> For the complete documentation index, see [llms.txt](https://docs.dropzone.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.dropzone.ai/integrations/alert/proofpoint_alert.md).

# Proofpoint

## Proofpoint

Dropzone AI integrates with [Proofpoint](https://www.proofpoint.com/us), an email-based security solution that analyzes and classifies emails to blocks ransomware and other email-based threats. Dropzone AI can ingest alerts from [Proofpoint TAP](https://www.proofpoint.com/us/resources/data-sheets/targeted-attack-protection) (Targeted Attack Protection) and [Proofpoint TRAP](https://www.proofpoint.com/uk/products/email-protection/threat-response-auto-pull) (Threat Response Auto-Pull).

## Proofpoint TAP

Proofpoint TAP requires TAP service credentials to enable.

To obtain your TAP service credentials, do the following:

* As an administrative user, sign into your [TAP Dashboard](https://threatinsight.proofpoint.com/)
* Navigate to Settings > Connected Applications

<figure><img src="/files/x3CmI8KAvip1WQfHUPpk" alt=""><figcaption><p>Navigate to Connected Applications</p></figcaption></figure>

* Click "Create New Credentials"

<figure><img src="/files/ROeszEmHG23k88DAT1DV" alt=""><figcaption><p>Create New Credentials</p></figcaption></figure>

* Name the credentials something memorable, such as Dropzone AI, and click "Generate"

<figure><img src="/files/hdiWGtEI6rxj15G1z1Ic" alt=""><figcaption><p>Generate the credentials</p></figcaption></figure>

* Copy the Service Principal and Secret shown for use later in the Dropzone UI where they are called "TAP Service Principal" and "TAP Secret" respectively

<figure><img src="/files/nZRAct9OJ5e5PFOUQfey" alt=""><figcaption><p>Copy the credentials</p></figcaption></figure>

* Click "Done"

## Proofpoint TRAP

Proofpoint TRAP requires Threat Protection credentials to enable.

To obtain your Threat Protection credentials, do the following:

* As an administrative user, log into your [Proofpoint Threat Protection console](https://threatprotection.proofpoint.com/)
* Navigate to System Settings > Customization > API Keys
* Next to "API Keys," click the (+) icon
* Name the key something memorable, such as "Dropzone AI"
* Check "Enabled," then click “Save”
* Copy the API and API secret shown for use later in the Dropzone UI where they are called "Threat Protection API Key" and "Threat Protection API Secret," respectively

### Enable Proofpoint

To enable the Alert Source integration, you will need the following information:

| Dropzone Field                     | Source                                                                          |
| ---------------------------------- | ------------------------------------------------------------------------------- |
| TAP Service Principle & Secret     | The Service Principle and Secret values generated earlier                       |
| TAP API URL                        | Your base TAP API host URL, e.g. <https://tap-api-v2.proofpoint.com>            |
| Threat Protection API Key & Secret | The API Key and Secret values generated earlier                                 |
| Threat Protection API URL          | Your base TRAP API host URL, e.g. <https://threatprotection-api.proofpoint.com> |

To enable the Alert Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Available"

<figure><img src="/files/brI7n2Ux40Tk0jTwBCVh" alt=""><figcaption><p>Click Available</p></figcaption></figure>

* In the Search bar, search Proofpoint, then click "Configure"

<figure><img src="/files/zvXuomqwUlqXjkndD3sC" alt=""><figcaption><p>The Proofpoint Tile</p></figcaption></figure>

* To enable Dropzone to ingest TAP Alerts, check the box labeled "Ingest TAP Alerts"
* Input the TAP Service Principle, Secret, and API URL

<figure><img src="/files/aErsxJyVH05XwkWIuxSw" alt=""><figcaption><p>The Proofpoint Alert Source Configuration (pt 1)</p></figcaption></figure>

* In the TAP Ingestion Settings section, select the types of [alert events](https://help.proofpoint.com/Threat_Insight_Dashboard/API_Documentation/SIEM_API) you want Dropzone to ingest
* If you want Dropzone to be able to investigate the emails associated with TAP alerts, check the box labeled "Investigate Phishing Emails"

{% hint style="info" %}
This feature requires the [Microsoft 365/Defender integration](https://docs.dropzone.ai/integrations/alert/ms_alert/ms365_alert) to be enabled.
{% endhint %}

* If you want to Dropzone to be able to investigate threats associated with Proofpoint alerts, check the box labeled "Investigate Threats"

<figure><img src="/files/zg0ScU4WjBRTZegDtUQV" alt=""><figcaption><p>The Proofpoint Alert Source Configuration (pt 2)</p></figcaption></figure>

* To enable Dropzone to ingest TRAP Incidents, check the box labeled "Ingest TRAP Incidents"
* Input the Threat Protection API Key, Secret, and URL

<figure><img src="/files/iwiWSDaanPu7QqhU3FWi" alt=""><figcaption><p>The Proofpoint Alert Source Configuration (pt 3)</p></figcaption></figure>

* To exclude closed incidents from Dropzone's analysis, check the box labeled "Skip Closed Incidents"
* To analyze email messages under quarantine, check the box labeled "Analyze clicked messages in MS Quarantine"

{% hint style="info" %}
This feature requires the [Microsoft 365/Defender integration](https://docs.dropzone.ai/integrations/alert/ms_alert/ms365_alert) to be enabled.
{% endhint %}

<figure><img src="/files/jSIre5opdmzG6gGdsNcy" alt=""><figcaption><p>The Proofpoint Alert Source Configuration (pt 4)</p></figcaption></figure>

* Input your desired log ingestion delay, poll interval and poll lookback

<figure><img src="/files/2qn1FRWfM87n9ApeByn9" alt=""><figcaption><p>The Proofpoint Alert Source Configuration (pt 5)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/infLIQONnAkvK8XGXOi4" alt=""><figcaption><p>The Proofpoint Alert Source Configuration (pt 5)</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors or questions, engage your Dropzone AI support representative.
