Avanan
ProCloud Identity & Email
Post-delivery email security — so you know if the kill chain started in the inbox.
Avanan homepage ↗Cloud email security from Check Point. Post-delivery phish + BEC + URL-payload detection on M365 and Google Workspace. Pulls quarantine verdicts, malicious-URL hits, and impersonation flags into the same case lifecycle as your endpoint + network signals — so when Wazuh fires on a suspicious PowerShell, you already know if the kill chain started with email.
Production-shippable, newer or thinner field coverage. Watch the changelog before pinning compliance claims.
What it watches
- Phishing + BEC + impersonation verdicts on M365 / Google Workspace mail
- Malicious-URL + weaponized-attachment detections
- Post-delivery quarantine + clawback events
- Account-takeover signals from mailbox behavior
- DLP + data-exfil-over-email flags
MITRE ATT&CK coverage
Tactics this connector gives CyberCLI visibility into.
What it helps you catch
What you'd see in CyberCLI
illustrativeWhen Wazuh fires on a suspicious PowerShell, Avanan tells you the kill chain started with an email — and which one.
Routed to Warden (triage) → Knight (detection) → Herald (notify)
⛓ every step hash-chained · replayable
Close more of the kill chain
Avanan covers 4 of 14 ATT&CK tactics. Pair it with these to widen coverage:
How to connect
- 1 In the Avanan / Check Point portal, generate an API token.
- 2 On Pro activation, the guided flow collects the token and wires it in (vault-stored).
- 3 CyberCLI pulls email-security events into the case lifecycle.
- 4 Confirm in the dashboard's Connectors panel.
Already on Avanan? Generate an API token in the Avanan portal — provisioned through the guided flow when you activate Pro.
Hybrid. Email verdicts come from Avanan's cloud via API; correlation with your endpoint + network signals happens in your sovereign SOC.