Integrations
- Integrations
- 1Password
- Abnormal
- Absolute
- AbuseIPDB
- Adaptive Shield
- Adobe Cloud
- ADP
- Agari Phishing Response
- Airlock
- Airlock Digital
- Akamai Identity Cloud Social
- Alert Logic
- AlgoSec Firewall Analyzer
- AlienVault OTX
- AlienVault USM
- Anodot
- Ansible
- Anvilogic
- Any Run
- Apex One
- ArcSight ESM
- Area 1
- Asana
- Asset Panda
- Atlassian User Management
- Atlassian User Provisioning
- auth0
- Authentik
- Authomize
- Automox
- AWS
- AWS IAM Identity Center
- Axonius
- Azure
- Azure Data Explorer
- Azure DevOps
- Azure Log Analytics
- Azure Storage
- BambooHR
- Big Fix
- BigPanda
- Bitbucket
- Bitdefender
- Bitsight
- Bitwarden
- Black Duck
- Black Kite
- Blink
- BMC Remedy
- Box
- Brinqa
- Cato Networks
- Censys
- Check Point Harmony
- Check Point Infinity Events
- Check Point XDR-XPR
- Check Point Management
- Checkmarx One
- Checkmarx SAST
- Chorus
- Chronicle
- Cisco Advanced Phishing Protection
- Cisco Domain Protection
- Cisco Meraki
- Cisco Talos
- Cisco Umbrella
- Cisco Webex
- Claroty xDome
- ClearPass
- ClickHouse
- ClickUp
- Cloud Custodian
- Cloudflare
- Cobalt
- Compass
- Confluence
- Confluence Data Center
- Coralogix
- Coralogix Incident Management
- Cortex XDR
- Cortex Xpanse
- CredStash
- Cribl
- CrowdStrike
- CyberArk
- Cybersixgill
- CyCognito
- Cyera
- Cylance
- Cyware CTIX
- Darktrace
- Dasera
- Databricks
- Datadog
- DataSet
- Delighted
- Delinea
- Devo
- Discord
- Docusign
- Domo
- Drata
- Dropbox
- Dropbox Business
- Druva
- Duo
- Duo Auth
- Dynatrace
- EasyVista
- EchoTrail
- Egnyte
- Egnyte Secure Govern
- Elasticsearch
- Entro
- Ermetic
- Exabeam
- Exchange Online
- Expel
- F5 BIG IP
- Falcon LogScale
- Falcon Surface
- Flare.io
- Forcepoint DLP
- Forescout
- FortiGate
- Freshservice
- GCP
- Ghostwriter
- Git
- GitHub
- GitLab
- Glean
- Gmail
- Google Calendar
- Google Chat
- Google Docs
- Google Drive
- Google Forms
- Google Looker
- Google Meet
- Google Sheets
- Google Workspace
- Grafana
- Grip Security
- GYTPOL
- Have I Been Pwned
- HiBob
- HubSpot
- Hunters
- Hybrid Analysis
- Hyperproof
- IBM Cloud
- IBM NS1 Connect
- IBM X Force
- Imperva
- incident.io
- Infoblox Cloud Services Portal
- Integrations
- Intercom
- Intezer
- IP API
- IPinfo
- IPWHOIS
- Ironscales
- Ivanti RiskSense
- Jamf
- JetBrains
- JFrog
- Jira
- Jira Data Center
- Joe Sandbox
- JumpCloud
- Kandji
- Keeper Secrets Manager
- Kenna Security
- KnowBe4
- KnowBe4 Events
- Kubernetes
- Lacework
- LaunchDarkly
- Linear
- Litmos
- LogicMonitor
- LogRhythm
- Manage Engine ServiceDesk Plus
- Mattermost
- Maven
- Microsoft Defender For Cloud
- Microsoft Defender For Cloud Apps
- Microsoft Defender For Endpoints
- Microsoft Defender XDR
- Microsoft E-Discovery
- Microsoft Entra ID
- Microsoft Graph
- Microsoft Intune
- Microsoft Office 365 Management Activity
- Microsoft Outlook
- Microsoft Purview
- Microsoft Sentinel
- Microsoft SQL Server
- Microsoft Teams
- Mimecast
- MISP
- Monday
- MongoDB Atlas
- MxToolbox
- Neo4j
- NetBox
- Netography
- Netskope
- New Relic
- Nightfall AI
- NinjaOne
- Notion
- Nozomi Networks
- Nuclei
- Nucleus
- Nutanix Hypervisor
- Obsidian
- Okta
- OneDrive
- OneLogin
- OneTrust
- OpenAI
- OpenCTI
- Opsgenie
- OPSWAT
- Oracle Cloud
- Oracle HCM
- Orca Security
- OWASP ZAP
- PagerDuty
- Palo Alto Cloud NGFW
- Palo Alto Firewall
- Panther
- Pentera
- Perception Point
- PhishLabs
- PhishLabs Incident Data
- PhishLabs Open Web Monitoring
- Pingdom
- PingID
- PingOne
- PlexTrac
- PortSwigger
- Postman
- Postman SCIM
- Power BI
- PowerShell
- Prisma Access
- Prisma Cloud CSPM
- Prisma Cloud CWP
- Prometheus
- Proofpoint
- Proofpoint
- Actions
- Overview
- Decode URLs
- Get Campaign Forensics
- Get Campaign Information
- Get Threat Forensics
- List Active Campaigns
- List Blocked URL Click Events
- List Delivered Message Events
- List Events Of All Known Threats
- List Events Of Permitted URL Clicks And Delivered Messages
- List Permitted URL Click Events
- List Top Clickers
- List Very Attacked People
- Proofpoint Custom Action
- Retrieve Incidents
- Triggers
- Proofpoint ITM
- Proofpoint Protection Server
- Proofpoint Security Awareness Training
- Proofpoint TAP
- Proofpoint Threat Response Auto Pull
- Pub-Sub
- QRadar
- Qualys
- Rapid7
- Rapid7 InsightIDR
- Rapid7 InsightVM Cloud
- Rapid7 Threat Command
- Reco
- Recorded Future
- Red Hat IdM
- Rippling
- runZero
- SafeBase
- Sage HR
- SailPoint
- SailPoint IdentityIQ
- Salesforce
- SAP Ariba
- ScienceLogic
- Securin
- Securin VI
- SecurityScorecard
- Securonix
- SemGrep
- SentinelOne
- ServiceNow
- SharePoint
- Shodan
- Shopify
- Silverfort
- Slack
- Smartsheet
- Snipe-IT
- Snowflake
- Snyk
- SolarWinds Service Desk
- SonarQube
- Sophos
- Split
- Splunk
- Splunk Observability
- Splunk SOAR
- Spur
- StrongDM
- Sumo Logic
- Symantec EDR
- Sysdig
- Tableau
- Tanium
- TeamCity
- TeamViewer
- Telegram
- Tenable
- Tenable Security Center
- Terraform
- Terraform Cloud
- TheHive
- Thinkst Canary
- ThreatQuotient
- Trellix Email Security
- Trello
- Trend Vision One
- Twilio
- UKG HR
- Uptycs
- URLScan
- Vault
- Veracode
- Verkada
- Vertica
- VirusTotal
- VMware Carbon Black
- VMware vSphere
- WeChat
- WhatsApp
- Whois
- WildFire
- Wiz
- Workday
- Workspace ONE UEM
- YesWeHack
- Zendesk
- Zero Networks
- Zoom
- Zscaler Internet Access
- Zscaler Private Access
Actions
Retrieve Incidents
Retrieve all incident metadata from Threat Response by specifying filter criteria such as the state of the incident or time of closure. For more information, visit the
Basic Parameters
Parameter | Description |
---|---|
Closed After | Retrieve incidents that were closed after specified date, in ISO 8601 format (UTC). |
Created After | Retrieve incidents that were created after specified date, in ISO 8601 format (UTC). |
Search By | Query either by incident creation date or closing date. |
Advanced Parameters
Parameter | Description |
---|---|
Closed Before | Retrieve incidents that were closed before specified date, in ISO 8601 format (UTC). if parameter is omitted, the current timestamp of the system is used in its place. |
Created Before | Retrieve incidents that were created before specified date, in ISO 8601 format (UTC). if parameter is omitted, the current timestamp of the system is used in its place. |
Expand Events | Retrieve incidents with events data expanded. |
State | State of the incidents to retrieve. |
Example Output
[ { "id": 1, "type": "Malware", "summary": "Unsolicited Bulk Email", "description": "EvilScheme test message", "score": 4200, "state": "Open", "created_at": "2018-05-26T21:07:17Z", "event_count": 3, "event_sources": [ "Proofpoint TAP" ], "users": [ "nbadguy" ], "assignee": "Unassigned", "team": "Unassigned", "hosts": { "attacker": [ "54.214.13.31", "http://tapdemo.evilscheme.org/files/313532373336373133382e33.pdf" ], "forensics": [ "http://tapdemo.evilscheme.org/files/313532373336373133382e33.pdf", "tapdemo.evilscheme.org" ] }, "incident_field_values": [ { "name": "Attack Vector", "value": "Email" }, { "name": "Classification", "value": "Spam" }, { "name": "Severity", "value": "Critical" } ], "events": [ { "id": 3, "category": "malware", "severity": "Info", "source": "Proofpoint TAP", "threatname": "Infection.PDF.File.Exploit.CVE-2010-0188_LibTIFF.", "classified": false, "state": "Linked", "description": "Infection.PDF.File.Exploit.CVE-2010-0188_LibTIFF.", "attackDirection": "inbound", "received": "2018-05-26T21:07:17Z", "malwareName": "Infection.PDF.File.Exploit.CVE-2010-0188_LibTIFF." }, { "id": 1, "category": "spam", "severity": "Critical", "source": "Proofpoint TAP", "threatname": "Unsolicited Bulk Email", "classified": false, "state": "Linked", "attackDirection": "inbound", "received": "2018-05-26T21:07:17Z" }, { "id": 2, "category": "spam", "severity": "Critical", "source": "Proofpoint TAP", "threatname": "Unsolicited Bulk Email", "classified": false, "state": "Linked", "attackDirection": "inbound", "received": "2018-05-26T21:07:17Z" } ], "quarantine_results": [], "successful_quarantines": 0, "failed_quarantines": 0, "pending_quarantines": 0 }, { "id": 2, "type": "Reported-abuse", "summary": "Unsolicited Bulk Email", "description": "", "score": 5200, "state": "Open", "created_at": "2018-06-01T17:57:09Z", "event_count": 2, "event_sources": [ "Abuse Mailbox 1", "Proofpoint TAP" ], "users": [], "assignee": "Unassigned", "team": "Unassigned", "hosts": { "attacker": [ "54.214.13.31", "http://tapdemo.evilscheme.org/files/313532373837353631342e3137.pdf" ], "cnc": [ "54.214.13.31" ], "url": [ "http://tapdemo.evilscheme.org/files/313532373837353631342e3137.pdf", "https://urldefense.proofpoint.com/v2/url?u=http-3A__tapdemo.evilscheme.org_files_313532373837353631342e3137.pdf&d=DwMBAg&c=iwluXPtBMDye_7UHm8BbHNhgJ2spJfG0G_Q5BwBe3AQ&r=zo9nQ1F7O9QiDphB0J9hvAhz521RbrdV9nCXSkiNU_g&m=7wroSca_eZ7TP3t47x-Q6n9tm1ABRvkUGBwwUvdvb6I&s=xTtBtrXodsTPyBwCFIDGBJxCvLCJXaYaiPQa1uSx6cs&e=" ], "forensics": [ "http://tapdemo.evilscheme.org/files/313532373837353631342e3137.pdf", "tapdemo.evilscheme.org" ] }, "incident_field_values": [ { "name": "Attack Vector", "value": "Email" }, { "name": "Severity", "value": "Critical" }, { "name": "Classification", "value": "Reported Abuse" }, { "name": "Abuse Disposition", "value": "Malicious" } ], "events": [ { "id": 8, "category": "malware", "severity": "Info", "source": "Proofpoint TAP", "threatname": "Malicious content dropped during execution", "classified": false, "state": "Linked", "description": "Malicious content dropped during execution", "attackDirection": "inbound", "received": "2018-06-01T18:02:10Z", "malwareName": "Malicious content dropped during execution" }, { "id": 6, "category": "malware", "severity": "Info", "source": "Proofpoint TAP", "threatname": "Example signature to fire on TAP demo evilness", "classified": false, "state": "Linked", "description": "Example signature to fire on TAP demo evilness", "attackDirection": "inbound", "received": "2018-06-01T17:57:10Z", "malwareName": "Example signature to fire on TAP demo evilness" }, ], "quarantine_results": [ { "alertSource": "Not Available", "startTime": "2018-06-01T18:17:43.941Z", "endTime": "2018-06-01T18:17:44.001Z", "status": "successful", "recipientType": "Search", "recipient": "jsmith@company.com", "messageId": "<20180601175356.GA30914@tapdemo.evilscheme.org>" "isRead": "true", "wasUndone": "true", "details": "Success" } ], "successful_quarantines": 1, "failed_quarantines": 0, "pending_quarantines": 0 }
Workflow Library Example
Retrieve Incidents with Proofpoint and Send Results Via Email
Preview this Workflow on desktop