{"id":92913,"date":"2020-09-01T13:42:56","date_gmt":"2020-09-01T11:42:56","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/5-check-point-sandblast-agent-management-platform-logs-reports-forensics-threat-hunting"},"modified":"2020-09-01T13:42:56","modified_gmt":"2020-09-01T11:42:56","slug":"5-check-point-sandblast-agent-management-platform-logs-reports-forensics-threat-hunting","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/5-check-point-sandblast-agent-management-platform-logs-reports-forensics-threat-hunting","title":{"rendered":"5. Check Point SandBlast Agent Management Platform. Logjet, Raportet &#038; Forenzik\u00ebn. K\u00ebrkimi i K\u00ebrc\u00ebnimeve","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"5. Check Point SandBlast Agent Management Platform. Logs, Reports &amp; Forensics. Threat Hunting\" src=\"\/wp-content\/uploads\/2020\/09\/a7187930f8cd3b00abd80e0f8d9f0324.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nMir\u00eb se vini n\u00eb artikullin e pest\u00eb t\u00eb ciklit mbi zgjidhjen e Platform\u00ebs s\u00eb Menaxhimit t\u00eb Check Point SandBlast Agent. Artikujt e m\u00ebparsh\u00ebm mund t\u00eb shihen duke kaluar n\u00eb linkun p\u00ebrkat\u00ebs: <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/511768\/\">e para<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/512614\/\">Dyt\u00eb<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/513254\/\">Tret\u00eb<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/515172\/\">makina e kat\u00ebrt<\/a><\/noindex>Sot do t\u00eb shqyrtojm\u00eb mund\u00ebsit\u00eb e monitorimit n\u00eb Platform\u00ebn e Menaxhimit, n\u00eb m\u00ebnyr\u00eb t\u00eb ve\u00e7ant\u00eb pun\u00ebn me logjet, panele interaktive (View) dhe raportet. Do t\u00eb trajtojm\u00eb gjithashtu tem\u00ebn e Shkenc\u00ebs s\u00eb K\u00ebrc\u00ebnimeve p\u00ebr identifikimin e k\u00ebrc\u00ebnimeve aktuale dhe ngjarjeve anomale n\u00eb makin\u00ebn e p\u00ebrdoruesit.<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h2>Logs<\/h2>\n<p>\nBurimi kryesor i informacionit p\u00ebr monitorimin e ngjarjeve t\u00eb siguris\u00eb \u00ebsht\u00eb seksioni Logs, i cili shfaq informacion t\u00eb detajuar p\u00ebr \u00e7do incident dhe gjithashtu lejon p\u00ebrdorimin e filtrave t\u00eb p\u00ebrshtatsh\u00ebm p\u00ebr t\u00eb sakt\u00ebsuar kriteret e k\u00ebrkimit. P\u00ebr shembull, duke klikuar me t\u00eb djatht\u00ebn n\u00eb parametrin (Blade, Action, Severity etj.) t\u00eb logut interesant, ky parametr mund t\u00eb filtrohet si <i>Filter: \u00abParameter\u00bb<\/i> ose <i>Filter Out: \u00abParameter\u00bb<\/i>. Po ashtu, p\u00ebr parametrin Source mund t\u00eb zgjidhet opsioni IP Tools, ku mund t\u00eb nisni ping p\u00ebr k\u00ebt\u00eb IP-adres\u00eb\/em\u00ebr ose t\u00eb kryeni nslookup p\u00ebr t\u00eb marr\u00eb IP-n\u00eb e burimit sipas emrit.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/er\/gj\/-r\/ergj-rhqeb5doaruijchefsbbmc.png\"><img decoding=\"async\" alt=\"5. Check Point SandBlast Agent Management Platform. Logs, Reports &amp; Forensics. Threat Hunting\" src=\"\/wp-content\/uploads\/2020\/09\/b38e68cc93766b19f412e89fd4e851f3.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>N\u00eb seksionin Logs p\u00ebr filtrimin e ngjarjeve, ka nj\u00eb n\u00ebnseksion Statistics, ku shfaqet statistika p\u00ebr t\u00eb gjith\u00eb parametrat: nj\u00eb diagram temporal me numrin e logjeve, si dhe tregues p\u00ebrqind\u00ebsor\u00eb p\u00ebr secilin nga parametrat. Nga ky n\u00ebnseksion mund t\u00eb filtrohen leht\u00ebsisht logjet pa kaluar n\u00eb kutin\u00eb e k\u00ebrkimit dhe shkruar shprehje filtrimi \u2014 mjafton t\u00eb zgjidhni parametrat e interesit dhe lista e re e logjeve do t\u00eb shfaqet menj\u00ebher\u00eb.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/sm\/gm\/mf\/smgmmffyujvi1crg45z5uitlvwa.png\"><img decoding=\"async\" alt=\"5. Check Point SandBlast Agent Management Platform. Logs, Reports &amp; Forensics. Threat Hunting\" src=\"\/wp-content\/uploads\/2020\/09\/10deab53312dbef413e58f7edb5f43f0.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>Informacionet e detajuar p\u00ebr secil\u00ebn log jan\u00eb n\u00eb dispozicion n\u00eb panelin e djatht\u00eb t\u00eb seksionit Logs, megjithat\u00eb, hapja e logut me dy klikime p\u00ebr analiz\u00ebn e p\u00ebrmbajtjes \u00ebsht\u00eb m\u00eb e p\u00ebrshtatshme. M\u00eb posht\u00eb \u00ebsht\u00eb nj\u00eb shembull logu (imazhi \u00ebsht\u00eb i klikuesh\u00ebm), n\u00eb t\u00eb cilin tregohet informacioni i detajuar p\u00ebr aktivizimin e veprimit Prevent t\u00eb blade Threat Emulation mbi nj\u00eb skedar t\u00eb infektuar \".docx\". Logu ka disa n\u00ebnseksione q\u00eb paraqesin detajet e ngjarjes s\u00eb siguris\u00eb: politika dhe mbrojtja q\u00eb u aktivizuan, detajet e forenzik\u00ebs, informacioni p\u00ebr klientin dhe trafikun. Ve\u00e7an\u00ebrisht t\u00eb r\u00ebnd\u00ebsishme jan\u00eb raportet e disponueshme nga logu \u2014 Raporti i Emulimit t\u00eb K\u00ebrc\u00ebnimeve dhe Raporti i Forenzik\u00ebs. K\u00ebto raporte gjithashtu mund t\u00eb hapen nga klienti SandBlast Agent.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/u5\/ch\/e1\/u5che1n2ww-hycuu8j1-55cadfi.png\"><img decoding=\"async\" alt=\"5. Check Point SandBlast Agent Management Platform. Logs, Reports &amp; Forensics. Threat Hunting\" src=\"\/wp-content\/uploads\/2020\/09\/2e3650320a5e06a7c0503433ac4ad541.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<h3>Raporti i Simulimit t\u00eb K\u00ebrc\u00ebnimeve<\/h3>\n<p>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/ns\/h4\/_k\/nsh4_knfdmptu_-nfd97_pemoim.png\"><img decoding=\"async\" alt=\"5. Check Point SandBlast Agent Management Platform. Logs, Reports &amp; Forensics. Threat Hunting\" src=\"\/wp-content\/uploads\/2020\/09\/b0d753ec281f8409fe02946f9a3680b3.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>Kur p\u00ebrdoret blendi Threat Emulation, pas emulimit n\u00eb re nga Check Point, n\u00eb logun p\u00ebrkat\u00ebs shfaqet nj\u00eb lidhje n\u00eb raportin e detajuar t\u00eb rezultateve t\u00eb emulimit \u2014 Threat Emulation Report. P\u00ebrmbajtja e k\u00ebtij raporti p\u00ebrshkruhet me holl\u00ebsi n\u00eb artikullin ton\u00eb rreth <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/477494\/\">analiz\u00ebs s\u00eb malware-it p\u00ebrmes forenzik\u00ebs Check Point SandBlast Network<\/a><\/noindex>. Duhet t\u00eb theksohet se ky raport \u00ebsht\u00eb interaktiv dhe lejon \"navigimin\" n\u00eb detaje p\u00ebr secil\u00ebn nga seksionet. Gjithashtu, ka mund\u00ebsin\u00eb p\u00ebr t\u00eb par\u00eb regjistrimin e procesit t\u00eb emulimit n\u00eb makin\u00eb virtuale, p\u00ebr t\u00eb shkarkuar skedarin origjinal malware ose p\u00ebr t\u00eb marr\u00eb hash-in e tij, si dhe p\u00ebr t\u00eb kontaktuar ekipin e reagimit t\u00eb incident\u00ebve t\u00eb Check Point.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/8a\/lh\/xx\/8alhxxvnjs1ewg8b4_2vb9w1464.gif\"><img decoding=\"async\" alt=\"5. Check Point SandBlast Agent Management Platform. Logs, Reports &amp; Forensics. Threat Hunting\" src=\"\/wp-content\/uploads\/2020\/09\/9048cf717e020ae6d5bf2c106397bfe3.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<h3>Forensics Report<\/h3>\n<p>\nP\u00ebr pothuajse \u00e7do ngjarje sigurie gjenerohet nj\u00eb raport Forensics Report, i cili p\u00ebrfshin informacion t\u00eb detajuar n\u00eb lidhje me skedarin malware: karakteristikat e tij, veprimet, pik\u00ebn e hyrjes n\u00eb sistem dhe ndikimin n\u00eb aktivet e r\u00ebnd\u00ebsishme t\u00eb kompanis\u00eb. Struktura e raportit \u00ebsht\u00eb shqyrtuar me holl\u00ebsi n\u00eb artikullin ton\u00eb rreth <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/478396\/\">analiz\u00ebs s\u00eb malware-it p\u00ebrmes forenzik\u00ebs Check Point SandBlast Agent<\/a><\/noindex>. Ky raport \u00ebsht\u00eb nj\u00eb burim i r\u00ebnd\u00ebsish\u00ebm informacioni gjat\u00eb hetimeve t\u00eb ngjarjeve t\u00eb siguris\u00eb, dhe n\u00eb rast nevoje mund t\u00eb d\u00ebrgoni menj\u00ebher\u00eb p\u00ebrmbajtjen e raportit n\u00eb ekipin e reagimit t\u00eb incident\u00ebve t\u00eb Check Point.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/wh\/qb\/pe\/whqbpe7hlwwujwxdv4um42eb-no.gif\"><img decoding=\"async\" alt=\"5. Check Point SandBlast Agent Management Platform. Logs, Reports &amp; Forensics. Threat Hunting\" src=\"\/wp-content\/uploads\/2020\/09\/7010f25765e6c3bfb6dff40a8cf48e24.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<h2>SmartView<\/h2>\n<p>\nCheck Point SmartView \u00ebsht\u00eb nj\u00eb mjet i p\u00ebrshtatsh\u00ebm p\u00ebr nd\u00ebrtimin dhe shikimin e panel\u00ebve dinamik\u00eb (View) dhe raporteve n\u00eb format PDF. Nga SmartView gjithashtu mund t\u00eb shikoni log\u00ebt dhe ngjarjet e auditimit p\u00ebr administrator\u00ebt. N\u00eb figur\u00ebn m\u00eb posht\u00eb p\u00ebrmenden raportet dhe panel\u00ebt m\u00eb t\u00eb dobish\u00ebm p\u00ebr p\u00ebrdorimin me SandBlast Agent.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/wr\/e5\/yo\/wre5yoe7iptzwak-7vgbmszpzky.png\"><img decoding=\"async\" alt=\"5. Check Point SandBlast Agent Management Platform. Logs, Reports &amp; Forensics. Threat Hunting\" src=\"\/wp-content\/uploads\/2020\/09\/62a262c57811eede4609637590481ef0.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>Raportet n\u00eb SmartView jan\u00eb dokumente me informacion statistik p\u00ebr ngjarjet p\u00ebr nj\u00eb periudh\u00eb t\u00eb caktuar kohore. Mb\u00ebshtetet eksportimi i raporteve n\u00eb format PDF n\u00eb makin\u00ebn ku \u00ebsht\u00eb hapur SmartView, si dhe eksportimi i rregullt n\u00eb PDF\/Excel n\u00eb emailin e administratorit. P\u00ebrve\u00e7 k\u00ebsaj, mb\u00ebshtetet importimi\/eksportimi i shablloneve t\u00eb raporteve, krijimi i raporteve t\u00eb personalizuara dhe mund\u00ebsia p\u00ebr t\u00eb fshehur emrat e p\u00ebrdoruesve n\u00eb raporte. N\u00eb figur\u00ebn m\u00eb posht\u00eb \u00ebsht\u00eb paraqitur nj\u00eb shembull i raportit t\u00eb integruar Threat Prevention.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/c2\/ol\/br\/c2olbrgf6jufazr6w6wzhi7rxgg.gif\"><img decoding=\"async\" alt=\"5. Check Point SandBlast Agent Management Platform. Logs, Reports &amp; Forensics. Threat Hunting\" src=\"\/wp-content\/uploads\/2020\/09\/293e7d94792e09eefe93981369af817b.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>Panohet\u00eb (View) n\u00eb SmartView lejojn\u00eb administratorin q\u00eb t\u00eb aksesoj\u00eb regjistrat sipas ngjarjeve p\u00ebrkat\u00ebse \u2014 mjafton t\u00eb klikohet dy her\u00eb n\u00eb objektin e interesit, qoft\u00eb ai nj\u00eb kolon\u00eb diagrami apo emri i nj\u00eb skedari t\u00eb d\u00ebmsh\u00ebm. Ashtu si n\u00eb rastin e raporteve, mund t\u00eb krijoni panoheta t\u00eb personalizuara dhe t\u00eb fshihni t\u00eb dh\u00ebnat e p\u00ebrdoruesve. Panohet gjithashtu mb\u00ebshtesin importin\/exportin e templatingeve, d\u00ebrgimin e rregullt n\u00eb PDF\/Excel n\u00eb emailin e administratorit dhe p\u00ebrdit\u00ebsimin automatik t\u00eb t\u00eb dh\u00ebnave p\u00ebr monitorimin e ngjarjeve t\u00eb siguris\u00eb n\u00eb koh\u00eb reale.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/md\/ob\/l3\/mdobl3ed5laokqioysiwzs6h3yi.gif\"><img decoding=\"async\" alt=\"5. Check Point SandBlast Agent Management Platform. Logs, Reports &amp; Forensics. Threat Hunting\" src=\"\/wp-content\/uploads\/2020\/09\/efd3584fdb1e1d61109e55a4137c8e0d.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<h2>Sezione shtes\u00eb t\u00eb monitorimit<\/h2>\n<p>\nP\u00ebrshkrimi i mjeteve t\u00eb monitorimit n\u00eb Management Platform do t\u00eb ishte i paplot\u00eb pa p\u00ebrmendur seksionet Overview, Computer Management, Endpoint Settings dhe Push Operations. K\u00ebto seksione jan\u00eb p\u00ebrshkruar n\u00eb detaje n\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/512614\/\">artikullin e dyt\u00eb<\/a><\/noindex>, megjithat\u00eb do t\u00eb ishte e dobishme t\u00eb shqyrtohen mund\u00ebsit\u00eb e tyre p\u00ebr zgjidhjen e detyrave t\u00eb monitorimit. Le t\u00eb fillojm\u00eb me Overview, q\u00eb p\u00ebrb\u00ebhet nga dy n\u00ebngrupe \u2014 Operational Overview dhe Security Overview, t\u00eb cilat paraqesin pano me informacion mbi gjendjen e makinave t\u00eb mbrojtura t\u00eb p\u00ebrdoruesve dhe ngjarjet e siguris\u00eb. Ashtu si n\u00eb nd\u00ebrveprimin me \u00e7do pano tjet\u00ebr, n\u00ebngrupet Operational Overview dhe Security Overview, me nj\u00eb klik t\u00eb dyfisht\u00eb mbi parametrin e interesit, lejojn\u00eb kalimin n\u00eb seksionin Computer Management me filtrin e zgjedhur (p.sh. \"Desktops\" ose \"Pre-Boot Status: Enabled\"), ose n\u00eb seksionin Logs p\u00ebr nj\u00eb ngjarje t\u00eb caktuar. N\u00ebngurupi Security Overview paraqet nj\u00eb pano \"Cyber Attack View \u2013 Endpoint\", e cila mund t\u00eb personalizohet \"sip\u00ebr\" dhe t\u00eb vendoset p\u00ebrdit\u00ebsimi automatik i t\u00eb dh\u00ebnave.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/--\/bl\/sr\/--blsrbxcaapnnnckd5ov9in5rk.gif\"><img decoding=\"async\" alt=\"5. Check Point SandBlast Agent Management Platform. Logs, Reports &amp; Forensics. Threat Hunting\" src=\"\/wp-content\/uploads\/2020\/09\/4f49d2a2f33f64cf65924ff3a1140e19.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>Nga seksioni Computer Management mund t\u00eb ndiqni gjendjen e agjentit n\u00eb makinat e p\u00ebrdoruesve, statusin e p\u00ebrdit\u00ebsimit t\u00eb baz\u00ebs s\u00eb t\u00eb dh\u00ebnave Anti-Malware, fazat e enkriptimit t\u00eb diskut dhe shum\u00eb m\u00eb tep\u00ebr. T\u00eb dh\u00ebnat p\u00ebrdit\u00ebsohen automatikisht, dhe p\u00ebr \u00e7do filtrin shfaqet nj\u00eb p\u00ebrqindje e makinerive t\u00eb p\u00ebrshtatshme t\u00eb p\u00ebrdoruesve. Gjithashtu mb\u00ebshtetet eksportimi i t\u00eb dh\u00ebnave mbi kompjuter\u00ebt n\u00eb formatin CSV.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/ij\/zi\/ni\/ijzinixrgrhpci2cgi3hugndspw.png\"><img decoding=\"async\" alt=\"5. Check Point SandBlast Agent Management Platform. Logs, Reports &amp; Forensics. Threat Hunting\" src=\"\/wp-content\/uploads\/2020\/09\/fd99e1dbfa12324f44bd18bfd07a7632.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>Nj\u00eb aspekt i r\u00ebnd\u00ebsish\u00ebm i monitorimit t\u00eb mbrojtjes s\u00eb stacioneve t\u00eb pun\u00ebs \u00ebsht\u00eb konfigurimi i njoftimeve p\u00ebr ngjarje kritike (Alerts) dhe eksportimi i regjistrave (Export Events) p\u00ebr ruajtje n\u00eb serverin e regjistrave t\u00eb kompanis\u00eb. T\u00eb dy konfigurimet kryhen n\u00eb seksionin Endpoint Settings, dhe p\u00ebr <i>Alerts<\/i> ka nj\u00eb mund\u00ebsi p\u00ebr t\u00eb lidhur nj\u00eb server e-mail p\u00ebr d\u00ebrgimin e njoftimeve mbi ngjarjet administratorit dhe p\u00ebr t\u00eb konfiguruar vlerat prag p\u00ebr aktivizimin\/fshirjen e njoftimeve n\u00eb var\u00ebsi t\u00eb p\u00ebrqindjes\/sasis\u00eb s\u00eb pajisjeve q\u00eb plot\u00ebsojn\u00eb kriteret e ngjarjes. <i>Export Events<\/i> lejon konfigurimin e d\u00ebrgimit t\u00eb log-eve nga Management Platform n\u00eb serverin e log-eve t\u00eb kompanis\u00eb p\u00ebr p\u00ebrpunim t\u00eb m\u00ebtejsh\u00ebm. Mb\u00ebshteten formatet SYSLOG, CEF, LEEF, SPLUNK, protokollet TCP\/UDP, \u00e7do sistem SIEM me nj\u00eb agjent syslog t\u00eb pun\u00ebs, p\u00ebrdorimi i enkriptimit TLS\/SSL dhe autentifikimi i klientit syslog.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/vx\/73\/o0\/vx73o0ismioxm9l-ymvdvfkjhny.gif\"><img decoding=\"async\" alt=\"5. Check Point SandBlast Agent Management Platform. Logs, Reports &amp; Forensics. Threat Hunting\" src=\"\/wp-content\/uploads\/2020\/09\/b9af095705868c7ba9f63d4d927bdae5.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>P\u00ebr analiz\u00eb t\u00eb thell\u00eb t\u00eb ngjarjeve n\u00eb agjent ose n\u00eb rast t\u00eb kontaktit me mb\u00ebshtetje teknike, mund t\u00eb mblidhen shpejt log-et nga klienti SandBlast Agent duke p\u00ebrdorur nj\u00eb operacion t\u00eb detyruar n\u00eb seksionin Operacione t\u00eb Shtyra. Mund t\u00eb konfigurohet d\u00ebrgimi i arkivit t\u00eb formuar me log-e n\u00eb server\u00ebt Check Point ose n\u00eb server\u00ebt e korporat\u00ebs, gjithashtu arkivi me log-e ruhen n\u00eb makin\u00ebn e p\u00ebrdoruesit n\u00eb direktorin\u00eb C:UsersusernameCPInfo. Mb\u00ebshtetet nisja e procesit t\u00eb mbledhjes s\u00eb log-eve n\u00eb koh\u00eb t\u00eb caktuar dhe mund\u00ebsia p\u00ebr t\u00eb shtyr\u00eb operacionin nga p\u00ebrdoruesi.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/iy\/5u\/6o\/iy5u6ovlg4fxi-ex0whpxh4yjms.gif\"><img decoding=\"async\" alt=\"5. Check Point SandBlast Agent Management Platform. Logs, Reports &amp; Forensics. Threat Hunting\" src=\"\/wp-content\/uploads\/2020\/09\/2ef458a297b223b30813091f54195d76.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<h2>K\u00ebrkimi i k\u00ebrc\u00ebnimeve<\/h2>\n<p>\nMetoda Threat Hunting p\u00ebrdoret p\u00ebr k\u00ebrkimin proaktiv t\u00eb aktiviteteve t\u00eb keqb\u00ebrjes dhe sjelljeve anormale n\u00eb sistem p\u00ebr hetimin e m\u00ebtejsh\u00ebm t\u00eb nj\u00eb ngjarjeje potenciale t\u00eb siguris\u00eb. Seksioni Threat Hunting n\u00eb Management Platform lejon k\u00ebrkimin e ngjarjeve me parametrat e caktuar n\u00eb t\u00eb dh\u00ebnat e makin\u00ebs p\u00ebrdoruese.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/su\/2p\/l5\/su2pl5rwsc32slfnokqn_rrqtus.png\"><img decoding=\"async\" alt=\"5. Check Point SandBlast Agent Management Platform. Logs, Reports &amp; Forensics. Threat Hunting\" src=\"\/wp-content\/uploads\/2020\/09\/3f771fbea121a78d1d50daf42f1643cb.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>Instrumenti Threat Hunting ka disa k\u00ebrkesa t\u00eb paracaktuara, p\u00ebr shembull: p\u00ebr klasifikimin e domain-eve ose skedar\u00ebve t\u00eb keqb\u00ebr\u00eb, ndjekjen e qasjeve t\u00eb rralla n\u00eb disa IP adresa (n\u00eb raport me statistikat e p\u00ebrgjithshme). Struktur\u00eb e k\u00ebrkes\u00ebs p\u00ebrb\u00ebhet nga tre parametra: <i>nj\u00eb indikator<\/i> (protokolli rrjetor, identifikuesi i procesit, lloji i skedarit etj.), <i>operator<\/i> (\u201c\u00ebsht\u00eb\u201d, \u201cnuk \u00ebsht\u00eb\u201d, \u201cp\u00ebrfshin\u201d, \u201cnj\u00eb nga\u201d etj.) dhe <i>trupi i k\u00ebrkes\u00ebs<\/i>. N\u00eb trupin e k\u00ebrkes\u00ebs mund t\u00eb p\u00ebrdoren shprehje t\u00eb rregullta, mb\u00ebshtetet p\u00ebrdorimi i disa filtrave nj\u00ebkoh\u00ebsisht n\u00eb vij\u00ebn e k\u00ebrkimit.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/1y\/3c\/2a\/1y3c2acosy5e22pturoe7khfchq.png\"><img decoding=\"async\" alt=\"5. Check Point SandBlast Agent Management Platform. Logs, Reports &amp; Forensics. Threat Hunting\" src=\"\/wp-content\/uploads\/2020\/09\/c0070db473264069eda4f07a919eaa8c.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>Pas shp\u00ebrndarjes s\u00eb filtrit dhe p\u00ebrfundimit t\u00eb p\u00ebrpunimit t\u00eb k\u00ebrkes\u00ebs, shfaqen t\u00eb gjith\u00eb ngjarjet p\u00ebrkat\u00ebse, me mund\u00ebsin\u00eb p\u00ebr t\u00eb par\u00eb informacionet e detajuara mbi ngjarjen, p\u00ebr ta futur objektin e k\u00ebrkes\u00ebs n\u00eb karantin\u00eb ose p\u00ebr t\u00eb gjeneruar nj\u00eb raport t\u00eb detajuar Forensics Report q\u00eb p\u00ebrshkruan ngjarjen. Aktualisht, ky mjet \u00ebsht\u00eb n\u00eb version beta dhe planifikohet zgjerimi i grumbullit t\u00eb mund\u00ebsive, p\u00ebr shembull, shtimi i informacionit mbi ngjarjen n\u00eb form\u00ebn e matrik\u00ebs Mitre Att&amp;ck.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/i8\/uh\/ck\/i8uhckgoeakoqcbd7nqx1btijac.png\"><img decoding=\"async\" alt=\"5. Check Point SandBlast Agent Management Platform. Logs, Reports &amp; Forensics. Threat Hunting\" src=\"\/wp-content\/uploads\/2020\/09\/61c9043715428af9cbd90bd49e679ce3.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<h3>P\u00ebrfundim<\/h3>\n<p>\nLe t\u00eb p\u00ebrmbyllim: n\u00eb k\u00ebt\u00eb artikull shqyrtuam mund\u00ebsit\u00eb e monitorimit t\u00eb ngjarjeve t\u00eb siguris\u00eb n\u00eb SandBlast Agent Management Platform, studiuam mjetin e ri p\u00ebr k\u00ebrkimin proaktiv t\u00eb aktiviteteve t\u00eb d\u00ebmshme dhe anomalive n\u00eb makinat e p\u00ebrdoruesve \u2013 Threat Hunting. Artikulli i ardhsh\u00ebm do t\u00eb jet\u00eb p\u00ebrfundimtar n\u00eb k\u00ebt\u00eb cik\u00ebl dhe n\u00eb t\u00eb do t\u00eb shqyrtojm\u00eb pyetjet m\u00eb t\u00eb shpeshta n\u00eb lidhje me zgjidhjen Management Platform dhe do t\u00eb flasim p\u00ebr mund\u00ebsit\u00eb e testimit t\u00eb k\u00ebtij produkti.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/358508\/\">Nj\u00eb koleksion i madh materialesh n\u00eb lidhje me Check Point nga TS Solution<\/a><\/noindex>. Q\u00eb t\u00eb mos humbisni publikimet e ardhshme mbi SandBlast Agent Management Platform, ndiqni p\u00ebrdit\u00ebsimet n\u00eb rrjetet tona sociale (<noindex><a rel=\"nofollow\" href=\"https:\/\/t.me\/tssolution\">Telegram<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.facebook.com\/groups\/tssolution.info\/\">Facebook<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/vk.com\/ts_solution\">VK<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/tssolution.ru\/blog\">Blogu i Zgjidhjeve TS<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/zen.yandex.ru\/id\/5c7d2162fa818600ae386a52\">Yandex.Zen<\/a><\/noindex>).<br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/516336\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0414\u043e\u0431\u0440\u043e \u043f\u043e\u0436\u0430\u043b\u043e\u0432\u0430\u0442\u044c \u043d\u0430 \u043f\u044f\u0442\u0443\u044e \u0441\u0442\u0430\u0442\u044c\u044e \u0446\u0438\u043a\u043b\u0430 \u043e \u0440\u0435\u0448\u0435\u043d\u0438\u0438 Check Point SandBlast Agent Management Platform. \u0421 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0438\u043c\u0438 \u0441\u0442\u0430\u0442\u044c\u044f\u043c\u0438 \u043c\u043e\u0436\u043d\u043e \u043e\u0437\u043d\u0430\u043a\u043e\u043c\u0438\u0442\u044c\u0441\u044f, \u043f\u0435\u0440\u0435\u0439\u0434\u044f \u043f\u043e \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e\u0449\u0435\u0439 \u0441\u0441\u044b\u043b\u043a\u0435: \u043f\u0435\u0440\u0432\u0430\u044f, \u0432\u0442\u043e\u0440\u0430\u044f, \u0442\u0440\u0435\u0442\u044c\u044f, \u0447\u0435\u0442\u0432\u0451\u0440\u0442\u0430\u044f. \u0421\u0435\u0433\u043e\u0434\u043d\u044f \u043c\u044b \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0438\u043c \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u0438 \u043c\u043e\u043d\u0438\u0442\u043e\u0440\u0438\u043d\u0433\u0430 \u0432 Management Platform, \u0430 \u0438\u043c\u0435\u043d\u043d\u043e \u0440\u0430\u0431\u043e\u0442\u0443 \u0441 \u043b\u043e\u0433\u0430\u043c\u0438, \u0438\u043d\u0442\u0435\u0440\u0430\u043a\u0442\u0438\u0432\u043d\u044b\u043c\u0438 \u0434\u0430\u0448\u0431\u043e\u0440\u0434\u0430\u043c\u0438 (View) \u0438 \u043e\u0442\u0447\u0451\u0442\u0430\u043c\u0438. \u0422\u0430\u043a\u0436\u0435 \u0437\u0430\u0442\u0440\u043e\u043d\u0435\u043c \u0442\u0435\u043c\u0443 Threat Hunting \u0434\u043b\u044f \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u044f \u0430\u043a\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0445 \u0443\u0433\u0440\u043e\u0437 \u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":92914,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-92913","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/5-check-point-sandblast-agent-management-platform-logs-reports-forensics-threat-hunting\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd475. Check Point SandBlast Agent Management Platform. Logs, Reports &amp; Forensics. Threat Hunting | ProHoster\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/5-check-point-sandblast-agent-management-platform-logs-reports-forensics-threat-hunting\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-09-01T11:42:56+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-09-01T11:42:56+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd475. Check Point SandBlast Agent Management Platform. Logs, Reports &amp; Forensics. Threat Hunting | ProHoster","description":"","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/5-check-point-sandblast-agent-management-platform-logs-reports-forensics-threat-hunting","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd475. Check Point SandBlast Agent Management Platform. Logs, Reports &amp; Forensics. Threat Hunting | ProHoster","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/5-check-point-sandblast-agent-management-platform-logs-reports-forensics-threat-hunting","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-09-01T11:42:56+00:00","article:modified_time":"2020-09-01T11:42:56+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"92913","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 11:58:25","updated":"2022-09-30 07:34:54","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/92913","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=92913"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/92913\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/92914"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=92913"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=92913"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=92913"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}