Proofpoint

Telemetry Evidence

These values show how indexed rules identify Proofpoint telemetry.

Kusto

  • Queried source table ProofpointPOD (10 rules)
  • Queried source table ProofPointTAPClicksPermittedV2_CL (1 rule)
  • Queried source table ProofPointTAPMessagesDeliveredV2_CL (1 rule)

Panther

  • Log type Proofpoint.Event (6 rules)
  • Platform proofpoint (6 rules)

Detection Rules

Kusto #

Panther #

  • Proofpoint Active Threat Campaign Detected source high: This rule alerts when Proofpoint identifies an email as part of an active threat campaign. Campaign-based threats indicate coordinated attacks that are targeting multiple organizations or users. These threats are typically more sophisticated and require immediate attention.T1204, T1566, T1587
  • Proofpoint High Impostor Score Detected source medium: This rule alerts when Proofpoint detects a high impostor score (50+), indicating potential Business Email Compromise (BEC) or impersonation attacks. The impostor score measures the likelihood that the sender is impersonating a trusted entity. Severity is dynamic based on the score: CRITICAL (80+), HIGH (65+), MEDIUM (50+).T1566
  • Proofpoint Malware Detected source high: This rule alerts when Proofpoint detects malware in an email message. It triggers when emails are quarantined with the malware rule or when the malware score is 90 or higher. Events quarantined to the Virus folder or with the notcleaned rule are handled by the Virus Detected rule instead.T1204, T1566
  • Proofpoint Multiple Threats Detected source high: This rule alerts when three or more active threats are detected in a single email message. This indicates a sophisticated multi-vector attack combining malware, phishing URLs, and malicious attachments. Severity is dynamic: CRITICAL (5+ threats), HIGH (3-4 threats).T1204, T1566
  • Proofpoint Phishing Email Detected source high: This rule alerts when Proofpoint detects phishing attempts in email. It triggers when emails are quarantined with the phish rule, have a high phish score (90+), or contain active phishing threats in the threats map.T1566, T1598
  • Proofpoint Virus Detected source high: This rule alerts when Proofpoint detects a virus in an email that cannot be disinfected. It triggers when emails are quarantined to the Virus folder or have the notcleaned quarantine rule applied.T1204, T1566

Other Index Content

This content is indexed for research but excluded from the detection-rule headline.

Kusto #