
Welcome to the new series of articles dedicated to protecting personal workstations using solutions and the new cloud management system β . We discussed SandBlast Agent in articles about and , and we have long promised to publish a complete course of articles on deploying and administering agents. The Check Point cloud management system for agents, Management Platform, available within the Infinity Portal, is best suited for this purpose β it takes just a few minutes from registration on the portal to launching the workstation scan by the agent and detecting malicious activity.
Why SandBlast Agent?
According to the latest test , the Check Point SandBlast Agent product received an "AA" rating and "recommended" status with the following test results:
- Web traffic blocking rate β 100%;
- Email blocking rate β 100%;
- Offline threat blocking rate β 100%;
- Bypass attempt blocking rate β 100%;
- Overall blocking rate β 99.12%;
- False-positive rate β 0.8%.

SandBlast Agent provides a high level of protection for user workstations through the collaboration of several components, referred to as "blades" in Check Point terminology. A brief description of the blades used in SandBlast Agent:
- Threat Emulation β sandbox technology resistant to various evasion techniques, preventing zero-day attacks;
- Threat Extraction β real-time file cleaning technology that allows users to receive a document free of active components before a full emulation verdict;
- Anti-Exploit β protection for commonly used applications (Microsoft Office, Adobe PDF Reader, browsers, etc.) from exploit-based attacks;
- Anti-Bot β technology for protecting personal computers from joining botnet networks, capable of detecting infections, stopping malicious software operation, and "healing" infected machines;
- Zero-Phishing β protection module that blocks fraudulent phishing sites and alerts users when their work password is used on external resources;
- Behavioral Guard β technology aimed at preventing attacks that utilize bypass and evasion techniques;
- Anti-Ransomware β a protection module that detects and blocks the actions of encryptors, as well as allows for the recovery of encrypted files using Snapshots;
- Forensics β a security module that records and analyzes all events on the machine, resulting in a detailed report on investigated attacks.

In addition to the aforementioned capabilities, SandBlast Agent supports full disk encryption, removable media encryption, and computer port protection, features a built-in VPN client, signature-based and heuristic malware protection modules. More details on the capabilities of all SandBlast Agent components will be discussed in subsequent articles, but for now it's time to get acquainted with the actively developing platform β Check Point Infinity.
Check Point Infinity: Protection Against Generation V Threats
Since 2017, Check Point has been developing and promoting a unified consolidated security architecture , which successfully protects all components of modern IT infrastructure: network and cloud infrastructures, workstations, and mobile devices. The main idea is to manage security measures of various categories from a single web-based management console.

Currently, the Check Point Infinity architecture allows the administration of cloud protection solutions β CloudGuard SaaS, network security β CloudGuard Connect, Smart-1 Cloud, Infinity SOC, as well as protecting user devices using the SandBlast Agent Management Platform, SandBlast Agent Cloud Management, and SandBlast Web Dashboard.
This series of articles will focus on the SandBlast Agent Management Platform solution (currently in Beta), which allows you to deploy a cloud management server in minutes, set security policies, and distribute agents to user computers.
Infinity Portal & SandBlast Agent Management Platform: Getting Started
The process of deploying SandBlast Agent using the Management Platform consists of 5 stages:
- Registration on the Check Point Infinity Portal;
- Registration of the SandBlast Agent Management Platform application;
- Creating a new Endpoint Management Service for managing agents;
- Creating and configuring policies for the agents;
- Deploying agents on user computers.
This article describes the first three stages, and in subsequent publications, we will examine the remaining two in detail, including studying the management platform interface, deploying agents on client computers, configuring policies, and testing the agentβs ability to handle the most common security threats.
1. Registering on the Infinity Portal
First, you need to go to the website and fill out the registration form, providing the company name, contact details, and agreeing to the service usage rules and the portal's privacy policy, as well as completing the reCAPTCHA. It is worth noting that during registration, you can choose the country in which the data collected by the portal will be stored, according to the service usage rules and the privacy policy. There are only two options: Ireland and the USA. To do this, you must check the box "Use specific data residency region" and select the country.

Upon successful registration on the portal, a confirmation email will be sent to the address you provided, confirming your access to the Infinity Portal and inviting you to log in. It is noteworthy that when logging in for the first time, you may need to select the password reset option for successful authentication.

2. Registering the SandBlast Agent Management Platform Application
After logging in to the portal and clicking on the "Menu" icon (step 1 in the image below), you will be prompted to register an application from the available list under the following categories: Cloud Protection, Network Protection, and Endpoint Protection. Each application deserves a separate course of introductory articles, so we wonβt go into more detail on them and will choose the SandBlast Agent Management Platform application in the Endpoint Protection category (step 2 in the image below).

After selecting the application, you must agree to the service usage rules and the portal's privacy policy, and after clicking the "TRY NOW" button, access to the Endpoint Management service creation interface will be opened.

3. Creating a New Endpoint Management Service
The final step is creating a new service for Endpoint Management, which serves as a web interface for managing agents. The process is straightforward, just like before: select the 'New Endpoint Management Service' option (as shown in the image below), fill in the details of your new service (identifier, hosting region, and password), and click the 'CREATE' button.


After the service creation process is completed, you will receive an email with the parameters you can use to connect to the management cloud server using the standard Check Point console for managing agents β SmartEndpoint version R80.40. We will not cover management using the standard console, as this series of articles aims to demonstrate the capabilities of the SandBlast agent management cloud system.

With this, the registration process for the cloud service for managing the SandBlast Agent endpoint protection tool can be considered successfully completed. We are presented with the web interface of the agent administration platform, which will be thoroughly examined in the next article of our series 'Check Point SandBlast Agent Management Platform'.

Conclusion
It's time to summarize the work done: we have successfully registered on the Infinity Portal, registered the SandBlast Agent Management Platform application on the portal, and created a new cloud management service for Endpoint Management Service.
In the next article of our series, we will take a detailed look at the agent management interface β no tab will be overlooked, enabling us to effortlessly create security policies and monitor the status of user machines using logs and reports.
. To not miss the next publications on the SandBlast Agent Management Platform β follow our updates on social media (, , , , ).
Source: habr.com
