Harmony Endpoint HealthCheck - Sample Report

PROFESSIONAL SERVICES HARMONY ENDPOINT HEALTH CHECK REPORT

EXECUTIVE SUMMARY

The following document summarizes the information collected from up to two (2) Harmony Endpoint Server(s). The project took place between [ date - begin ] and [ date - end ].

The project examined the deployment of your Harmony solution and identified opportunities to optimize your Endpoint Security Management System.

Each recommendation is rated as follows:

X Serious Needs immediate attention.
! Attention Needs attention.
√ Good No need for any action.

CONTROL CHANGE

Version Date Description Author
Initial 19/01/2022 Initial Document John Smith (Check Point)

ABBREVIATIONS

ABBREVIATION DEFINITION
PS Professional Services
GUI Graphical User Interface
SG Security Gateway
VAP Virtual Application Processor
VSX Virtual Network Extender
VS Virtual System
SMS Security Management Server
SO Smart Optimize

SERVER INFORMATION

HOSTNAME STATUS VERSION OS SW BLADES REMEDIATION
EPSRV01 ! R80.40 Gaia Anti-Malware Media Encryption & Port Protection Firewall and Access Zones Full Disk Encryption SandBlast Agent Anti-Bot SandBlast Agent Anti-Ransomware, Behavioral Guard and Forensics SandBlast Agent Threat Extraction, Emulation and Anti-Exploit Upgrade to R81.10 version

LICENSE INFORMATION

License Status Report

STATUS COUNT PERCENT REMEDIATION
Total of Endpoint Seats √ 5884/7450 78%

All licenses are valid.

INTRODUCTION

[ COMPANY_NAME ] has deployed Check Point Endpoint Security to ( # ) endpoints throughout their organization.

HARDWARE NAME VERSION FIXES CPU RAM
VM EPSRV01 R80.40 N/A 8 Cores 32 GB

ENVIRONMENT

RECOMMENDATIONS AND BEST PRACTICES

Detected 700 devices with object duplicated; consider deleting the duplicated objects.

Review the following list of Endpoint devices with licenses and no connectivity to Endpoint server for more than 30 days:

nid distinguished_name
e5f5e588-93e2-3c42-af1a-4253dc18e42e CN=FCBARADJ05L1R5,OU=Desktops,OU=Windows 10 Machines,DC=WI,DC=FCIB,DC=com
e4f84447-36fb-46f5-8f6d-cbd666a1d597 CN=FCIBANTINS001,CN=Computers,DC=WI,DC=FCIB,DC=com
f62d5bc0-f479-4b5b-b59f-d1cdc015eaa0 CN=FCCAYADJ07N0NS,OU=Desktops,OU=Windows 10 Machines,DC=WI,DC=FCIB,DC=com
f5a16ef4-5595-9c40-ae2d-9c5df0810836 CN=FCANTADJ05L1YY,OU=Desktops,OU=Windows 10 Machines,DC=WI,DC=FCIB,DC=com
06d82713-4788-4a45-ba92-d82f3820bfbb CN=FCGRE_L0Z8GYL,FN=deleted
b26a23f6-c48f-47f3-8859-a402557275a6 CN=W92700KENL,FN=deleted
a5b5187b-f9e5-4aeb-b5a6-835b3c0a3e40 CN=FCJAMADJ04LNEM,OU=Desktops,OU=Windows 10 Machines,DC=WI,DC=FCIB,DC=com
946ba15b-d2ef-40fa-80ee-5b8b6296a28f CN=FCBAR7LC0AKNZ3,FN=deleted
992f6572-811f-4277-adae-68731367ba92 CN=FCBAR7DJ04LND0,FN=deleted
a7ca6649-d3e5-d941-aa95-7e9839290aec CN=FCBAH_LXEBBDL,FN=deleted

BLADES

There are 31 Endpoint clients not reporting the status of software blades or state unknown. This could be a general error; to fix the status of the clients, ensure processes are running in the background, and that there is connectivity to the Endpoint Management Server. If the problem persists, consider re-installing the Endpoint software.

FULL DISK ENCRYPTION

MEDIA ENCRYPTION AND PORT PROTECTION

  1. Comment rule #1 and #5 (offline), and rule #1,#3,#4,#5,#7 (online) for audit and compliance purposes.
  2. For client upgrade, it is highly recommended to test certain conditions before (crashes of MEPP driver MeDlpFlt reported on E86.01, solved on E86.10):
    • Encrypt device USB or HDD with E84.50.
    • Test upgrade to E86.20.
    • Validate that the USB is encrypted; the user should have access to data.

ANTI-MALWARE

Under the Anti-Malware blade, Scan Optimization action "Scan priority will be lower than other running processes" should be checked if there are performance issues with the Anti-Malware blade.

Any 3rd party Anti-Malware solution should be disabled on all machines before deploying the Endpoint Security Client. Select Randomize scan time to ensure that not all computers perform a scan for malware simultaneously.

Edit Properties - Periodical Scan Schedule

Select action:

Exclusion area: Exclusion locations could be where the folders used by the application are located.

SANDBLAST AGENT ANTI-RANSOMWARE, BEHAVIORAL GUARD AND FORENSICS.

Anti-Ransomware, Behavior Guard and Forensics Blade Overview:

Anti-Ransomware is an automated process that creates point-in-time backups of user file data as an executable is attempting to read and write to the file system. This process generates honeypot folders and stores backups in a vault that is only readable by the Check Point system account.

Behavior Guard utilizes real-time dynamic analysis to determine executable behavior for resemblance to malware families, identifying zero-day threats in real-time.

Forensics aids from an EDR perspective by monitoring and logging executable behavior to provide forensics reports post-event.

SANDBLAST AGENT ANTI-BOT

The purpose of this blade is to monitor network traffic directed at Command and Control centers for potential instructions to pull down malicious code.

Best Practice configuration

Exclude trusted domains:

Exclusions for trusted entities:

Exclusion Name Exclusion Type
protected.domains Domain
https://protected.URLs URL

THREAT EXTRACTION, EMULATION AND ANTI-EXPLOIT

Threat Extraction can quickly provide sanitized copies of potential malware before final delivery to the end-user. Anti-Exploit additionally monitors vulnerable applications for threats.

Best Practice configuration

Ensure to add known safe locations and folders for applications to avoid unnecessary risk.

ANTI-EXPLOIT ENGINE

The Anti-exploit engine evaluates highly exploitable applications and adds exceptions as necessary for false positives.

FIREWALL

Endpoint Security client installation disables Windows Defender Firewall using Microsoft's "wscsvc" service. Ensure this service is disabled before deploying the Endpoint Security Client.

APPLICATION CONTROL / URL FILTERING

This feature is currently disabled:

Rule Name Action
Default Application Control settings Disables Application Control

VIRTUAL GROUPS BEST PRACTICES

To test new Operating Systems and new hardware, create separate Virtual Groups to configure new policies transparently without affecting all devices.

  1. Create a Virtual Group named Staging.
  2. Create a Virtual Group for Troubleshooting, allowing temporary movement of machines to disable features or modify security policies.

SYSTEM HEALTHCHECK

Platform Model
VMware Virtual Platform Intel(R) Xeon(R) CPU E5-2650 v3

Known Issues:

CONCLUSION

The general feedback is that the Check Point configuration is adequate but improvements must be made towards best practices. The transition may take weeks, and Check Point Professional Services can assist through this process.

On behalf of Check Point Professional Services, I express gratitude for your loyalty.

Report Completed on: