Proofpoint Threat Response
Use the Proofpoint Threat Response integration to orchestrate and automate incident response.
- Category
- Network Security
- Pack
- ProofpointThreatResponse
Configuration parameters
- url — Server URL (e.g. https://192.168.0.1) (required)
- credentials —
- apikey — API Key
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- isFetch — Fetch incidents
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
- first_fetch — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)
- fetch_limit — Fetch limit - maximum number of incidents per fetch
- fetch_delta — Fetch delta - The delta time in each batch. e.g. 1 hour, 3 minutes.
- states — Fetch incident with specific states.
- event_sources — Fetch incidents with specific event sources. Can be a list of comma separated values.
- abuse_disposition — Fetch incidents with specific 'Abuse Disposition' values. Can be a list of comma separated values.
- post_url_id — POST URL of the JSON alert source.
Commands (15)
- proofpoint-tr-add-to-list — Adds a member to the specified list.
- proofpoint-tr-add-user-to-incident — Assigns a user to an incident as a target or attacker.
- proofpoint-tr-block-domain — Adds the supplied domains to the specified block list.
- proofpoint-tr-block-hash — Adds the supplied file hashes to the specified file hash block list.
- proofpoint-tr-block-ip — Adds the supplied IP addresses to the specified IP block list.
- proofpoint-tr-block-url — Adds the supplied URLs to the specified URL block list.
- proofpoint-tr-close-incident — Close a specified incident.
- proofpoint-tr-delete-indicator — Deletes an indicator from the specified list.
- proofpoint-tr-get-incident — Retrieves incident metadata from Threat Response.
- proofpoint-tr-get-list — Gets items for the specified list.
- proofpoint-tr-ingest-alert — Ingest an alert into Threat Response.
- proofpoint-tr-list-incidents — Retrieves all incident metadata from Threat Response by specifying filter criteria such as the state of the incident or time of closure.
- proofpoint-tr-search-indicator — Returns indicators from the specified list, according to the defined filter.
- proofpoint-tr-update-incident-comment — Adds comments to an existing Threat Response incident, by incident ID.
- proofpoint-tr-verify-quarantine — Verify if an email has been quarantined.