
Shell and SmartDashboard scripts that check Check Point management servers for indicators of compromise tied to CVE-2026-93616, including rogue Python scripts, login attempts, and suspicious IPs.
Move compromise-check.sh to Check Point Management server chmod +x compromise-check.sh
Run these commands in Expert mode on the Check Point management server, from the directory containing compromise-check.sh.
smartdashboard_runscript.sh can simply be run from smartdashboard by going to the manager and clicking run script and pasting in this code.
This looks for added python scripts, login attempts, and some IP space.