5. Check Point SandBlast Agent Management Platform. Logs, Reports & Forensics. Threat Hunting

5. Check Point SandBlast Agent Management Platform. Logs, Reports & Forensics. Threat Hunting

Welcome to the fifth article in the series on the Check Point SandBlast Agent Management Platform. You can find the previous articles by following the corresponding link: One, Two, Three, the fourth. Today, we will discuss the monitoring capabilities in the Management Platform, specifically working with logs, interactive dashboards (View), and reports. We will also touch on the topic of Threat Hunting to identify current threats and anomalous events on the user's machine.

Logs

The primary source of information for monitoring security events is the Logs section, which displays detailed information for each incident and also allows you to use convenient filters to refine your search criteria. For example, by right-clicking on a parameter (Blade, Action, Severity, etc.) of the log of interest, this parameter can be filtered as Filter: "Parameter" or Filter Out: "Parameter". Additionally, for the Source parameter, the IP Tools option can be selected, which allows you to ping the given IP address/name or perform a nslookup to obtain the source IP address by name.

5. Check Point SandBlast Agent Management Platform. Logs, Reports & Forensics. Threat Hunting

In the Logs section, for filtering events, there is a subsection Statistics, which displays statistics for all parameters: a time chart with the number of logs, as well as percentage indicators for each parameter. From this subsection, you can easily filter logs without accessing the search bar or writing filtering expressions β€” simply select the desired parameters, and the new list of logs will be displayed immediately.

5. Check Point SandBlast Agent Management Platform. Logs, Reports & Forensics. Threat Hunting

Detailed information for each log is available in the right panel of the Logs section; however, a more convenient option is to open the log with a double-click to analyze its content. Below is an example of a log (the image is clickable), which displays detailed information about the triggering of the Prevent action of the Threat Emulation blade on an infected file ".docx". The log has several subsections that display security event details: policies and protection that were triggered, forensics details, client and traffic information. Special attention should be paid to the reports available from the log β€” Threat Emulation Report and Forensics Report. These reports can also be opened from the SandBlast Agent client.

5. Check Point SandBlast Agent Management Platform. Logs, Reports & Forensics. Threat Hunting

Threat Emulation Report

5. Check Point SandBlast Agent Management Platform. Logs, Reports & Forensics. Threat Hunting

When using the Threat Emulation blade, a link to a detailed emulation results report β€” Threat Emulation Report β€” appears in the corresponding log after the emulation is performed in the Check Point cloud. The content of such a report is described in detail in our article on malware analysis using Check Point SandBlast Network forensics. It should be noted that this report is interactive and allows you to "drill down" into details for each section. There is also an option to view the recording of the emulation process in a virtual machine, download the original malicious file, or obtain its hash, as well as to contact the Check Point Incident Response Team.

5. Check Point SandBlast Agent Management Platform. Logs, Reports & Forensics. Threat Hunting

Forensics Report

Almost every security event generates a Forensics Report, which includes detailed information about the malicious file: its characteristics, actions, entry point into the system, and impact on important company assets. The structure of the report was detailed in our article on malware analysis using Check Point SandBlast Agent forensics. Such a report is an important source of information when investigating security events, and if necessary, the report's contents can be immediately sent to the Check Point Incident Response Team.

5. Check Point SandBlast Agent Management Platform. Logs, Reports & Forensics. Threat Hunting

SmartView

Check Point SmartView is a convenient tool for building and viewing dynamic dashboards (Views) and reports in PDF format. From SmartView, administrators can also view user logs and audit events. The image below shows the most useful reports and dashboards for working with SandBlast Agent.

5. Check Point SandBlast Agent Management Platform. Logs, Reports & Forensics. Threat Hunting

Reports in SmartView are documents containing statistical information about events over a specific period. Reports can be exported in PDF format to the machine running SmartView, as well as regularly exported to PDF/Excel to the administrator's email. Additionally, import/export of report templates is supported, along with the creation of custom reports and the ability to hide user names in reports. The image below shows an example of a built-in Threat Prevention report.

5. Check Point SandBlast Agent Management Platform. Logs, Reports & Forensics. Threat Hunting

Dashboards (View) in SmartView allow administrators to access logs related to specific events β€” simply double-click on the object of interest, whether it's a chart column or a malicious file name. Just like with reports, you can create custom dashboards and hide user data. Dashboards also support template import/export, regular exports to PDF/Excel sent to the administrator's email, and automatic data refresh for real-time security event monitoring.

5. Check Point SandBlast Agent Management Platform. Logs, Reports & Forensics. Threat Hunting

Additional monitoring sections

The description of monitoring tools in the Management Platform would be incomplete without mentioning the Overview, Computer Management, Endpoint Settings, and Push Operations sections. These sections were detailed in the second article, however, it will be useful to examine their capabilities for addressing monitoring tasks. Let’s start with Overview, which consists of two subsections β€” Operational Overview and Security Overview, both of which are dashboards that provide information on the status of protected user machines and security events. Like with any other dashboard, double-clicking on an interesting parameter in the Operational Overview and Security Overview subsections leads to the Computer Management section with the selected filter (for instance, 'Desktops' or 'Pre-Boot Status: Enabled') or to the Logs section for a specific event. The Security Overview subsection features the 'Cyber Attack View – Endpoint' dashboard, which can be customized and set up for automatic data refresh.

5. Check Point SandBlast Agent Management Platform. Logs, Reports & Forensics. Threat Hunting

From the Computer Management section, you can monitor the status of agents on user machines, the update status of the Anti-Malware database, disk encryption stages, and much more. All data is updated automatically, and for each filter, the percentage of suitable user machines is displayed. Data about computers can also be exported in CSV format.

5. Check Point SandBlast Agent Management Platform. Logs, Reports & Forensics. Threat Hunting

An important aspect of monitoring the security of workstations is the setup of alerts for critical events (Alerts) and log export (Export Events) for storage on the company's log server. Both settings are performed in the Endpoint Settings section, and for Alerts It is possible to connect a mail server to send event notifications to the administrator and configure threshold values for triggering/disabling notifications based on the percentage/number of devices that meet the event criteria. Export Events This allows for the configuration of log forwarding from the Management Platform to the company's log server for further processing. The formats SYSLOG, CEF, LEEF, SPLUNK are supported, as well as TCP/UDP protocols and any SIEM systems with an operational syslog agent, using TLS/SSL encryption and syslog client authentication.

5. Check Point SandBlast Agent Management Platform. Logs, Reports & Forensics. Threat Hunting

For deep analysis of events on the agent or in case of contacting technical support, logs can be promptly collected from the SandBlast Agent client through a forced operation in the Push Operations section. The generated log archive can be configured to be forwarded to Check Point servers or corporate servers, and the log archive is also saved on the user's machine in the directory C:UsersusernameCPInfo. Support for starting the log collection process at a specified time and the option for the user to delay the operation are available.

5. Check Point SandBlast Agent Management Platform. Logs, Reports & Forensics. Threat Hunting

Threat Hunting

The Threat Hunting method is used for the proactive search of malicious activities and anomalous behavior in the system for further investigation of potential security events. The Threat Hunting section in the Management Platform allows for searching events with specified parameters in the data of the user's machine.

5. Check Point SandBlast Agent Management Platform. Logs, Reports & Forensics. Threat Hunting

The Threat Hunting tool has several pre-installed queries, for example: for classifying malicious domains or files, tracking rare accesses to certain IP addresses (relative to the overall statistics). The query structure consists of three parameters: sync status indicator (network protocol, process ID, file type, etc.), an operator ("is", "is not", "includes", "one of", etc.) and the body of the request. In the body of the request, regular expressions can be used, and multiple filters can be applied simultaneously in the search string.

5. Check Point SandBlast Agent Management Platform. Logs, Reports & Forensics. Threat Hunting

After selecting a filter and completing the request processing, access to all relevant events is available, with the option to view detailed information about the event, quarantine the request object, or generate a detailed Forensics Report describing the event. Currently, this tool is in beta and plans to expand its capabilities in the future, such as adding event information in the form of a Mitre Att&ck matrix.

5. Check Point SandBlast Agent Management Platform. Logs, Reports & Forensics. Threat Hunting

Conclusion

In summary: in this article, we explored the capabilities for monitoring security events in the SandBlast Agent Management Platform, examined a new tool for proactive searching of malicious actions and anomalies on user machines β€” Threat Hunting. The next article will be the final one in this cycle, where we will address the most frequently asked questions about the Management Platform and discuss the testing possibilities of this product.

A large collection of materials on Check Point from TS Solution. To not miss the next publications on the SandBlast Agent Management Platform β€” follow our updates on social media (Telegram, Facebook, VK, TS Solution Blog, Yandex.Zen).

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers πŸ”₯ Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster