Proofpoint TAP Threat Intelligence

Query Proofpoint TAP threat intelligence and SIEM event data for security analysis.

39|17|Updated Feb 4, 2026
One-click install
npx skills add https://github.com/wyre-technology/msp-claude-plugins --skill proofpoint-tap-threat-intelligence
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: Proofpoint TAP Threat Intelligence
Source: https://github.com/wyre-technology/msp-claude-plugins/tree/main/msp-claude-plugins/proofpoint/proofpoint/skills/threats
Command: npx skills add https://github.com/wyre-technology/msp-claude-plugins --skill proofpoint-tap-threat-intelligence

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill helps security analysts and MSPs efficiently query and understand threat intelligence data from Proofpoint Targeted Attack Protection (TAP), enabling faster incident response and threat hunting.

Core Features & Use Cases

  • Query Threat Data: Retrieve active URL threats, attachment threats, and message text threats.
  • Analyze SIEM Events: Examine click events (permitted and blocked) and message delivery events for detailed threat context.
  • Investigate Campaigns: Gather intelligence on threat campaigns, including actors, families, and associated infrastructure.
  • Use Case: Investigate a user-reported suspicious email by querying SIEM events for related clicks and messages, then use campaign data to understand the broader attack.

Quick Start

Use the proofpoint threat skill to get all blocked click events in the last 24 hours.

Frequently Asked Questions about Proofpoint TAP Threat Intelligence

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I retrieve Proofpoint TAP threat intelligence for incident response?

To retrieve Proofpoint TAP threat intelligence, query the SIEM API for active URL, attachment, and message text threats to support incident response and threat hunting. This extracts real-time threat types and event context for security analysis.

What is the best way to analyze Proofpoint TAP click events during phishing investigations?

The best way to analyze Proofpoint TAP click events is to query SIEM event data for permitted and blocked clicks. This retrieves detailed message delivery events and threat context to investigate suspicious emails and user-reported phishing.

Can I investigate threat campaigns and associated malware families using Proofpoint TAP?

Yes, you can investigate threat campaigns using Proofpoint TAP by gathering intelligence on campaign actors, malware families, and associated infrastructure. This contextualizes individual threats within broader attack patterns for campaign analysis.

Does Proofpoint TAP threat intelligence integration require a separate SIEM API setup?

Proofpoint TAP threat intelligence integration uses Proofpoint's SIEM API for real-time threat data extraction. You must have your SIEM API access configured to retrieve click events, message events, and campaign details for threat hunting.

What types of threats can I query from Proofpoint TAP for malware analysis?

You can query active URL threats, attachment threats, and message text threats from Proofpoint TAP for malware analysis. The SIEM API extracts these threat types along with message delivery and click events for comprehensive security analysis.