Proofpoint
Proofpoint is a leading cybersecurity and compliance platform that provides comprehensive email security, threat protection, data loss prevention, and information security solutions. As an enterprise-grade security service, Proofpoint protects organizations from advanced email threats, phishing attacks, business email compromise (BEC), malware, ransomware, and other cyber threats targeting email and digital communications.
| Category | Email security |
| Direction | Query source |
| Sign-in | API Key |
| Query languages | STIX |
| Website | proofpoint.com |
Before you start
Huntbase signs in to Proofpoint with API Key. Create the credential in Proofpoint first, then keep it to hand for the Connect step.
- Log in to the TAP dashboard at
https://threatinsight.proofpoint.com. - Go to Settings › Connected Applications and click Create New Credential.
- Name the credential set and click Generate.
- Copy the Service Principal and Secret.
- The SIEM API returns at most one hour of data per request and can look back at most 7 days.
- Requests are throttled, with a shared limit of 1,800 requests per 24 hours.
For the vendor's own instructions, see Proofpoint TAP SIEM API documentation.
Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.
Connect Proofpoint
- Go to Connections and click New connection, or click New connection on the Proofpoint product page.
- On Product, pick Proofpoint and choose the Owner.
- On Details, give the connection a Name and, optionally, a Description.
- On Connect, fill in the settings and credentials described below.
- On Verify, review the summary and click Create & check.
For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.
Settings
Where your Proofpoint lives:
| Field | Required | Notes |
|---|---|---|
| Server Address | Yes | tap-api-v2.proofpoint.com |
| Port | Yes | 443 Defaults to 443. |
Credentials
The only Method is API Key. Enter a Credential label (for example Production), then fill in:
| Field | Required | Notes |
|---|---|---|
| Service Principal | Yes | The Service Principal value. Secret — not shown again after you save it. |
| Secret | Yes | The Secret value. Secret — not shown again after you save it. |
Query it
Once connected, Proofpoint can serve these languages in a query tab, and Scout can use it when you ask in Auto:
| Language | Use it for |
|---|---|
| STIX | STIX patterns for indicator sweeps, translated into the product's native search. |
Next steps
- Connections — health, credentials and settings after you connect
- Query languages — syntax, parameters and time ranges
- Chatting with Scout — ask questions without writing a query
- All integrations — the rest of the catalog