> Source: [sk167102](https://support.checkpoint.com/results/sk/sk167102)

# sk167102 - Investigative Threat Prevention Best Practices

| Property | Value |
|----------|-------|
| Solution ID | sk167102 |
| Date Created | 2020-05-27 |
| Last Modified | 2020-05-31 |
| Technical Level | General |

## Solution

This article incorporates video tutorials that explains the best way to investigate Threat Prevention attacks in your organization and helps to identify significant events generated by your Threat Prevention environment and understand their meaning:  
� Identify infected hosts and mobile devices  
� Detect malicious emails.  
� Learn about the attacks and the corresponding vulnerabilities in your system  
� Tune your threat prevention policy based on reports

**Table of Contents**

* Threat Prevention Best Practices
* Infected hosts
* Malicious emails
* Reconnaissance and Exploit
* Mobile Devices
* IPS Utilization

Threat Prevention Best Practices {#Video 1}
-------------------------------------------

Infected hosts {#Video 2}
-------------------------

Malicious emails {#Video 3}
---------------------------

Reconnaissance and Exploit {#Video 4}
-------------------------------------

Mobile Devices {#Video 5}
-------------------------

IPS Utilization {#Video 6}
--------------------------

**Related documentation:**

* [Threat Prevention R80.30 Best Practices](https://sc1.checkpoint.com/documents/Best_Practices/CP_R80.30_Best_Practices_for_Threat_Prevention/Default.htm)
* [Threat Prevention R80.20 Best Practices](https://sc1.checkpoint.com/documents/Best_Practices/CP_R80.20_Best_Practices_for_Threat_Prevention/Default.htm)
* [IPS Optimzation report for R80.20](https://downloads.checkpoint.com/dc/download.htm?ID=104333)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
