSE

Moreover, the operational overhead has never been greater: • Analysts are charged with managing multiple, siloed detection tools • They must sift through and review an overwhelming number of alerts • Alerts are delivered without context • The rate of false positives is high

Too often this makes shutting down an attack before the damage spreads a profoundly difficult task.

It’s no surprise then, that the average time to identifying and containing a breach is at an astounding 277 days (about 9 months).2

The SOC challenge to robust protection • Keeping up with new cyber skills requirements • Multiple tools in silos • Endless alerts • High rates of false positives • Narrow view of attacks

2 IBM, Cost of a Data Breach Report 2023

Introduction The threat landscape Cyberattacks are more frequent, sophisticated, and costly than ever before. This is making it very difficult for security operations teams to keep up with the required tools and knowledge for accelerating threat handling and ensuring its efficacy.

The Growing Risk of Cyberattacks (Source: Check Point Research)

https://www.ibm.com/reports/data-breach https://blog.checkpoint.com/2022/07/26/check-point-research-weekly-cyber-attacks-increased-by-32-year-over-year-1-out-of-40-organizations-impacted-by-ransomware-2/

5CHECK POINT XDR THREAT PREVENTION & RESPONSE

What the SOC needs to mitigate the risk To mitigate the risk of today’s challenging threat landscape, security teams must operate at peak efficiency to prevent an attack before the damage is done.

Achieving this demands the ability to automatically consolidate security data from all relevant sources, for rapid intelligence-driven correlations, investigations, and incident handling.

It also requires automated prevention playbooks and generative AI-powered insights, automations, and on-demand assistance, so teams can streamline and accelerate incident investigation, analysis, and threat hunting.

Furthermore, these capabilities must extend across the entire security estate, including networks, endpoints, cloud environments, email systems, identity providers, mobile, and IoT devices.

The SOC need • Maximizing resources to do more with less • Focus only on events requiring action • Consolidating security data from every source • Correlations among separate events • Automated prevention playbooks • On-demand support from a GenAI assistant • Comprehensive coverage for the entire security estate

The traditional XDR approach & why it falls short Today’s extended detection and response (XDR) approach aims to address these needs by integrating data from multiple security sources and automating detection and response.

But the current approach still falls short as it does not provide complete coverage with the requisite intelligence-driven correlations for discovering incidents before they propagate and spread across the organization.

Traditional XDR may reduce the alarm queue and number of false positives for improved detection. But detection is not enough.

What organizations need is a way to derive a higher level of value from all the data consolidated by XDR and leverage it for intelligence-driven correlations that uncover severe threats currently flying under the radar of standard XDR solutions. This comprehensive prevention-first approach goes beyond simple detection and response to prevent damage from the stealthiest attacks and help SOC analysts focus their attention where they can have the most impact.

6CHECK POINT XDR THREAT PREVENTION & RESPONSE

Otherwise, the day-to-day mission to protect will remain cumbersome, analysts will still be overwhelmed by too much information, they will still lack the visibility into how what’s happening on the network relates to what’s happening on the endpoint, email, and cloud, for example, as well as what they need to do to stop threats fast and efficiently.

The limitations of traditional XDR • Coverage is not comprehensive • No intelligence-driven correlations of behaviors and events • Limited early detection of incidents • Not preventive, detection only

This is where Check Point XDR comes into play.

Prevention-first protection with Check Point XDR Check Point XDR is a comprehensive security operations platform that empowers SOC teams with prevention-first XDR across the entire security estate.

It delivers clarity and enables focus with intelligence-driven correlations, collaborative AI insights, and consolidated analytics.

Check Point XDR identifies and connects multiple complex security events, which may seem to be unrelated and benign, but are in fact part of a single critical threat. This is how it stops threats from propagating and spreading within the organization at the earliest possible stage.

Moreover, event context and insights with built-in guidelines for response are accessible to analysts through a single pane of glass, for unprecedented visibility, speed, and operational efficiency.

The solution is available in multiple options, each tailored to meet varying needs, including an end-to-end offering that supports a comprehensive range of data sources; a fully managed service for 24/7 monitoring and assistance by the Check Point Services team; and an XDR solution that is focused on supporting Check Point Endpoint Security.

https://protect.checkpoint.com/v2/___https://igs.checkpoint.com/___.YzJlOmNwYWxsOmM6bzoyY2ZiOGU0YWU1ZWQxN2FmMGJhNDM5NmY5M2NlMGVmNjo2OjU2NWE6Yzc1YjJiZTQ2ZTE1ZjJmNzg0M2QyZTY1OGIyZjY0MzUzMGM3YzAwMjUxYzIyMGIwMDdlZGJhMjQ0NTExNDg3MDpwOkY6Tg

7CHECK POINT XDR THREAT PREVENTION & RESPONSE

Comprehensive threat prevention Part of the Check Point cybersecurity platform, Check Point XDR is AI-powered and cloud-delivered and enables accurate attack prevention across the entire security estate, including networks, endpoints, emails, cloud, identities, mobile, and IoT.

It brings rich API capabilities for configuration and monitoring, enabling integration with third party tools and workflows. It triggers automatic response based on both Check Point and third-party security data sources and can ingest data from a broad spectrum of sources, integrating with multiple gateways and connecting to third-party data feeds.

Moreover, with advanced IOC management, Check Point XDR automatically blocks malicious indicators that are identified on any connected product or external data feed.

IoC management and enforcement

Check Point XDR: comprehensive, collaborative, and consolidated

Comprehensive Threat Prevention

Accurate attack prevention across the entire security estate

Collaborative Threat & Event Correlation

Powered by AI and threat intelligence, correlating Check Point and

third-party events

Consolidated Analytics

Improving security posture with visibility into attack

behavior, context, and damage

8CHECK POINT XDR THREAT PREVENTION & RESPONSE

An overview of the current security status, as aggregated from every connected data source, provides analysts ongoing visibility into the preventive actions and auto-responses that have been executed, as well as into those awaiting manual response and handling.

Transforming millions of events into one unified incident

• Access the status of all products connected to Check Point XDR

• See only the logs that require action, from among millions of alerts

• Connect all relevant logs into one incident that requires action

• Correlate network, endpoint, email, cloud, and IoT

• Get deep dive visibility into high priority, high severity incidents

9CHECK POINT XDR THREAT PREVENTION & RESPONSE

AI technology 50+ AI and Machine Learning technologies

that identify and block emerging threats that were never seen before

Big data threat intelligence Always acquires the most recent IoCs and protections of latest attacks seen in the wild

ThreatCloud APIs

Telemetry Telemetry ACCURATE PREVENTION

(MALICIOUS/SAFE)

99.7% Security effectiveness

BEST RESULT IN THE

INDUSTRY**

ThreatCloud AI

Check Point Research cp<r> Hundreds of in-house analysts power Check Point’s leading cyber security research, which enriches Check Point XDR with an additional threat intelligence feed. Using proprietary AI modules, anomaly detection, reverse engineering, and threat hunting techniques the Check Point team leads the global effort to prevent cyberattacks.

Built-in AI assistance Check Point's generative AI-powered assistant provides security teams with actionable recommendations and on-demand support for threat hunting, incident analysis and response, and investigations. It also automates incident summary generation and repetitive tasks, enhancing efficiency, reducing workloads, and strengthening the overall security posture.

Collaborative, intelligence and AI-based threat & event correlation ThreatCloud AI Check Point XDR is powered by Check Point ThreatCloud AI, a real-time global threat intelligence platform that monitors networks around the world for emerging threats and vulnerabilities, providing intelligence-driven insights and context.

https://www.checkpoint.com/ai/

10CHECK POINT XDR THREAT PREVENTION & RESPONSE

Personalized newseed A personalized cybersecurity newsfeed, curated and continuously updated by Check Point Research, delivers insights into the latest threats, vulnerabilities, campaigns, and more. It enables detailed correlations and provides retroactive detection tailored to the specific organization’s sector, region, and logs, offering immediate clarity on whether and how these threats impact the environment.

External threat intelligence Integrated threat intelligence based on Check Point Research (CP<R>) insights and premium VirusTotal analytics, provides visibility into attack behavior and context, and streamlines operations.

In addition, threat intelligence and event correlation powered by ThreatCloud AI, Check Point Research, Check Point Exposure Management, and third-party threat intelligence, connects the dots between benign events, exposing critical threats and enriching insights with more context.

Cross-product detection Check Point XDR provides cross-product detection and correlations even when connected to a single data source. By running AI and machine learning-powered behavioral analytics on all the collected data, analysts can review insights from any security solution through a single pane of glass and improve detection even further by connecting events across the complete attack flow and security stack, including native Check Point and third-party solutions.

Unified IOC management Unified indicators of compromise (IOC management with the ability to ingest third party IOC feeds enables consolidated enforcement of IOCs across all integrated products.

Consolidated user and entity behavior analytics Check Point XDR employs sophisticated AI and ML algorithms along with behavioral analytics to correlate, prioritize, and prevent threats across the entire security landscape.

Analytics are performed on data aggregated from across all relevant data sources, connected security products, and first and third-party intelligence feeds, including VirusTotal, to provide the broadest visibility into attack behavior, context, and damage.

This way, analysts can identify anomalous behavior indicative of a potential threat and gain a fast and accurate understanding of where the attack is within the kill chain.

Moreover, incidents are fully mapped to MITRE, enabling analysts to review the tactics detected in the attack and the assets involved, along with the fuller context of the malicious indicators of compromise with intelligence enrichment for each.

By combining intelligence-based correlations and consolidated analytics, analysts can conclude with confidence what the severity level of the event is, eliminating the noise, reducing false positives, and focusing only on the events that require action.

https://protect.checkpoint.com/v2/___https://research.checkpoint.com/___.YzJlOmNwYWxsOmM6bzoyY2ZiOGU0YWU1ZWQxN2FmMGJhNDM5NmY5M2NlMGVmNjo2OmQ2YzE6ZmM3NDIyYzA0OTZjZDc0ZTc3ZWVlOGM0ODk4ZjM4MTM1ZmFiNDRiZGFhYTc1MDFmOTdmZGY4YzgyZWE1Y2U1YzpwOkY6Tg https://protect.checkpoint.com/v2/___https://blog.checkpoint.com/security/virustotal-threat-intelligence-now-seamlessly-integrated-in-infinity-xdr-xpr/___.YzJlOmNwYWxsOmM6bzoyY2ZiOGU0YWU1ZWQxN2FmMGJhNDM5NmY5M2NlMGVmNjo2OjU0OGM6NjdhZDk3NjQ5M2RiNWI3ZDU5M2NlZWFiMmI5OTQ3Zjk3YWFlNjNiM2NlYWEyYmE2ZjYxYmUwZGYwMDIxOGRjODpwOkY6Tg https://protect.checkpoint.com/v2/___https://www.checkpoint.com/ai/threatcloud/___.YzJlOmNwYWxsOmM6bzoyY2ZiOGU0YWU1ZWQxN2FmMGJhNDM5NmY5M2NlMGVmNjo2OmM2N2M6ZDE2NDAzY2VhMDQ5ZGFlNGZkZDMzOGI1ZDA1NDY3MWNjNjg5MmRiMmFmZWM1YzQ2NWU1MDFlN2E2ZTZlM2U4YjpwOkY6Tg

11CHECK POINT XDR THREAT PREVENTION & RESPONSE

Check Point XDR insights consolidation for incident investigation

Automated response Check Point XDR automates incident response for a significant reduction in the time required to manage an incident and achieve resolution.

And with Check Point Playblocks it provides out-of-the-box playbooks that automates threat prevention and operations across the entire landscape.

Check Point Playblocks connects to IT management tools and ticketing systems, integrating seamlessly with other productivity and administrative tools. It streamlines collaboration across products, people, and processes with automated responses, including quarantining, blocking, and remediation of threats, devices, and users.

Automated actions include isolating the compromised endpoint, blocking malicious indicators, email quarantine, endpoint forensics analysis, process termination, and enforcing password reset for identity providers.

https://protect.checkpoint.com/v2/___https://www.checkpoint.com/infinity/playblocks/___.YzJlOmNwYWxsOmM6bzo0ZmMxODU1MzE2Y2ZkOWZkMjZkNWIyOTVhZDhmZjhhNDo2OmFlNTA6MGUxMTdkODdiNDk2YjhlZGY1NWFjNjRlZTg3ZmM2NjIzMzAxMDBlYzA2MDJjYmE5YTNlOTg2YzRmNDdiMzAxZDpwOlQ6Tg

12CHECK POINT XDR THREAT PREVENTION & RESPONSE

Prevention-first XDR built from the ground up as a prevention first solution across all products, including third party offerings

Comprehensive coverage for any data source, including network, cloud, endpoint, mobile, email and identities

Exclusive Check Point Research intelligence with attack statistics from ThreatCloud AI

Immediate IoC sharing across all connected products for optimized enforcing and blocking of malicious indicators

Check Point's built-in AI for on-demand support, guidance, and automations with a GenAI-powered always-on virtual security assistant

Off-the-shelf automated responses and playbooks for accelerated operational efficiency

Check Point XDR highlights

Use cases European bank: intelligent correlations A bank in Europe had detected seemingly benign events on the gateway logs and several endpoints, which didn’t raise suspicion, as they seemed to be isolated and unrelated.

The events included:

• Process signed by Microsoft and running on the endpoint

• Anti-virus on endpoint disabled

• Endpoints communicating with unfamiliar domains

• Network traffic on unfamiliar domains

• Teams process changing the registry

• User logging into three devices

Typically, each on their own would have been deemed to be low severity events.

However, Check Point XDR correlated all these events, identifying that this was a high severity breach that reached the command-and-control stage.

As a result, all the required responses were automatically triggered, Check Point XDR isolated the machines, blocked the malicious URLs, terminated the processes on all the devices, and restored Microsoft Defender policy, resolving the incident immediately.

13CHECK POINT XDR THREAT PREVENTION & RESPONSE

Government organization in Latin America: Raspberry Robin malware detection Raspberry Robin is one of the most distributed malwares. It has several entry vectors that lead to the main sample. The most prevalent one is an LNK disguised as a USB drive or a network share which launches msiexec.exe that downloads the main component.

At one government organization in Latin America, Check Point XDR had correlated multiple low severity detections from the endpoint and the gateway. It identified malware activity, detecting that it was Raspberry Robin malware that had compromised an endpoint. Upon detection, the malware was automatically blocked and prevented from spreading.

Moreover, with the threat hunting capabilities of Check Point XDR, the government organization’s security team determined that a USB drive was inserted into the infected machine right before the attack. And with data from Check Point Research about the targets and timeline of the attack, it was uncovered that government organizations are the second most targeted vertical for this type of malware.

“Thank you very much for alerting us to this incident. The USB in question was subsequently scanned, and we changed the password for the endpoint and user account. We also took your advice to isolate the endpoint through the Check Point XDR portal.”

European financial institution: phishing prevention At this European financial institution, Check Point XDR had correlated an informational password re-use alert with URL and IP reputation to discover a medium severity incident of credentials leakage to an unknown phishing website.

Had preventive action not been taken by Check Point XDR, the attacker would have succeeded at leveraging these credentials to gain direct access to 18 additional machines, including domain controllers and other critical assets.

Instead, the financial institution prevented potential damage from an unknown phishing website, blocking malicious indicators on all products connected to Check Point XDR and forcing password renewal across the organization.

14CHECK POINT XDR THREAT PREVENTION & RESPONSE

Oil & gas company in Latin America: gateway logs correlation Check Point XDR connected with Check Point firewalls to correlate more than 100 logs on the gateway to identify a high severity threat at a Latin American oil and gas company, which could have potentially reached the command-and-control stage.

Having identified recurrent and periodic calls to the command and control, it was concluded that a critical asset, a mail server, was infected.

Check Point XDR alerted the security team that the endpoint does not have Check Point Endpoint Security installed, underscoring the heightened risk. As a result, the organization installed anti-virus on the relevant endpoint for proactive prevention.

Conclusion The damage trajectory of cyberattacks is accelerating. Current XDR solutions aim to help SOC teams with improved detection. But detection is not enough. Prevention is key.

This is what Check Point XDR is all about, bringing prevention-first detection and response with complete visibility and efficient operation across the entire IT environment from a single pane of glass.

It is comprehensive, collaborative, and consolidated, powering fast intelligence-driven correlations and even faster, more accurate investigations and response, ensuring the robust protection to which every organization aspires.

Comprehensive coverage of the entire security estate

Built-in AI: a GenAI-powered always-on virtual security assistant

Focusing on only viable threats

Automatically connecting all activities across attack flow

Intelligence-driven insights from all sources and products

Single pane of glass for status, insights, intelligence, actions

Out-of-the-box playbooks connected to productivity tools

Fast onboarding as a cloud service

Available as managed service for prevention and response

The Check Point XDR advantage

https://protect.checkpoint.com/v2/___https://www.checkpoint.com/quantum/___.YzJlOmNwYWxsOmM6bzo0ZmMxODU1MzE2Y2ZkOWZkMjZkNWIyOTVhZDhmZjhhNDo2Ojc4MjI6ZmM0NTMwOWFhMmE3NmMzN2Q3ODMyOGVmNWEyMTI5OTBhZTIzY2NlNjU1MmFiNzE2OTcxYmJjYmEyMTQ0Y2M0NzpwOlQ6Tg

15CHECK POINT XDR THREAT PREVENTION & RESPONSE

Worldwide Headquarters 5 Shlomo Kaplan Street, Tel Aviv 6789159, Israel | Tel: +972-3-753-4599

U.S. Headquarters 100 Oracle Parkway, Suite 800, Redwood City, CA 94065 | Tel: 1-800-429-4391

www.checkpoint.com

© 2024 Check Point Software Technologies Ltd. All rights reserved.

Check Point XDR: comprehensive prevention-first protection

“The behavior insights of Check Point XDR brought a unique value that we didn’t have before. Thanks to its behavior detection and correlated events from the endpoint and the gateways, a high severity attack of an evasive malware was prevented.”

— Retail Company, North America

To see how Check Point XDR can help you detect incidents sooner and resolve them faster with greater efficiency, we invite you to book a demo here.

To learn more, visit our website.

https://pages.checkpoint.com/infinity-xdr-xpr-demo.html https://protect.checkpoint.com/v2/___https://www.checkpoint.com/horizon/xdr-xpr/___.YzJlOmNwYWxsOmM6bzo0ZmMxODU1MzE2Y2ZkOWZkMjZkNWIyOTVhZDhmZjhhNDo2OmIyNzI6NTZjNTJhMzU0NTExMzI2NmY4NTgxNjlmMTBhYmJlZTRlMjY1MTYyOTZlZjA1NmFkZjQxYWE3MWU3NGVkMTliODpwOlQ6Tg

Bookmark 1 Zero Trust and Why You Should Embrace It Executive Summary Introduction The threat landscape What the SOC needs to mitigate the risk The traditional XDR approach & why it falls short

Prevention-first protection with Infinity XDR/XPR Comprehensive threat prevention Collaborative, intelligence and AI-based threat & event correlation ThreatCloud AI Check Point Research cp<r> AI Copilot Personalized newsfeed External threat intelligence Cross-product detection Unified IOC management

Consolidated user and entity behavior analytics Automated response

Use cases European bank: intelligent correlations Infinity XDR/XPR highlights Government organization in Latin America: Raspberry Robin malware detection European financial institution: phishing prevention Oil & gas company in Latin America: gateway logs correlation

Conclusion


Item Type: pdf