> Source: [sk105167](https://support.checkpoint.com/results/sk/sk105167)

# sk105167 - ThreatCloud IntelliStore Quick Start Guide

| Property | Value |
|----------|-------|
| Solution ID | sk105167 |
| Date Created | 2015-03-10 |
| Last Modified | 2023-03-18 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Solution

**Table of Contents:**

1. Introduction
2. Prerequisites
3. Configuration Procedure
4. Appendix
   * Installing Add-On on Security Management Server
   * Viewing IntelliStore Hits in the User Center
   * Purchasing/Evaluating relevant IntelliStore feeds
   * Validating Feed Licensing and Entitlement
   * Reporting False Positives or Bad Classifications
   * Testing IntelliStore Feeds
5. Related solutions

(I) Introduction {#Introduction}
--------------------------------

This article provides a step-by-step guide for configuring and evaluating [ThreatCloud IntelliStore](http://www.checkpoint.com/products/threatcloud-intellistore/) - a unique threat intelligence marketplace that enables organizations to select intelligence feeds that will automatically prevent cyberattacks. IntelliStore is an extension of Check Point's core security intelligence infrastructure ? ThreatCloud?, which delivers threat data from a worldwide network of threat sensors.

This article is intended for Network Administrators, using Check Point R77.20 and above.

(II) Prerequisites {#Prerequisites}
-----------------------------------

1. The IntelliStore is supported on Security Gateway version R77.20 and above running on Gaia OS or SecurePlatform 2.6 OS.
2. Both Anti-Virus blade and Anti-Bot blade must be enabled on Security Gateway.
3. (Optional) To view IntelliStore Hits in the User Center:  
   * [R77.30 Add-On](http://supportcontent.checkpoint.com/solutions?id=sk105412) must be installed on *R77.30* Security Management Server.
   * [R77.20 Add-On](http://supportcontent.checkpoint.com/solutions?id=sk101217) must be installed on *R77.20* Security Management Server.

(III) Configuration Procedure {#Configuration Procedure}
--------------------------------------------------------

Configuration Procedure consists of two steps.

1. **Step 1 - Installing a hotfix on Security Gateway R77.20**

   **Note:** This step applies only to R77.20.
   On Security Gateway R77.20, follow the instructions in [sk102649 - Security Gateway R77.20 fails to fetch new IntelliStore feeds](http://supportcontent.checkpoint.com/solutions?id=sk102649).   

2. **Step 2 - Activating the feeds on Security Gateway**

   If you have not already purchased or evaluated IntelliStore feeds, then refer to "Appendix - Purchasing/Evaluating relevant IntelliStore feeds" section.
   1. Log in to the [User Center](https://usercenter.checkpoint.com/usercenter/index.jsp).   

   2. Go to ***ASSETS/INFO*** tab - click on ***Product Center***:

      [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Assets_Info_Product_Center.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Assets_Info_Product_Center.png "Click the image to see it in full size in a new tab/window")   

   3. Go to the ***Services*** tab. In the left upper corner, select the relevant account:

      [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Product_Center_Services_tab.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Product_Center_Services_tab.png "Click the image to see it in full size in a new tab/window")   

   4. Verify you have *valid* ***ThreatCloud IntelliStore*** feeds.

      **Note:** If you do not have valid feeds, then refer to section "Appendix - Purchasing/Evaluating relevant IntelliStore feeds".

      *Example*:
      [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Product_Center_Services_Valid.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Product_Center_Services_Valid.png "Click the image to see it in full size in a new tab/window")   

   5. Bind the IntelliStore feed to the selected Security Gateway(s) by clicking on the feed's name.

      *Example*:
      [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Product_Center_Services_Bind_IntelliStore_feed.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Product_Center_Services_Bind_IntelliStore_feed.png "Click the image to see it in full size in a new tab/window")   

   6. Choose on which Security Gateways you would like to activate the IntelliStore feeds:

      * Automatic on All Gateways
      * Manual on Selected Gateways

      <br />

      [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Activation_mode.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Activation_mode.png "Click the image to see it in full size in a new tab/window")   

   7. Select the feed policy for the Security Gateway:

      * Use Gateway Policy \& Hit Analysis
      * Log \& Hit Analysis
      * Hit Analysis
      * Inactive

      **Note:** The policy selection would affect the Security Gateway only if you have installed the Management Add-On (as described in the "Appendix - Installing Add-On on Security Management Server" section). If the Management Add-On is *not* installed, then the feeds will use the Security Gateway's default settings.

      [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Feed_policy.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Feed_policy.png "Click the image to see it in full size in a new tab/window")

      Policy feed selection options:
      [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Feed_policy_help.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Feed_policy_help.png "Click the image to see it in full size in a new tab/window")   

   8. Click on ***Save*** button in the upper right corner.

      *Example*:
      [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Save.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Save.png "Click the image to see it in full size in a new tab/window")   

   9. Repeat ***Steps E-G*** for *each* of the IntelliStore feeds.   

   10. Connect with SmartDashboard to Security Management Server / Domain Management Server.   

   11. Install the Network Security and Threat Prevention policy onto the selected Security Gateways.   

   12. Verify the feeds have been updated on the selected Security Gateways. Refer to the "Appendix - Validating Feed Licensing and Entitlement" section.

(IV) Appendix {#Appendix}
-------------------------

### Appendix - Installing Add-On on Security Management Server {#Appendix - Installing Add-On on Security Management Server}

The Management Add-On provides the ability to integrate the User Center to the Security Gateways as well as to view IntelliStore feed hits and analysis in the User Center website. This Add-On is a prerequisite to view IntelliStore Hits in the User Center.

Follow the instructions in:

* [sk105412 - R77.30 Add-On](http://supportcontent.checkpoint.com/solutions?id=sk105412).
* [sk101217 - R77.20 Add-On](http://supportcontent.checkpoint.com/solutions?id=sk101217).

### Appendix - Viewing IntelliStore Hits in the User Center {#Appendix - Viewing IntelliStore Hits in the User Center}

1. Install the Management Add-On as described in:

   * [sk105412 - R77.30 Add-On](http://supportcontent.checkpoint.com/solutions?id=sk105412).
   * [sk101217 - R77.20 Add-On](http://supportcontent.checkpoint.com/solutions?id=sk101217).

   <br />

   <br />

2. Connect with SmartDashboard to Security Management Server / Domain Management Server.   

3. Open the properties of the involved Security Gateway / Cluster object.   

4. Go to ***Anti-Bot and Anti-Virus*** pane.   

5. Check the following boxes in the ***Check Point ThreatCloud*** section:

   * `Share anonymous attack information with Check Point ThreatCloud`
   * `Allow me to view attack statistics in my User Center account`

   <br />

   [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/GW_Properties_AV_AB.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/GW_Properties_AV_AB.png "Click the image to see it in full size in a new tab/window")   

6. Click on *OK* to apply the changes.   

7. Install the policy on this Security Gateway / Cluster object.   

8. Log in to the [User Center](https://usercenter.checkpoint.com/usercenter/index.jsp).   

9. Go to ***ASSETS/INFO*** tab - click on ***Product Center***:

   [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Assets_Info_Product_Center.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Assets_Info_Product_Center.png "Click the image to see it in full size in a new tab/window")   

10. Go to the ***Services*** tab. In the left upper corner, select the relevant account:

    [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Product_Center_Services_tab.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Product_Center_Services_tab.png "Click the image to see it in full size in a new tab/window")   

11. In the ***ThreatCloud IntelliStore*** line, click on the number in the ***Valid*** column.   

12. Click on ***Show IntelliStore Hits*** button.

    *Example*:
    [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Show_IntelliStore_Hits.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Show_IntelliStore_Hits.png "Click the image to see it in full size in a new tab/window")   

13. A resulting table will be displayed outlining the hit count from all valid feeds during the last 30 days.

    **Note:** The hit count in the User Center may take up to 2 hours to update.

    *Example*:
    [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/IntelliStore_Hit_Count.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/IntelliStore_Hit_Count.png "Click the image to see it in full size in a new tab/window")   

14. In the resulting table, you can click any of the hit count numbers to get a detailed report of the detected malware.   

15. You can also click on any one of the tabs to view analysis of the hits per severity, trend line, or to compare the different active feeds.

    *Example of Trend Line*:
    [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Hits_Trend_Line.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Hits_Trend_Line.png "Click the image to see it in full size in a new tab/window")

### Appendix - Purchasing/Evaluating relevant IntelliStore feeds {#Appendix - Purchasing/Evaluating relevant IntelliStore feeds}

1. Log in to the [User Center](https://usercenter.checkpoint.com/usercenter/index.jsp).   

2. Go to ***SALES TOOLS*** tab - click on ***Product Catalog \& Quoting***:

   [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Sales_Tools_Product_Catalog_and_Quoting.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Sales_Tools_Product_Catalog_and_Quoting.png "Click the image to see it in full size in a new tab/window")   

3. Click on ***NETWORK SECURITY*** tab - in the section ***Security Cloud Services \& Mobility*** , click on ***ThreatCloud IntelliStore***:

   [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Product_Catalog_and_Quoting_ThreatCloud_IntelliStore.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Product_Catalog_and_Quoting_ThreatCloud_IntelliStore.png "Click the image to see it in full size in a new tab/window")   

4. Click on each feed, in which you are interested:

   * For evaluating this feed, click on ***Try Now*** button.
   * For purchasing this feed, click on ***Select*** button.

   *Example*:
   [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Product_Catalog_and_Quoting_ThreatCloud_IntelliStore_Feed_evaluate_purchase.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Product_Catalog_and_Quoting_ThreatCloud_IntelliStore_Feed_evaluate_purchase.png "Click the image to see it in full size in a new tab/window")   

5. Make sure you select the account, in which you would like to activate the feeds.

   *Example*:
   [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Product_Catalog_and_Quoting_ThreatCloud_IntelliStore_Feed_select_account.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Product_Catalog_and_Quoting_ThreatCloud_IntelliStore_Feed_select_account.png "Click the image to see it in full size in a new tab/window")   

6. Once you have selected your feeds, you should be able to see them in your User Center Services section, as detailed in Step 3 above.

### Appendix - Validating Feed Licensing and Entitlement {#Appendix - Validating Feed Licensing and Entitlement}

**Note:** It may take several minutes (up to 5) for the feeds to get updated on the Security Gateway after activating them in the User Center.

1. Connect with SmartView Monitor to Security Management Server / Domain Management Server.   

2. In the upper right pane, select the relevant Security Gateway / cluster member.   

3. In the lower pane, in the ***Anti-Bot \& Anti-Virus*** section, click on ***More...***

   *Example*:
   [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/SmartView_Monitor_More.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/SmartView_Monitor_More.png "Click the image to see it in full size in a new tab/window")   

4. Scroll to the bottom of the displayed screen - in the lower left corner, click on ***ThreatCloud IntelliStore*** link.

   *Example*:
   [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/SmartView_Monitor_ThreatCloud_IntelliStore.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/SmartView_Monitor_ThreatCloud_IntelliStore.png "Click the image to see it in full size in a new tab/window")   

5. Verify that the appropriate feeds are listed (Anti-Virus *and* Anti-Bot).

   *Example*:
   [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/SmartView_Monitor_ThreatCloud_IntelliStore_Feeds.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/SmartView_Monitor_ThreatCloud_IntelliStore_Feeds.png "Click the image to see it in full size in a new tab/window")   

6. **For R77.20 and R77.30 only:** Refer to [sk104601 - Check Point ThreatCloud IntelliStore partners names mapping](http://supportcontent.checkpoint.com/solutions?id=sk104601).

### Appendix - Reporting False Positives or Bad Classifications {#Appendix - Reporting False Positives or Bad Classifications}

Each vendor is responsible for the quality and validity of his feed. If you feel events triggered are erroneous or false positives, you can report them using the following procedure:

1. Connect with SmartEvent GUI to SmartEvent Server.   

2. Go to *Threat Prevention* tab.   

3. Locate the event you would like to report.   

4. Right-click on the event - click on "*Report Event to Check Point*".

   *Example*:
   [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Report_Event_to_Check_Point1505071256.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Report_Event_to_Check_Point1505071256.png "Click the image to see it in full size in a new tab/window")   

5. You may add any additional information, which can help the feed vendor asses your incident.  
   If you would like to receive updates or correspondence from the vendor, then add your e-mail address.

   *Example*:
   [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Report_Event_to_Check_Point_window1505071257.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/Report_Event_to_Check_Point_window1505071257.png "Click the image to see it in full size in a new tab/window")   

6. Click on *Send* button.

You may also report a wrong classification in Check Point UserCheck screen when "Prevent" mode is configured in the appropriate policy. The UserCheck screen is visible to the end-customers who trigger an Anti-Virus or an Anti-Bot event.

Reporting a wrong classification can be performed by clicking the link as illustrated in the example below:

[![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/UserCheck_report1505071257.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105167/UserCheck_report1505071257.png "Click the image to see it in full size in a new tab/window")

### Appendix - Testing IntelliStore Feeds {#Appendix - Testing IntelliStore Feeds}

You may use the table below to verify the IntelliStore feeds are indeed identified by the Security Gateways (through the SmartLog or SmartView Tracker).

If you have installed and configured the R77.20/R77.30 Add-On, you should be able to see the hits analysis in the User Center (allow 2 hours for hits to be presented).

The links below are ***harmless*** and do ***NOT*** include any malware.

**Important Note: Make sure you have configured the feeds correctly and checked for licensing entitlement BEFORE clicking these links (refer to "Validating Feed Licensing and Entitlement" section). If you click these links before the feeds have been updated, your Security Gateway will include the test domain as benign to the Security Gateway's cache. It may take as long as 24 hours for the Security Gateway's cache to clear and re-check ThreatCloud.**

|-----------------|--------------------------------------------------------------------------|-----------------------------------------------------------------------------|
| Vendor          | Anti-Virus Test link                                                     | Anti-Bot Test link                                                          |
| CrowdStrike     | <http://www.threat-cloud.com/IntelliStore/test/CrowdStrike_test.html>    | <http://www.threat-cloud.com/IntelliStore/test/CrowdStrike_test_AB.html>    |
| IID             | <http://www.threat-cloud.com/IntelliStore/test/IID_test.html>            | <http://www.threat-cloud.com/IntelliStore/test/IID_test_AB.html>            |
| iSIGHT Partners | <http://www.threat-cloud.com/IntelliStore/test/iSIGHT_Partners_test.htm> | <http://www.threat-cloud.com/IntelliStore/test/iSIGHT_Partners_test_AB.htm> |
| Malware Patrol  | <http://www.threat-cloud.com/IntelliStore/test/Malware_Patrol_test.html> | <http://www.threat-cloud.com/IntelliStore/test/Malware_Patrol_test_AB.html> |
| Mnemonic        | <http://www.threat-cloud.com/IntelliStore/test/Mnemonic_test.html>       | <http://www.threat-cloud.com/IntelliStore/test/Mnemonic_test_AB.html>       |
| NetClean        | <http://www.threat-cloud.com/IntelliStore/test/NetClean_test.html>       | This vendor has no Anti-Bot                                                 |
| Norse           | <http://www.threat-cloud.com/IntelliStore/test/Norse_test.html>          | <http://www.threat-cloud.com/IntelliStore/test/Norse_test_AB.html>          |
| PhishLabs       | <http://www.threat-cloud.com/IntelliStore/test/PhishLabs_test.htm>       | <http://www.threat-cloud.com/IntelliStore/test/PhishLabs_test_AB.htm>       |
| SentryBay       | <http://www.threat-cloud.com/IntelliStore/test/SentryBay_test.htm>       | <http://www.threat-cloud.com/IntelliStore/test/SentryBay_test_AB.htm>       |
| SenseCy         | <http://www.threat-cloud.com/IntelliStore/test/SenseCy_test.html>        | <http://www.threat-cloud.com/IntelliStore/test/SenseCy_test_AB.html>        |
| ZeroFOX         | <http://www.threat-cloud.com/IntelliStore/test/ZeroFox_test.html>        | This vendor has no Anti-Bot                                                 |

(V) Related solutions {#Related solutions}
------------------------------------------

* [sk105412 - R77.30 Add-On](http://supportcontent.checkpoint.com/solutions?id=sk105412)  

* [sk101217 - R77.20 Add-On](http://supportcontent.checkpoint.com/solutions?id=sk101217)  

* [sk102649 - Security Gateway R77.20 fails to fetch new IntelliStore feeds](http://supportcontent.checkpoint.com/solutions?id=sk102649)  

* [sk104601 - Check Point ThreatCloud IntelliStore partners names mapping](http://supportcontent.checkpoint.com/solutions?id=sk104601)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
