> Source: [sk115236](https://support.checkpoint.com/results/sk/sk115236)

# sk115236 - CheckMe - Instant Security Check

| Property | Value |
|----------|-------|
| Solution ID | sk115236 |
| Date Created | 2017-01-01 |
| Last Modified | 2026-02-17 |
| Technical Level | General |
| Products | Other |
| Versions | Not Version-Specific |

## Solution

**ARE YOU VULNERABLE TO NEW TYPES OF ATTACKS?**

CheckMe service **simulates** many types of attacks that can compromise your computer and the information on your network.  
This service includes a series of tests that check the vulnerability of your network, endpoint and mobile to  
Ransomware, Phishing, Zero Day, Bot communication, Browser Exploit, Anonymize usage and Data leakage.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk115236/flowchart_full image1701040436.png)

What threats are being checked?
-------------------------------

Show / Hide this section  
CheckMe **simulates** various scenarios that could be a starting point for the following attack vectors:

|-----------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------|
| ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk115236/Ransomware_Attack.png)      | **Ransomware**is an attack that takes advantage of a particular vulnerability in a computing system.                                         |
| ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk115236/e21803200105.jpg)          | **Command \& Control Communication**let attackers take complete control over an infected computer.                                           |
| ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk115236/Zero_Day.png)               | **Zero Day**attacks use the surprise element to exploit holes in the software that are unknown to the vendor.                                |
| ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk115236/Bot_Infection.png)          | **Malware Infection** is used to gather guarded information or disrupt corporate, governance and individual operation.                       |
| ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk115236/Browser_Code_Injection.png) | **Browser Exploit**is an attack that takes advantage of a particular vulnerability in a computing system.                                    |
| ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk115236/e31803200109.jpg)          | **Persistent Malware** is a continuous computer hacking processes targets private organizations or states for business or political motives. |
| ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk115236/Anonymizer_Usage.png)       | **Anonymous surfing** allows users to hide their online activity. It can open backdoor into an organization's network.                       |
| ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk115236/Sensitive_Data_Leakage.png) | **Data leakage** is the transfer of classified or sensitive information outside an organization's network by theft or accidental exposure.   |
| ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk115236/e41803200113.jpg)          | **Cloud Segmentation**scans for open ports of accessible machines within the same environment to indicate for access control lacking.        |

Tests Specifications \& Remediation Guidelines
----------------------------------------------

Show / Hide this section  
The table below summarizes different attacks that were used during the simulation and explanation how to remediate each attack.

|--------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Threat             | Test Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | Remediation Guidelines                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Malware Infection  | **Network** This test downloads a test-infected file (EICAR) through your network. * http://files.checkme.checkpoint.com/e.txt * https://files.checkme.checkpoint.com/e.zip * http://files.checkme.checkpoint.com/getcfg.php?SERVICES=DEVICE.LOG\&x=y\&AUTHORIZED_GROUP=1 <br /> Note: It is supported on 700 / 1200R / 1400 SMB appliances running R77.20.70 and higher and not supported on 600 / 1100 appliances. **Endpoint** This test simulates malware infection by downloading an exe which create an EICAR file. In case that EICAR file is deleted after few seconds it means that the endpoint is well protected. | Improve your security with Check Point [Threat Prevention](https://www.checkpoint.com/products-solutions/threat-prevention-appliances-and-software/) and [Endpoint Security](https://www.checkpoint.com/harmony/advanced-endpoint-protection/) solution by following these steps: **Network** 1. Make sure your [Anti-Virus](https://www.checkpoint.com/products/antivirus-software-blade/) and [IPS](https://www.checkpoint.com/products/ips-software-blade/) blades are configured based on the Check Point "Optimized" Profile. 2. Enable the "Archive scanning" in your [Anti-Virus](https://www.checkpoint.com/products/antivirus-software-blade/) blade (in the Threat Prevention profile). 3. Enable the [HTTPS Inspection](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108202) feature to inspect HTTPS traffic.Enable the [IPS](https://www.checkpoint.com/products/ips-software-blade/) blade and ensure that IPS protections are up to date. 4. In case it is not possible to update the IPS protections to the latest release, enable the following IPS protection: D-Link Routers Information Disclosure <br /> **Endpoint** Improve your network security with Check Point [Endpoint Security](https://www.checkpoint.com/harmony/advanced-endpoint-protection/) which includes Anti-Malware blade, whose default settings block malware files. |
| C\&C Communication | This test simulates C\&C communication via a known Command and Control protocol. **Network** CheckMe simulates this test by posting: * creditcard=1234\&expyear=2017\&ccv=123\&pin=1234 To: * http://files.checkme.checkpoint.com/post.html <br /> **Endpoint** CheckMe simulate this test with the following get command: `curl --user-agent "Miner" http://www.threat-cloud.com/config.php`                                                                                                                                                                                                                                | Improve your security with Check Point [Next Generation Threat Prevention](https://www.checkpoint.com/products-solutions/threat-prevention-appliances-and-software/) and [Endpoint Security](https://www.checkpoint.com/harmony/advanced-endpoint-protection/) that includes Anti-Bot blade, whose default settings block access to Command and Control servers.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Ransomware         | **Endpoint** This test simulates a ransomware attack by creating files in the user's Downloads directory and encrypts them using AES (Advanced Encryption Standard) and generated key with usage of MD5 of current user SID, And open CMD process. In case that the encryption process has terminated after few seconds that endpoint is well protected.                                                                                                                                                                                                                                                                     | Improve your endpoint security with Check Point [Endpoint Security](https://www.checkpoint.com/harmony/advanced-endpoint-protection/) that includes [Anti Ransomware](http://pages.checkpoint.com/anti-ransomware.html) component, whose default settings block ransomware attacks. **Note** that Anti-Ransomware is available from version E80.70.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Browser Exploit    | **Network** This test checks if your network is protected against Cross-Site Scripting (XSS). CheckMe **simulates** this test by connecting to: http://files.checkme.checkpoint.com/1.asp?xss=%3Cscript%3Ealert%28%221%22%29%3C%2Fscript%3E **Endpoint** This test checks if your browser is exploit by simulating a shellcode execution in the Internet Explorer.                                                                                                                                                                                                                                                           | Improve your network security with [Check Point Next Generation Threat Prevention](https://www.checkpoint.com/products-solutions/threat-prevention-appliances-and-software/) and [Endpoint Security](https://www.checkpoint.com/harmony/advanced-endpoint-protection/) that includes [Intrusion Prevention System (IPS)](https://www.checkpoint.com/products/ips-software-blade/) and Anti Exploit blades. **Network** Configure the IPS protections against Cross-Site Scripting (such as "[Cross-Site Scripting Scanning Attempt](https://www.checkpoint.com/defense/advisories/public/2016/cpai-2016-0042.html)") to "Prevent" mode. 1. Enable the IPS blade and ensure that IPS protections are up to date. 2. If it is not possible to update the IPS protections to the latest release, enable the following IPS protection: Cross-Site Scripting Scanning Attempt. **Endpoint** Enable Anti-Exploit on your Check Point [Endpoint Security](https://www.checkpoint.com/harmony/advanced-endpoint-protection/) to improve your security risk against exploits. Note that Anti-Exploit protection is available from version E80.83.                                                                                                                                                                                                                                                                                      |
| Zero Day           | **Network** This test downloads files in different formats that are often used in Zero Day attacks through your network. CheckMe **simulates** this test by downloading the following files: * http://files.checkme.checkpoint.com/win7_64bit_big.zip * http://files.checkme.checkpoint.com/win7_64bit_big.pdf <br /> <br /> **Endpoint** CheckMe simulates this test by downloading and saving zipped PDF file with malicious macros. In case that the file is deleted after few seconds it means that the endpoint well protected.                                                                                         | Improve your network security with [Check Point Threat Prevention](https://www.checkpoint.com/products-solutions/threat-prevention-appliances-and-software/) and [Endpoint Security](https://www.checkpoint.com/harmony/advanced-endpoint-protection/) solutions by following these steps: **Network** 1. Enable the [Threat Emulation](https://www.checkpoint.com/quantum/advanced-network-threat-prevention/) blade. 2. Enable the [Threat Extraction](https://www.checkpoint.com/quantum/advanced-network-threat-prevention/) blade to strip the files from malicious content. **Endpoint** Improve your network security with Check Point [Endpoint Security](https://www.checkpoint.com/harmony/advanced-endpoint-protection/) that includes [Threat Emulation](https://www.checkpoint.com/products/threat-emulation-sandboxing/) blade, whose default settings block Zero Day attacks.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Anonymous          | **Network** This test connects to an anonymizing site through your network. CheckMe **simulates** this test by attempting to access: http://www.anonymizer.com/wp-content/themes/genesis-anon/assets/images/favicon.ico                                                                                                                                                                                                                                                                                                                                                                                                      | **Network** Improve your network security with [Check Point Threat Prevention](https://www.checkpoint.com/products-solutions/threat-prevention-appliances-and-software/) solution that includes [URL Filtering](https://www.checkpoint.com/products/url-filtering-software-blade/) blade. Ensure that anonymizing sites are blocked by the URL Filtering policy.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Data Leakage       | **Network** This test generates a traffic structured as credit card numbers (over HTTP and HTTPS) to public sites through your network. CheckMe **simulates** this test by posting: * 4580-0000-0000-0000, 5500 0000 0000 0004, 4024 0071 0007 2775, 4024007117885730, 4024007186169115 To: * http://files.checkme.checkpoint.com/post.html * https://files.checkme.checkpoint.com/post.html **Note:** This test is **not** supported for Capsule Cloud.                                                                                                                                                                     | **Network** Improve your network security with [Data Loss Prevention (DLP)](https://www.checkpoint.com/products/dlp-software-blade/)blade. Ensure that PCI - Credit Card Numbers are blocked by the DLP policy.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Persistent Malware | **Endpoint** This test simulates persistent malware by downloading an exe file that and creates an EICAR file. In case that both files are deleted after few seconds the endpoint is well protected.                                                                                                                                                                                                                                                                                                                                                                                                                         | **Endpoint** Improve your network security with Check Point [Endpoint Security](https://www.checkpoint.com/harmony/advanced-endpoint-protection/) that includes Forensics.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |

CheckMe assessment for Network and Endpoint
-------------------------------------------

Show / Hide this section  
1. Go to <http://checkme.checkpoint.com/> and select the environments you wish to assess (Network and/or Endpoint).

2. CheckMe runs independently and analyzes your environments.

3. Your web browser communicates with CheckMe service to analyze your network's security controls (**without any actual risk for your network**).

   *Example of final results page*:
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181004/CheckMe_Network_Endpoint202602170925421.png)

Credential Exposure Assessment
------------------------------

Show / Hide this section  
In this assessment, ERM platform searching for uncompromised credentials exposed across the deep and dark web.

1. When you click Scan Now, you are redirected to the <https://intelligence.checkpoint.com/> web page. Enter your business email address.

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181004/Uncover202602170935041.png)
2. The platform searches for leaked credentials.

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181004/scanning202602170939181.png)
3. After a few seconds, you will receive a high-level report. To view the detailed report, fill in your details.  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181004/report202602170942152.png)

FAQ
---

Show / Hide this section  
* **Can CheckMe cause any damage to a computer that runs these tests?**

  > All tests are secured and there is no risk to the user's devices and network.  
  > The administrator may see alerts in the security system that notify about the tests simulation.
* **Does CheckMe test my computer or my network security?**

  > With the new version of CheckMe it is possible to assess the customer's network or endpoint. The users should select the environments they wish to assess in the welcome page.
* **How CheckMe simulates the threats?**

  > **Network assessment:**   
  >
  > CheckMe uses JavaScript functions that run in the context of the page and do the following:   
  >
  > 1. Download a "malicious" file from <http://checkme.checkpoint.com> over HTTP, HTTPS and ZIPed.
  > 2. Post "sensitive" data to <http://checkme.checkpoint.com>.
  > 3. Load images from bad domains (domains with bad reputation).

  > **Endpoint:**   
  >
  > CheckMe download a binary to the customer's desktop which simulates the "malicious" behaviour.   
  >
  > Each threat includes one or more test that can take part in the attack vector. For example: The final phase of bot infection is the use of command and control sites for remote administration of the malware. CheckMe simulates the C\&C protocol, which can be a part of the bot infection threat and can indicate if the network is exposed to bot infection.
* **Why is CheckMe flagged as not secure by a browser when you open the URL?**   

  > Since there are tests over http, the site must be http as well. That does not mean that the site is not secured.

Revision History
----------------

Show / Hide this section  

|--------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Date         | Description                                                                                                                                                                                                                                                                                                                           |
| 17 Feb 2026  | * Added Credential Exposure Assessment * Removed CheckMe assessment for Mobile (Android) * Removed Tests Specifications \& Remediation Guidelines for CheckMe Mobile application                                                                                                                                                      |
| 30 Mar 2025  | Removed the *CheckMe assessment for Cloud Environment (AWS and Microsoft Azure)* section, and changed Network \& Cloud in *Tests Specifications \& Remediation Guidelines* section to Network.                                                                                                                                        |
| 20 May 2023  | * Added CheckMe assessment for Network and Endpoint.                                                                                                                                                                                                                                                                                  |
| 20 Mar 2018  | * Updated the tests table. * Added 2 new threats.                                                                                                                                                                                                                                                                                     |
| 19 Oct 2017  | * Updated the description of "Identity Theft / Phishing Attack".                                                                                                                                                                                                                                                                      |
| 25 Sep 2017  | * Updated the link to *favicon.ico* file for "Anonymizer usage".                                                                                                                                                                                                                                                                      |
| 27 Aug 2017  | * Updated the description of "Browser attack".                                                                                                                                                                                                                                                                                        |
| 26 July 2017 | * Updated the links to *favicon.ico* file for "Identity Theft / Phishing Attack". * Updated the link to *favicon.ico* file for "Anonymizer usage".                                                                                                                                                                                    |
| 23 July 2017 | * Updated the links to *favicon.ico* file for "Identity Theft / Phishing Attack".                                                                                                                                                                                                                                                     |
| 15 Mar 2017  | * Updated the description of and remediation guidelines for "Zero Day Attack". * Updated the description of and remediation guidelines for "Identity Theft / Phishing Attack".                                                                                                                                                        |
| 02 Mar 2017  | * Updated the description of "Ransomware attack". * Updated the description of and remediation guidelines for "Browser attack". * Added a note that Sensitive data leakage tests are not supported for Capsule Cloud.                                                                                                                 |
| 20 Feb 2017  | * Removed "Beta Version" from the article title. * Renamed from "Browser Code Injection" to "Browser attack". * Updated the tests that simulate a "Browser attack". * Improved the remediation guidelines for "Browser attack". * Added a note that Ransomware Attack tests are not supported for 600/700/1100/1200R/1400 appliances. |
| 12 Feb 2017  | * Improved the remediation guidelines for "Zero Day Attack".                                                                                                                                                                                                                                                                          |
| 07 Feb 2017  | * Improved all the remediation guidelines.                                                                                                                                                                                                                                                                                            |
| 05 Feb 2017  | * Changed the design of this article. * Upgraded the CheckMe service.                                                                                                                                                                                                                                                                 |
| 09 Jan 2017  | * Minor text improvements.                                                                                                                                                                                                                                                                                                            |
| 09 Jan 2017  | * Added notes that this service simulates the attacks without any actual risk for customer's environment.                                                                                                                                                                                                                             |
| 05 Jan 2017  | * First release of this article.                                                                                                                                                                                                                                                                                                      |

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
