Check Point's security engines explained

Modified on Tue, Oct 6 at 7:13 AM

Check Point splits its protection into separate security engines, each with its own job. This page is a quick reference for what each engine checks and what it typically catches. For how engines are switched on and applied to users, see How Check Point works: engines vs policies.

The engines at a glance

EngineWhat it checksExample of what it catches
Anti-PhishingThe message itself: sender, wording, links, headers, QR codes and SPF/DKIM/DMARC results. Gives a verdict of phishing, suspected phishing, spam or graymail.A fake invoice from a lookalike domain, or a CEO impersonation asking for a payment.
Anti-MalwareAttachments, including running them in a sandbox to see what they do when opened.A Word document that downloads ransomware when opened.
Threat ExtractionAttachments that came back clean. Strips risky active content (macros, embedded objects, hidden links) and delivers a safe copy.A clean-looking PDF with a hidden link or script that nothing has flagged yet.
Click-Time ProtectionLinks, checked at the moment they are clicked rather than only on arrival.A link that was harmless when the email arrived but points to a phishing page by the afternoon.
URL ReputationLinks, checked against reputation data when the email is delivered.A link to a domain already known for hosting malware.
DLPSensitive data in mail leaving (or arriving into) the organisation. Can block, quarantine or encrypt.A spreadsheet of card numbers being emailed to an outside address.
Anomaly DetectionAccounts rather than emails: sign-in locations, mailbox rules and sending behaviour.A login from another country minutes after a login from the office, or a new rule forwarding all mail out.
Smart BannersNot a detection engine. Adds a contextual warning banner to emails so users get a prompt in the moment.A banner on a first-time external sender saying to be careful with links and payments.

Why separate engines?

  • Different jobs. Judging the wording of an email, detonating an attachment and spotting a hijacked account are different problems, so each gets a specialist engine.
  • Independent tuning. You can be strict on malware and relaxed on spam, or turn on Threat Extraction without changing anything else.
  • Exceptions stay contained. An allow-list entry only affects its own engine, so trusting a sender for phishing does not switch off malware scanning on their attachments.
  • One set of engines, many apps. The same engines protect email, Teams, OneDrive, SharePoint and Google Drive.

The trade-off is that there is more than one place to configure, and no single allow or block list. That is deliberate: it gives finer control and stops one exception from quietly weakening everything else.

Related

How Check Point works: engines vs policies
Managing exceptions and allow-lists
DLP and keyword-triggered email encryption
Anomaly Detection and impossible-travel logins
Creating a policy: a worked example with Click-Time Protection

Need Help with Check Point Harmony?

We deploy, configure, and manage Check Point Harmony Email & Collaboration for businesses, making sure your policies, engines, and protection modes are set up correctly so your organisation is fully covered.

Speak to an expert

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article