> Source: [sk100633](https://support.checkpoint.com/results/sk/sk100633)

# sk100633 - Best Practices - threats investigation using Threat Prevention Software Blades 

| Property | Value |
|----------|-------|
| Solution ID | sk100633 |
| Date Created | 2014-05-14 |
| Last Modified | 2023-10-15 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server |
| Versions | R82.10, R82, R81.20, R82.10, R82, R81.20 |

## Solution

Introduction
------------

Organizations today are facing unprecedented growth in the diversity and number of security threats from advanced and sophisticated malware. These malicious attacks can focus on stealing data, sabotaging business continuity, and damaging an organization's reputation.

To help stay ahead of modern malware, early detection and rapid response is essential. Security teams should actively seek to identify and confirm infections before they proliferate in the environment. This proactive approach helps to save organization resources and minimizes malware damage.

Check Point's comprehensive Threat Prevention solution helps protect networks from today's sophisticated malware and cyber-attacks. Check Point introduces a multi-layered defense, that includes the Anti-Bot Software Blade. This blade provides a post-infection solution that detects and prevents bot threats by blocking the bot communication channel.

Threats investigation using Threat Prevention Software Blades
-------------------------------------------------------------

Follow the [Investigative Best Practices with Threat Prevention presentation](https://support.checkpoint.com/results/download/33206) to implement a response process for malware infections using Threat Prevention Software Blades. These guidelines and tools, focusing on real-time monitoring and interpretation of security events, should help you answer the following key questions:

* How can I investigate if a host is truly infected?
* What is the nature of the threat?
* Are there additional infected hosts in my network?

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
