# Proofpoint

## Proofpoint

Dropzone AI integrates with [Proofpoint](https://www.proofpoint.com/us), an email-based security solution that analyzes and classifies emails to blocks ransomware and other email-based threats. Dropzone AI can ingest alerts from [Proofpoint TAP](https://www.proofpoint.com/us/resources/data-sheets/targeted-attack-protection) (Targeted Attack Protection) and [Proofpoint TRAP](https://www.proofpoint.com/uk/products/email-protection/threat-response-auto-pull) (Threat Response Auto-Pull).

## Proofpoint TAP

Proofpoint TAP requires TAP service credentials to enable.

To obtain your TAP service credentials, do the following:

* As an administrative user, sign into your [TAP Dashboard](https://threatinsight.proofpoint.com/)
* Navigate to Settings > Connected Applications

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-6875900f7529a65703a74816c15dff8a6f0cbf8a%2Fproofpoint-tap-1.png?alt=media" alt=""><figcaption><p>Navigate to Connected Applications</p></figcaption></figure>

* Click "Create New Credentials"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-5357bc26dd3146631e8c55197c5c1ab30b3104d1%2Fproofpoint-tap-2.png?alt=media" alt=""><figcaption><p>Create New Credentials</p></figcaption></figure>

* Name the credentials something memorable, such as Dropzone AI, and click "Generate"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-7bea47537372f7649d06181ce9daf2fa4b7404d7%2Fproofpoint-tap-3.png?alt=media" alt=""><figcaption><p>Generate the credentials</p></figcaption></figure>

* Copy the Service Principal and Secret shown for use later in the Dropzone UI where they are called "TAP Service Principal" and "TAP Secret" respectively

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-88d083286f4cca7b574cd86504cb24b9c536510a%2Fproofpoint-tap-4.png?alt=media" alt=""><figcaption><p>Copy the credentials</p></figcaption></figure>

* Click "Done"

## Proofpoint TRAP

Proofpoint TRAP requires Threat Protection credentials to enable.

To obtain your Threat Protection credentials, do the following:

* As an administrative user, log into your [Proofpoint Threat Protection console](https://threatprotection.proofpoint.com/)
* Navigate to System Settings > Customization > API Keys
* Next to "API Keys," click the (+) icon
* Name the key something memorable, such as "Dropzone AI"
* Check "Enabled," then click “Save”
* Copy the API and API secret shown for use later in the Dropzone UI where they are called "Threat Protection API Key" and "Threat Protection API Secret," respectively

### Enable Proofpoint

To enable the Alert Source integration, you will need the following information:

| Dropzone Field                     | Source                                                                          |
| ---------------------------------- | ------------------------------------------------------------------------------- |
| TAP Service Principle & Secret     | The Service Principle and Secret values generated earlier                       |
| TAP API URL                        | Your base TAP API host URL, e.g. <https://tap-api-v2.proofpoint.com>            |
| Threat Protection API Key & Secret | The API Key and Secret values generated earlier                                 |
| Threat Protection API URL          | Your base TRAP API host URL, e.g. <https://threatprotection-api.proofpoint.com> |

To enable the Alert Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-b3f07f902b1402dadc7abbd8bb62f9c204547390%2Fui-integrations-dropdown.png?alt=media" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Available"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-434641ec6d4e45051842f86164f485d6bd289424%2Fapp_system_integrations_available.png?alt=media" alt=""><figcaption><p>Click Available</p></figcaption></figure>

* In the Search bar, search Proofpoint, then click "Configure"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-7b88a75916db9cb1f06449f07843c62ea4f9ada0%2Fapp_system_integrations_available_proofpoint.png?alt=media" alt=""><figcaption><p>The Proofpoint Tile</p></figcaption></figure>

* To enable Dropzone to ingest TAP Alerts, check the box labeled "Ingest TAP Alerts"
* Input the TAP Service Principle, Secret, and API URL

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-de04f9d47842a87eef1e3e11294016e4320b1f3c%2Fapp_system_integrations_available_proofpoint_config_1.png?alt=media" alt=""><figcaption><p>The Proofpoint Alert Configuration (pt 1)</p></figcaption></figure>

* In the TAP Ingestion Settings section, select the types of [alert events](https://help.proofpoint.com/Threat_Insight_Dashboard/API_Documentation/SIEM_API) you want Dropzone to ingest
* If you want Dropzone to be able to investigate the emails associated with TAP alerts, check the box labeled "Investigate Phishing Emails"

{% hint style="info" %}
This feature requires the [Microsoft 365/Defender integration](https://docs.dropzone.ai/integrations/alert/ms_alert/ms365_alert) to be enabled.
{% endhint %}

* If you want to Dropzone to be able to investigate threats associated with Proofpoint alerts, check the box labeled "Investigate Threats"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-5503785abbabbe5a56a366b99bc6e9e9e2aae557%2Fapp_system_integrations_available_proofpoint_config_2.png?alt=media" alt=""><figcaption><p>The Proofpoint Alert Configuration (pt 2)</p></figcaption></figure>

* To enable Dropzone to ingest TRAP Incidents, check the box labeled "Ingest TRAP Incidents"
* Input the Threat Protection API Key, Secret, and URL

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-ea16d26b7e1b007f2ce70de139732820401fa579%2Fapp_system_integrations_available_proofpoint_config_3.png?alt=media" alt=""><figcaption><p>The Proofpoint Alert Configuration (pt 3)</p></figcaption></figure>

* To exclude closed incidents from Dropzone's analysis, check the box labeled "Skip Closed Incidents"
* To analyze email messages under quarantine, check the box labeled "Analyze clicked messages in MS Quarantine"

{% hint style="info" %}
This feature requires the [Microsoft 365/Defender integration](https://docs.dropzone.ai/integrations/alert/ms_alert/ms365_alert) to be enabled.
{% endhint %}

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-d5b03e86952636d20e4910dbcbd10f0950ca5302%2Fapp_system_integrations_available_proofpoint_config_4.png?alt=media" alt=""><figcaption><p>The Proofpoint Alert Configuration (pt 4)</p></figcaption></figure>

* Input your desired log ingestion delay, poll interval and poll lookback

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-acd1d4f887f9047addb9ef62505770112e28b273%2Fapp_system_integrations_available_proofpoint_config_5.png?alt=media" alt=""><figcaption><p>The Proofpoint Alert Configuration (pt 5)</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors or questions, engage your Dropzone AI support representative.
