A Check Point administrator is tuning ThreatCloud Intelligence consumption on a Security Gateway that fronts a busy web farm. Internal penetration tests show that files downloaded over TLS are reaching endpoints without ever being emulated, even though the Threat Emulation blade is enabled on the gateway and shows as active. Reviewing SmartConsole, the administrator confirms the HTTPS inspection policy exists but no certificate is presented to internal clients. What is the most likely cause of the missing emulation?
Detect mode only logs what would have been inspected; the gateway does not terminate TLS, so no certificate is presented and file streams stay opaque. Because payloads are never decrypted, Threat Emulation receives nothing to emulate. Switching the layer to Prevent mode (with a trusted CA certificate distributed to clients) restores decryption and the emulation path.
Why this answer
Without TLS termination the gateway cannot see the file stream, so nothing is handed to Threat Emulation. Detect mode logs decryption decisions without actually decrypting, which is why the blade looks enabled yet no certificate appears and no emulation occurs. Moving the HTTPS Inspection layer to Prevent mode and distributing the inspection CA to clients restores decryption and lets emulation inspect downloaded files.
Exam trap
The trap here is assuming an enabled Threat Emulation blade guarantees inspection of all traffic, when encrypted sessions stay invisible unless HTTPS Inspection actually decrypts them.