Forescout eyeExtend for Check Point� Threat Prevention

Forescout eyeExtend ® for Check Point Threat Prevention

Strengthen advanced threat detection and accelerate threat response

Organizations deploy advanced threat detection (ATD) solutions such as Check Point Threat Prevention to detect and eliminate known and advanced cyberthreats via multiple methods of security analysis. However, the speed and evasiveness of today’s targeted attacks and increasing network complexity from a proliferation of network-attached devices—traditional campus, data center devices, cloud instances, unmanaged bring your own device (BYOD), Internet of Things (IoT), and transient—can overwhelm security defenses and render them ineffective. IT and security teams must have a complete picture of the entire enterprise attack surface and a comprehensive, automated response strategy to combat today’s cyberthreats, limit threat propagation and prevent security breaches and data exfiltration.

Forescout eyeExtend for Check Point Threat Prevention enhances the power of Check Point’s solution by helping organizations identify their entire attack surface, extend threat hunting to managed and unmanaged devices, and accelerate threat response.

Challenges

The Solution

Forescout eyeExtend for Check Point Threat Prevention orchestrates workflows between the Forescout platform and Check Point Threat Prevention to provide real-time device discovery and assessment for all network-connected devices, scan for indicators of compromise (IOCs) across all devices and accelerate threat response by isolating compromised devices in real time to prevent lateral threat propagation.

Check Point Threat Prevention fortifies network security by examining ingress and egress traffic and detecting and stopping bot command and control communications, unknown malware, viruses and file transfers. However, preventing unmanaged devices and devices infected on outside networks or via non-network pathways—such as USB devices—from connecting to the corporate network remains a challenge. Organizations must also find ways to determine the full extent of network infection and contain threats to prevent further internal propagation. It is often up to the IT or security staff to analyze threat information and determine the best way to stop attacks from spreading, resulting in unnecessary delays and errors that enable damaging data breaches.

This is where Forescout eyeExtend for Check Point Threat Prevention steps in. Forescout eyeExtend powered by Forescout eyeSight enables organizations to

Benefits

Highlights

In summary, Forescout eyeExtend for Check Point Threat Prevention helps organizations reduce their attack surface and prevents threats from spreading and breaching sensitive data.

Use Cases

Leverage shared threat intelligence to maximize joint threat hunting and detection

When Check Point Threat Prevention identifies malicious files and IOCs on managed devices, it immediately notifies Forescout eyeExtend for Check Point Threat Prevention. Forescout eyeExtend then extends this threat intelligence to the entire network using the Forescout platform, monitoring all network-connected devices—including unmanaged BYOD, guest and IoT devices—for IOCs. The Forescout platform also uses the threat information provided by Check Point Threat Prevention to scan newer or transiently connected devices for threat IOCs the moment they connect. It then initiates device isolation and remediation, preventing the spread of threats from any connected device across the network.

Accelerate and automate policy-driven threat response

Forescout eyeExtend helps organizations react in real time to threats based on predefined security policies using the Forescout platform. IT and security teams can create Forescout policies for handling anti-bot, antivirus and threat emulation detections. Based on policy and threat severity, the Forescout platform automatically takes appropriate actions such as restricting, isolating or blocking compromised devices and initiating remediation workflows. These actions reduce mean time to respond and limit the impact of threats.