proofpoint alert.md

For the complete documentation index, see llms.txt. Markdown versions of documentation pages are available by appending .md to page URLs; this page is available as Markdown.

Proofpoint

Proofpoint

Dropzone AI integrates with Proofpoint, an email-based security solution that analyzes and classifies emails to block ransomware and other email-based threats. Dropzone AI can ingest alerts from Proofpoint TAP (Targeted Attack Protection) and Proofpoint TRAP (Threat Response Auto-Pull).

Proofpoint TAP

Proofpoint TAP requires TAP service credentials to enable.

To obtain your TAP service credentials, do the following:

Navigate to Connected Applications

Create New Credentials

Generate the credentials

Copy the credentials

Proofpoint TRAP

Proofpoint TRAP requires Threat Protection credentials to enable.

To obtain your Threat Protection credentials, do the following:

Enable Proofpoint

To enable the Alert Source integration, you will need the following information:

Dropzone Field Source
TAP Service Principle & Secret The Service Principle and Secret values generated earlier
TAP API URL Your base TAP API host URL, e.g. https://tap-api-v2.proofpoint.com
Threat Protection API Key & Secret The API Key and Secret values generated earlier
Threat Protection API URL Your base TRAP API host URL, e.g. https://threatprotection-api.proofpoint.com

To enable the Alert Source integration, do the following:

Integrations Dropdown

Click Available

The Proofpoint Tile

The Proofpoint Alert Source Configuration (pt 1)

{% hint style="info" %} This feature requires the Microsoft 365/Defender integration to be enabled. {% endhint %}

The Proofpoint Alert Source Configuration (pt 2)

The Proofpoint Alert Source Configuration (pt 3)

The Proofpoint Alert Source Configuration (pt 4)

The Proofpoint Alert Source Configuration (pt 5)

The Proofpoint Alert Source Configuration (pt 5)

If you have any errors or questions, engage your Dropzone AI support representative.