Skip to main content

Proofpoint

Proofpoint is a leading cybersecurity and compliance platform that provides comprehensive email security, threat protection, data loss prevention, and information security solutions. As an enterprise-grade security service, Proofpoint protects organizations from advanced email threats, phishing attacks, business email compromise (BEC), malware, ransomware, and other cyber threats targeting email and digital communications.

CategoryEmail security
DirectionQuery source
Sign-inAPI Key
Query languagesSTIX
Websiteproofpoint.com

Before you start​

Huntbase signs in to Proofpoint with API Key. Create the credential in Proofpoint first, then keep it to hand for the Connect step.

  1. Log in to the TAP dashboard at https://threatinsight.proofpoint.com.
  2. Go to Settings › Connected Applications and click Create New Credential.
  3. Name the credential set and click Generate.
  4. Copy the Service Principal and Secret.
Watch out for
  • The SIEM API returns at most one hour of data per request and can look back at most 7 days.
  • Requests are throttled, with a shared limit of 1,800 requests per 24 hours.

For the vendor's own instructions, see Proofpoint TAP SIEM API documentation.

tip

Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.

Connect Proofpoint​

  1. Go to Connections and click New connection, or click New connection on the Proofpoint product page.
  2. On Product, pick Proofpoint and choose the Owner.
  3. On Details, give the connection a Name and, optionally, a Description.
  4. On Connect, fill in the settings and credentials described below.
  5. On Verify, review the summary and click Create & check.

For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.

Settings​

Where your Proofpoint lives:

FieldRequiredNotes
Server AddressYestap-api-v2.proofpoint.com
PortYes443 Defaults to 443.

Credentials​

The only Method is API Key. Enter a Credential label (for example Production), then fill in:

FieldRequiredNotes
Service PrincipalYesThe Service Principal value. Secret — not shown again after you save it.
SecretYesThe Secret value. Secret — not shown again after you save it.

Query it​

Once connected, Proofpoint can serve these languages in a query tab, and Scout can use it when you ask in Auto:

LanguageUse it for
STIXSTIX patterns for indicator sweeps, translated into the product's native search.

Next steps​