Proofpoint Cloud Threat Response
Fetches Proofpoint Cloud Threat Response (CTR) incidents into Cortex XSOAR for case management, and exposes commands to list and retrieve incident details.
- Category
- Case Management
- Pack
- ProofpointCloudThreatResponse
Configuration parameters
- url — Server URL (required)
- credentials — Client ID (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- isFetch — Fetch incidents
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
- first_fetch — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)
- max_fetch — Maximum number of incidents per fetch
- fetch_delta — Fetch delta (minutes)
- fetch_states — Fetch incidents with specific states
- fetch_enrich — Enrich incidents during fetch
Commands (2)
- proofpoint-ctr-incident-get — Returns full details for a specific Proofpoint Cloud Threat Response incident.
- proofpoint-ctr-incidents-list — Returns a list of Proofpoint Cloud Threat Response incidents matching the supplied filters.