> For the complete documentation index, see [llms.txt](https://docs.dropzone.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.dropzone.ai/integrations/alert/proofpoint_alert.md).

# Proofpoint

## Proofpoint

Dropzone AI integrates with [Proofpoint](https://www.proofpoint.com/us), an email-based security solution that analyzes and classifies emails to blocks ransomware and other email-based threats. Dropzone AI can ingest alerts from [Proofpoint TAP](https://www.proofpoint.com/us/resources/data-sheets/targeted-attack-protection) (Targeted Attack Protection) and [Proofpoint TRAP](https://www.proofpoint.com/uk/products/email-protection/threat-response-auto-pull) (Threat Response Auto-Pull).

## Proofpoint TAP

Proofpoint TAP requires TAP service credentials to enable.

To obtain your TAP service credentials, do the following:

* As an administrative user, sign into your [TAP Dashboard](https://threatinsight.proofpoint.com/)
* Navigate to Settings > Connected Applications

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-20111cf3d2f4f5a053a8561c07bd63da712ae8a9%2Fproofpoint-tap-1.png?alt=media" alt=""><figcaption><p>Navigate to Connected Applications</p></figcaption></figure>

* Click "Create New Credentials"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-e8e2aa0c5e0efcd2533fbe630bb3f01235dc2d78%2Fproofpoint-tap-2.png?alt=media" alt=""><figcaption><p>Create New Credentials</p></figcaption></figure>

* Name the credentials something memorable, such as Dropzone AI, and click "Generate"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-72d8bf0eed0963ca935971f0fc397f055de38ff9%2Fproofpoint-tap-3.png?alt=media" alt=""><figcaption><p>Generate the credentials</p></figcaption></figure>

* Copy the Service Principal and Secret shown for use later in the Dropzone UI where they are called "TAP Service Principal" and "TAP Secret" respectively

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-d122539eeaa17cc042e169af3e855cdcf0bff31d%2Fproofpoint-tap-4.png?alt=media" alt=""><figcaption><p>Copy the credentials</p></figcaption></figure>

* Click "Done"

## Proofpoint TRAP

Proofpoint TRAP requires Threat Protection credentials to enable.

To obtain your Threat Protection credentials, do the following:

* As an administrative user, log into your [Proofpoint Threat Protection console](https://threatprotection.proofpoint.com/)
* Navigate to System Settings > Customization > API Keys
* Next to "API Keys," click the (+) icon
* Name the key something memorable, such as "Dropzone AI"
* Check "Enabled," then click “Save”
* Copy the API and API secret shown for use later in the Dropzone UI where they are called "Threat Protection API Key" and "Threat Protection API Secret," respectively

### Enable Proofpoint

To enable the Alert Source integration, you will need the following information:

| Dropzone Field                     | Source                                                                          |
| ---------------------------------- | ------------------------------------------------------------------------------- |
| TAP Service Principle & Secret     | The Service Principle and Secret values generated earlier                       |
| TAP API URL                        | Your base TAP API host URL, e.g. <https://tap-api-v2.proofpoint.com>            |
| Threat Protection API Key & Secret | The API Key and Secret values generated earlier                                 |
| Threat Protection API URL          | Your base TRAP API host URL, e.g. <https://threatprotection-api.proofpoint.com> |

To enable the Alert Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-8c77435ef341f8180540e049f505d3390a27bbf4%2Fui-integrations-dropdown.png?alt=media" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-7e038b4f51ee27d4cf4f1ac6f76c5ddae2bf29c5%2Fapp_system_integrations_library.png?alt=media" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Proofpoint, then click "Configure"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-0bc901f0f8427ef5c01c3b44c0db4da88f121ed6%2Fapp_system_integrations_available_proofpoint.png?alt=media" alt=""><figcaption><p>The Proofpoint Tile</p></figcaption></figure>

* To enable Dropzone to ingest TAP Alerts, check the box labeled "Ingest TAP Alerts"
* Input the TAP Service Principle, Secret, and API URL

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-d7ad21747866bce3b648cba09c75c911fe7e620e%2Fapp_system_integrations_available_proofpoint_config_1.png?alt=media" alt=""><figcaption><p>The Proofpoint Alert Source Configuration (pt 1)</p></figcaption></figure>

* In the TAP Ingestion Settings section, select the types of [alert events](https://help.proofpoint.com/Threat_Insight_Dashboard/API_Documentation/SIEM_API) you want Dropzone to ingest
* If you want Dropzone to be able to investigate the emails associated with TAP alerts, check the box labeled "Investigate Phishing Emails"

{% hint style="info" %}
This feature requires the [Microsoft 365/Defender integration](https://docs.dropzone.ai/integrations/alert/ms_alert/ms365_alert) to be enabled.
{% endhint %}

* If you want to Dropzone to be able to investigate threats associated with Proofpoint alerts, check the box labeled "Investigate Threats"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-0897a19818cc4b0de460124dcd969dde0de58969%2Fapp_system_integrations_available_proofpoint_config_2.png?alt=media" alt=""><figcaption><p>The Proofpoint Alert Source Configuration (pt 2)</p></figcaption></figure>

* To enable Dropzone to ingest TRAP Incidents, check the box labeled "Ingest TRAP Incidents"
* Input the Threat Protection API Key, Secret, and URL

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-1c0793ad368e0ab83c3f39f52b1eb86466ad3987%2Fapp_system_integrations_available_proofpoint_config_3.png?alt=media" alt=""><figcaption><p>The Proofpoint Alert Source Configuration (pt 3)</p></figcaption></figure>

* To exclude closed incidents from Dropzone's analysis, check the box labeled "Skip Closed Incidents"
* To analyze email messages under quarantine, check the box labeled "Analyze clicked messages in MS Quarantine"

{% hint style="info" %}
This feature requires the [Microsoft 365/Defender integration](https://docs.dropzone.ai/integrations/alert/ms_alert/ms365_alert) to be enabled.
{% endhint %}

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-c3463c8dafc2408eb69fa4ecd1002966dbee586e%2Fapp_system_integrations_available_proofpoint_config_4.png?alt=media" alt=""><figcaption><p>The Proofpoint Alert Source Configuration (pt 4)</p></figcaption></figure>

* Input your desired log ingestion delay, poll interval and poll lookback

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-f1ae06f6ebb62844650b057e427ccc2c44c92f99%2Flog-ingestion-poll-interval-lookback.png?alt=media" alt=""><figcaption><p>The Proofpoint Alert Source Configuration (pt 5)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-43a55827dfbfd5a9af3d744a16e7e8306fc8e253%2Fadvanced-filtering-test-save.png?alt=media" alt=""><figcaption><p>The Proofpoint Alert Source Configuration (pt 5)</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors or questions, engage your Dropzone AI support representative.
