Proofpoint Threat Protection
Threat Protection APIs are REST APIs that allow Proofpoint On Demand customers to retrieve, add, update or delete certain PoD configurations.
Email · Proofpoint Threat Protection
Details
| ID | Proofpoint Threat Protection |
|---|---|
| Provider | Thoma Bravo |
| Category | |
| From Version | 6.10.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Supported Modules | Agentix XSIAM |
README
Threat Protection APIs are REST APIs that allow Proofpoint On Demand customers to retrieve, add, update or delete certain PoD configurations.
Configure Proofpoint Threat Protection in Cortex
| Parameter | Required |
|---|---|
| URL | True |
| Client ID | True |
| Client Secret | True |
| Trust any certificate (not secure) | False |
| Use system proxy settings | False |
| Cluster ID | True |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
proofpoint-tp-blocklist-get
Get all entries in the Organizational Block List.
Base Command
proofpoint-tp-blocklist-get
Input
There are no input arguments for this command.
Context Output
| Path | Type | Description |
|---|---|---|
| ProofpointThreatProtection.Blocklist | unknown | A list of entries in the blocklist. |
proofpoint-tp-blocklist-add-or-delete-entry
Add/Delete entry from the Organizational Block List.
Base Command
proofpoint-tp-blocklist-add-or-delete-entry
Input
| Argument Name | Description | Required |
|---|---|---|
| action | The action to perform. Possible values are: add, delete. | Required |
| attribute | Supported attributes for the Organizational Block List. Possible values are: $from, $hfrom, $ip, $host, $helo, $rcpt. | Required |
| operator | Supported operators for the Organizational Block List. Possible values are: equal, not_equal, contain, not_contain. | Required |
| value | The entry that the action is to be performed upon in the Organizational Block List. | Required |
| comment | A short comment about the entry (max 150 chars). “comment” is ignored for the “delete” action. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| ProofpointThreatProtection.Blocklist | unknown | Standard HTTP response with status code 200. |
proofpoint-tp-safelist-get
Get all entries in the Organizational Safe List.
Base Command
proofpoint-tp-safelist-get
Input
There are no input arguments for this command.
Context Output
| Path | Type | Description |
|---|---|---|
| ProofpointThreatProtection.Safelist | unknown | A list of entries in the Organizational Safe List. |
proofpoint-tp-safelist-add-or-delete-entry
Add To/Delete From the Organizational Safe List.
Base Command
proofpoint-tp-safelist-add-or-delete-entry
Input
| Argument Name | Description | Required |
|---|---|---|
| action | The action to perform. Possible values are: add, delete. | Required |
| attribute | Supported attributes for the Organizational Safe List. Possible values are: $from, $hfrom, $ip, $host, $helo, $rcpt. | Required |
| operator | Supported operators for the Organizational Safe List. Possible values are: equal, not_equal, contain, not_contain. | Required |
| value | The entry that the action is to be performed upon in the Organizational Safe List. | Required |
| comment | A short comment about the entry (max 150 chars). “comment” is optional for “add” action and ignored for the “delete” action. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| ProofpointThreatProtection.Safelist | unknown | Standard HTTP response with status code 200. |
proofpoint-tp-blocklist-list
Get entries from the Organizational Block List.
Base Command
proofpoint-tp-blocklist-list
Input
| Argument Name | Description | Required |
|---|---|---|
| all_results | A boolean argument to designate whether to send back all the list results. This argument takes precedence over the limit argument when set to true. Default is False. Possible values are: True, False. | Optional |
| limit | An integar argument to designate the amount of entries to return from the list results. Defualt is 25. Maximum is 100. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| ProofpointThreatProtection.Blocklist | unknown | A list of entries in the blocklist. |
proofpoint-tp-blocklist-add-entry
Add an entry to the Organizational Block List.
Base Command
proofpoint-tp-blocklist-add-entry
Input
| Argument Name | Description | Required |
|---|---|---|
| attribute | Supported attributes for the Organizational Block List. Possible values are: $from, $hfrom, $ip, $host, $helo, $rcpt. | Required |
| operator | Supported operators for the Organizational Block List. Possible values are: equal, not_equal, contain, not_contain. | Required |
| value | The entry that is to be added to the Organizational Block List. | Required |
| comment | An optional short comment about the added entry (max 150 chars). | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| ProofpointThreatProtection.Blocklist | unknown | Standard HTTP response with status code 200. |
proofpoint-tp-blocklist-delete-entry
Delete an entry from the Organizational Block List.
Base Command
proofpoint-tp-blocklist-delete-entry
Input
| Argument Name | Description | Required |
|---|---|---|
| attribute | Supported attributes for the Organizational Block List. Possible values are: $from, $hfrom, $ip, $host, $helo, $rcpt. | Required |
| operator | Supported operators for the Organizational Block List. Possible values are: equal, not_equal, contain, not_contain. | Required |
| value | The entry that is to be deleted from the Organizational Block List. | Required |
| comment | The short comment associated with the blockilst entry. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| ProofpointThreatProtection.Blocklist | unknown | Standard HTTP response with status code 200. |
proofpoint-tp-safelist-list
Get entries from the Organizational Safe List.
Base Command
proofpoint-tp-safelist-list
Input
| Argument Name | Description | Required |
|---|---|---|
| all_results | A boolean argument to designate whether to send back all the list results. This argument takes precedence over the limit argument when set to true. Default is False. Possible values are: True, False. | Optional |
| limit | An integar argument to designate the amount of entries to return from the list results. Defualt is 25. Maximum is 100. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| ProofpointThreatProtection.Safelist | unknown | A list of entries in the Organizational Safe List. |
proofpoint-tp-safelist-add-entry
Add an entry to the Organizational Safe List.
Base Command
proofpoint-tp-safelist-add-entry
Input
| Argument Name | Description | Required |
|---|---|---|
| attribute | Supported attributes for the Organizational Safe List. Possible values are: $from, $hfrom, $ip, $host, $helo, $rcpt. | Required |
| operator | Supported operators for the Organizational Safe List. Possible values are: equal, not_equal, contain, not_contain. | Required |
| value | The entry to be added to the Organizational Safe List. | Required |
| comment | An optional short comment about the added entry (max 150 chars). | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| ProofpointThreatProtection.Safelist | unknown | Standard HTTP response with status code 200. |
proofpoint-tp-safelist-delete-entry
Delete an entry from the Organizational Safe List.
Base Command
proofpoint-tp-safelist-delete-entry
Input
| Argument Name | Description | Required |
|---|---|---|
| attribute | Supported attributes for the Organizational Safe List. Possible values are: $from, $hfrom, $ip, $host, $helo, $rcpt. | Required |
| operator | Supported operators for the Organizational Safe List. Possible values are: equal, not_equal, contain, not_contain. | Required |
| value | The entry to be deleted from the Organizational Safe List. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| ProofpointThreatProtection.Safelist | unknown | Standard HTTP response with status code 200. |
Configuration parameters
url— Server URL (required)credentials— Client ID (required)insecure— Trust any certificate (not secure)proxy— Use system proxy settingscluster_id— Cluster ID (required)
Commands (6)
-
proofpoint-tp-blocklist-add-entryAdd an entry to the Organizational Block List.
-
proofpoint-tp-blocklist-delete-entryDelete an entry from the Organizational Block List.
-
proofpoint-tp-blocklist-listGet entries from the Organizational Block List.
-
proofpoint-tp-safelist-add-entryAdd an entry to the Organizational Safe List.
-
proofpoint-tp-safelist-delete-entryDelete an entry from the Organizational Safe List.
-
proofpoint-tp-safelist-listGet entries from the Organizational Safe List.
category: Email provider: Thoma Bravo sectionorder: - Connect - Collect commonfields: id: Proofpoint Threat Protection version: -1 configuration: - defaultvalue: https://threatprotection-api.proofpoint.com/api/v1 display: Server URL name: url required: true section: Connect type: 0 - display: Client ID displaypassword: Client Secret name: credentials required: true section: Connect type: 9 - advanced: true display: Trust any certificate (not secure) name: insecure required: false section: Connect type: 8 - advanced: true display: Use system proxy settings name: proxy required: false section: Connect type: 8 - display: Cluster ID name: cluster_id required: true type: 0 section: Connect description: Threat Protection APIs are REST APIs that allow Proofpoint On Demand customers to retrieve, add, update or delete certain PoD configurations. display: Proofpoint Threat Protection name: Proofpoint Threat Protection script: commands: - arguments: - auto: PREDEFINED predefined: - 'True' - 'False' name: all_results description: A boolean argument to designate whether to send back all the list results. This argument takes precedence over the limit argument when set to true. Default is False. - name: limit description: An integar argument to designate the amount of entries to return from the list results. Defualt is 25. Maximum is 100. description: Get entries from the Organizational Block List. name: proofpoint-tp-blocklist-list outputs: - contextPath: ProofpointThreatProtection.Blocklist description: A list of entries in the blocklist. - arguments: - auto: PREDEFINED name: attribute predefined: - '$from' - '$hfrom' - '$ip' - '$host' - '$helo' - '$rcpt' required: true description: Supported attributes for the Organizational Block List. - auto: PREDEFINED name: operator predefined: - equal - not_equal - contain - not_contain required: true description: Supported operators for the Organizational Block List. - description: The entry that is to be added to the Organizational Block List. name: value required: true - description: An optional short comment about the added entry (max 150 chars). name: comment description: Add an entry to the Organizational Block List. name: proofpoint-tp-blocklist-add-entry outputs: - contextPath: ProofpointThreatProtection.Blocklist description: Standard HTTP response with status code 200. - arguments: - auto: PREDEFINED name: attribute predefined: - '$from' - '$hfrom' - '$ip' - '$host' - '$helo' - '$rcpt' required: true description: Supported attributes for the Organizational Block List. - auto: PREDEFINED name: operator predefined: - equal - not_equal - contain - not_contain required: true description: Supported operators for the Organizational Block List. - description: The entry that is to be deleted from the Organizational Block List. name: value required: true - description: The short comment associated with the blockilst entry. name: comment description: Delete an entry from the Organizational Block List. name: proofpoint-tp-blocklist-delete-entry outputs: - contextPath: ProofpointThreatProtection.Blocklist description: Standard HTTP response with status code 200. compliantpolicies: - Domain Blockage - IP Blockage - arguments: - auto: PREDEFINED predefined: - 'True' - 'False' name: all_results description: A boolean argument to designate whether to send back all the list results. This argument takes precedence over the limit argument when set to true. Default is False. - name: limit description: An integar argument to designate the amount of entries to return from the list results. Defualt is 25. Maximum is 100. description: Get entries from the Organizational Safe List. name: proofpoint-tp-safelist-list outputs: - contextPath: ProofpointThreatProtection.Safelist description: A list of entries in the Organizational Safe List. - arguments: - auto: PREDEFINED name: attribute predefined: - '$from' - '$hfrom' - '$ip' - '$host' - '$helo' - '$rcpt' required: true description: Supported attributes for the Organizational Safe List. - auto: PREDEFINED name: operator predefined: - equal - not_equal - contain - not_contain required: true description: Supported operators for the Organizational Safe List. - description: The entry to be added to the Organizational Safe List. name: value required: true - description: An optional short comment about the added entry (max 150 chars). name: comment description: Add an entry to the Organizational Safe List. name: proofpoint-tp-safelist-add-entry outputs: - contextPath: ProofpointThreatProtection.Safelist description: Standard HTTP response with status code 200. compliantpolicies: - Domain Blockage - IP Blockage - arguments: - auto: PREDEFINED name: attribute predefined: - '$from' - '$hfrom' - '$ip' - '$host' - '$helo' - '$rcpt' required: true description: Supported attributes for the Organizational Safe List. - auto: PREDEFINED name: operator predefined: - equal - not_equal - contain - not_contain required: true description: Supported operators for the Organizational Safe List. - description: The entry to be deleted from the Organizational Safe List. name: value required: true description: Delete an entry from the Organizational Safe List. name: proofpoint-tp-safelist-delete-entry outputs: - contextPath: ProofpointThreatProtection.Safelist description: Standard HTTP response with status code 200. dockerimage: demisto/python3:3.12.13.10116658 alt_dockerimages: ["demisto/fastapi:0.111.0.100929"] runonce: false script: '' subtype: python3 type: python fromversion: 6.10.0 tests: - No tests (auto formatted)