Enrich Incident Investigations with ThreatCloud Intelligence
Check Point Email Security now enriches incident investigations with ThreatCloud intelligence, providing immediate context for indicators of compromise directly within the investigation workflow.
When investigating email or collaboration security incidents, analysts often need to understand why a sender, URL, or attachment was classified as malicious or legitimate. ThreatCloud – Check Point’s AI-powered threat intelligence platform – aggregates intelligence from billions of indicators, global sensors, and real-time research. Check Point Email Security now brings that intelligence directly into the investigation workflow, providing immediate context for every IOC without leaving the incident page.
A new intelligence icon is now available next to senders, URLs, and attachments on the incident page. Clicking the icon opens a detailed IOC intelligence panel, allowing analysts to explore the context behind the selected indicator without interrupting their investigation. The panel provides valuable insights, including associated threat actors, geographic and time-based activity distribution, detected malicious activities, reputation data, and additional intelligence collected by ThreatCloud.
By enriching investigations with integrated threat intelligence, Check Point Email Security helps SOC teams validate threats faster, better understand the context behind suspicious indicators, and make more informed response decisions. Eliminating the need to pivot to external threat intelligence tools streamlines investigations and enables analysts to respond to threats with greater speed and confidence.
This feature is gradually being deployed and will be available in customer portals over the next 7 days.



