# PROFESSIONAL SERVICES HARMONY ENDPOINT HEALTH CHECK REPORT

## EXECUTIVE SUMMARY

The following document summarizes the information collected from up to two (2) Harmony Endpoint Server(s). The project took place between [ date - begin ] and [ date - end ].

The project examined the deployment of your Harmony solution and identified opportunities to optimize your Endpoint Security Management System.

Each recommendation is rated as follows:

| X | Serious | Needs immediate attention. |
|---|---------|--------------------------|
| ! | Attention| Needs attention. |
| √ | Good    | No need for any action.  |

## CONTROL CHANGE

| Version | Date       | Description        | Author                 |
|---------|------------|---------------------|-----------------------|
| Initial | 19/01/2022 | Initial Document     | John Smith (Check Point)|

## ABBREVIATIONS

| ABBREVIATION | DEFINITION                  |
|--------------|----------------------------|
| PS           | Professional Services       |
| GUI          | Graphical User Interface    |
| SG           | Security Gateway            |
| VAP          | Virtual Application Processor|
| VSX          | Virtual Network Extender    |
| VS           | Virtual System              |
| SMS          | Security Management Server   |
| SO           | Smart Optimize              |

## SERVER INFORMATION

| HOSTNAME | STATUS | VERSION | OS   | SW BLADES                                                                                                                   | REMEDIATION                   |
|----------|--------|---------|------|-----------------------------------------------------------------------------------------------------------------------------|-------------------------------|
| EPSRV01  | !      | R80.40  | Gaia| Anti-Malware Media Encryption & Port Protection Firewall and Access Zones Full Disk Encryption SandBlast Agent Anti-Bot SandBlast Agent Anti-Ransomware, Behavioral Guard and Forensics SandBlast Agent Threat Extraction, Emulation and Anti-Exploit | Upgrade to R81.10 version     |

## LICENSE INFORMATION

### License Status Report

| STATUS | COUNT      | PERCENT | REMEDIATION |
|--------|------------|---------|-------------|
| Total of Endpoint Seats | √ | 5884/7450 | 78% | N/A |

All licenses are valid.

## INTRODUCTION

[ COMPANY_NAME ] has deployed Check Point Endpoint Security to ( # ) endpoints throughout their organization.

| HARDWARE | NAME   | VERSION | FIXES | CPU       | RAM   |
|----------|--------|---------|-------|-----------|-------|
| VM       | EPSRV01| R80.40  | N/A   | 8 Cores   | 32 GB |

### ENVIRONMENT

- Clients communicate with the Management Server over HTTP/HTTPS.
- The Endpoint Management architecture works in a "star" scheme to support large-scale.
- The central "brain" of the system is the "Management Server" and the delegate servers are named "Policy Servers."
- Each Management Server can support a maximum of ~10,000 endpoints. Multiple Policy Servers can be chained to support a management of up to 400,000 devices from a single environment.
- The environment supports unified log reporting through SmartLog.

## RECOMMENDATIONS AND BEST PRACTICES

- **Check Point recommends** that you install the most recent software release to stay up-to-date with the latest functional improvements, stability fixes, security enhancements, and protection against new and evolving attacks. The last version that we have seen working good is R81 and the recommended Take is the GA, at this moment it is the Take: 44.
- It is best practice and recommended to thoroughly test the latest recommended Harmony Endpoint client version before deploying to production machines. The latest recommended version can be found on the Endpoint Security Homepage, sk117536.
- The release notes for the specific client version should be reviewed carefully to ensure the Harmony Endpoint client and blades are deployed to supported client machines. The current recommended Harmony Endpoint client for Windows is E86.20; see E86.20 Endpoint Security Client for Windows Release Notes.
- Create Virtual Group for staging and troubleshooting purposes.

**Detected 700 devices with object duplicated; consider deleting the duplicated objects.**

Review the following list of Endpoint devices with licenses and no connectivity to Endpoint server for more than 30 days:

| nid                                   | distinguished_name                                                                                                           |
|---------------------------------------|------------------------------------------------------------------------------------------------------------------------------|
| e5f5e588-93e2-3c42-af1a-4253dc18e42e | CN=FCBARADJ05L1R5,OU=Desktops,OU=Windows 10 Machines,DC=WI,DC=FCIB,DC=com                                               |
| e4f84447-36fb-46f5-8f6d-cbd666a1d597 | CN=FCIBANTINS001,CN=Computers,DC=WI,DC=FCIB,DC=com                                                                       |
| f62d5bc0-f479-4b5b-b59f-d1cdc015eaa0 | CN=FCCAYADJ07N0NS,OU=Desktops,OU=Windows 10 Machines,DC=WI,DC=FCIB,DC=com                                             |
| f5a16ef4-5595-9c40-ae2d-9c5df0810836 | CN=FCANTADJ05L1YY,OU=Desktops,OU=Windows 10 Machines,DC=WI,DC=FCIB,DC=com                                             |
| 06d82713-4788-4a45-ba92-d82f3820bfbb | CN=FCGRE_L0Z8GYL,FN=deleted                                                                                               |
| b26a23f6-c48f-47f3-8859-a402557275a6 | CN=W92700KENL,FN=deleted                                                                                                  |
| a5b5187b-f9e5-4aeb-b5a6-835b3c0a3e40 | CN=FCJAMADJ04LNEM,OU=Desktops,OU=Windows 10 Machines,DC=WI,DC=FCIB,DC=com                                             |
| 946ba15b-d2ef-40fa-80ee-5b8b6296a28f | CN=FCBAR7LC0AKNZ3,FN=deleted                                                                                              |
| 992f6572-811f-4277-adae-68731367ba92 | CN=FCBAR7DJ04LND0,FN=deleted                                                                                              |
| a7ca6649-d3e5-d941-aa95-7e9839290aec | CN=FCBAH_LXEBBDL,FN=deleted                                                                                               |

## BLADES

There are 31 Endpoint clients not reporting the status of software blades or state unknown. This could be a general error; to fix the status of the clients, ensure processes are running in the background, and that there is connectivity to the Endpoint Management Server. If the problem persists, consider re-installing the Endpoint software.

## FULL DISK ENCRYPTION

## MEDIA ENCRYPTION AND PORT PROTECTION

1. Comment rule #1 and #5 (offline), and rule #1,#3,#4,#5,#7 (online) for audit and compliance purposes.
2. For client upgrade, it is highly recommended to test certain conditions before (crashes of MEPP driver MeDlpFlt reported on E86.01, solved on E86.10):
   - Encrypt device USB or HDD with E84.50.
   - Test upgrade to E86.20.
   - Validate that the USB is encrypted; the user should have access to data.

## ANTI-MALWARE

Under the Anti-Malware blade, Scan Optimization action "Scan priority will be lower than other running processes" should be checked if there are performance issues with the Anti-Malware blade.

Any 3rd party Anti-Malware solution should be disabled on all machines before deploying the Endpoint Security Client. Select Randomize scan time to ensure that not all computers perform a scan for malware simultaneously.

### Edit Properties - Periodical Scan Schedule

Select action:

- Anti-MW Perform periodic anti-malware scan

**Exclusion area:** Exclusion locations could be where the folders used by the application are located.

## SANDBLAST AGENT ANTI-RANSOMWARE, BEHAVIORAL GUARD AND FORENSICS.

### Anti-Ransomware, Behavior Guard and Forensics Blade Overview:

Anti-Ransomware is an automated process that creates point-in-time backups of user file data as an executable is attempting to read and write to the file system. This process generates honeypot folders and stores backups in a vault that is only readable by the Check Point system account.

Behavior Guard utilizes real-time dynamic analysis to determine executable behavior for resemblance to malware families, identifying zero-day threats in real-time.

Forensics aids from an EDR perspective by monitoring and logging executable behavior to provide forensics reports post-event.

## SANDBLAST AGENT ANTI-BOT

The purpose of this blade is to monitor network traffic directed at Command and Control centers for potential instructions to pull down malicious code.

### Best Practice configuration

Exclude trusted domains:
- **Best Practice - Domain inspection**

### Exclusions for trusted entities:
| Exclusion Name         | Exclusion Type |
|------------------------|----------------|
| protected.domains      | Domain         |
| https://protected.URLs | URL            |

## THREAT EXTRACTION, EMULATION AND ANTI-EXPLOIT

Threat Extraction can quickly provide sanitized copies of potential malware before final delivery to the end-user. Anti-Exploit additionally monitors vulnerable applications for threats.

### Best Practice configuration

Ensure to add known safe locations and folders for applications to avoid unnecessary risk.

## ANTI-EXPLOIT ENGINE

The Anti-exploit engine evaluates highly exploitable applications and adds exceptions as necessary for false positives.

## FIREWALL

Endpoint Security client installation disables Windows Defender Firewall using Microsoft's "wscsvc" service. Ensure this service is disabled before deploying the Endpoint Security Client.

## APPLICATION CONTROL / URL FILTERING

This feature is currently disabled:

| Rule Name | Action                                       |
|-----------|---------------------------------------------|
| Default Application Control settings | Disables Application Control      |

## VIRTUAL GROUPS BEST PRACTICES

To test new Operating Systems and new hardware, create separate Virtual Groups to configure new policies transparently without affecting all devices.

1. Create a Virtual Group named Staging.
2. Create a Virtual Group for Troubleshooting, allowing temporary movement of machines to disable features or modify security policies.

## SYSTEM HEALTHCHECK

| Platform               | Model                               |
|-----------------------|-------------------------------------|
| VMware Virtual Platform | Intel(R) Xeon(R) CPU E5-2650 v3  |

### Known Issues:
- EPSRV01 kernel: fwm[9054]: segfault error in libDataStruct.so.

## CONCLUSION

The general feedback is that the Check Point configuration is adequate but improvements must be made towards best practices. The transition may take weeks, and Check Point Professional Services can assist through this process.

On behalf of Check Point Professional Services, I express gratitude for your loyalty.

**Report Completed on:**

---

---

---

---

---

---

---

---

---

---

---

---

---
