
Enhanced Integration with IOC Live Feeds

Seamlessly connect HEC to trusted threat intelligence sources with new marketplace options and support for STIX/TAXII 2.1.
To stay ahead of evolving threats, many organizations connect their security systems to live feeds of Indicators of Compromise (IOCs). These feeds provide real-time threat intelligence – such as malicious IPs, URLs, domains, and file hashes – helping security teams detect and block emerging threats faster and more effectively.
HEC now supports expanded options for integrating with live IOC feeds:
-
Feed Marketplace: Instantly connect to verified, Check Point-maintained feeds from SWIFT, MS-ISAC, and FS-ISAC – no manual setup required.
-
STIX/TAXII 2.1 Support: When configuring custom integrations, HEC now supports the industry-standard STIX/TAXII 2.1 format for structured threat intelligence.
To configure integrations, visit Global IOC Management Input Feeds