Proofpoint
Telemetry Evidence
These values show how indexed rules identify Proofpoint telemetry.Kusto
ProofpointPOD ProofPointTAPClicksPermittedV2_CL ProofPointTAPMessagesDeliveredV2_CL Panther
Proofpoint.Event proofpoint
Detection Rules
Kusto #
- ProofpointPOD - Binary file in attachment source medium: 'Detects when email received with binary file as attachment.'
T1078 - ProofpointPOD - Email sender in TI list source medium: 'Email sender in TI list.'
T1078,T1567 - ProofpointPOD - Email sender IP in TI list source medium: 'Email sender IP in TI list.'
T1078,T1567 - ProofpointPOD - High risk message not discarded source low: 'Detects when email with high risk score was not rejected or discarded by filters.'
T1566 - ProofpointPOD - Multiple archived attachments to the same recipient source medium: 'Detects when multiple emails where sent to the same recipient with large archived attachments.'
T1567 - ProofpointPOD - Multiple large emails to the same recipient source medium: 'Detects when multiple emails with large size where sent to the same recipient.'
T1567 - ProofpointPOD - Multiple protected emails to unknown recipient source medium: 'Detects when multiple protected messages where sent to early not seen recipient.'
T1567 - ProofpointPOD - Possible data exfiltration to private email source medium: 'Detects when sender sent email to the non-corporate domain and recipient's username is the same as sender's username.'
T1078 - ProofpointPOD - Suspicious attachment source medium: 'Detects when email contains suspicious attachment (file type).'
T1566 - ProofpointPOD - Weak ciphers source low: 'Detects when weak TLS ciphers are used.'
T1573
Panther #
- Proofpoint Active Threat Campaign Detected source high: This rule alerts when Proofpoint identifies an email as part of an active threat campaign. Campaign-based threats indicate coordinated attacks that are targeting multiple organizations or users. These threats are typically more sophisticated and require immediate attention.
T1204,T1566,T1587 - Proofpoint High Impostor Score Detected source medium: This rule alerts when Proofpoint detects a high impostor score (50+), indicating potential Business Email Compromise (BEC) or impersonation attacks. The impostor score measures the likelihood that the sender is impersonating a trusted entity. Severity is dynamic based on the score: CRITICAL (80+), HIGH (65+), MEDIUM (50+).
T1566 - Proofpoint Malware Detected source high: This rule alerts when Proofpoint detects malware in an email message. It triggers when emails are quarantined with the malware rule or when the malware score is 90 or higher. Events quarantined to the Virus folder or with the notcleaned rule are handled by the Virus Detected rule instead.
T1204,T1566 - Proofpoint Multiple Threats Detected source high: This rule alerts when three or more active threats are detected in a single email message. This indicates a sophisticated multi-vector attack combining malware, phishing URLs, and malicious attachments. Severity is dynamic: CRITICAL (5+ threats), HIGH (3-4 threats).
T1204,T1566 - Proofpoint Phishing Email Detected source high: This rule alerts when Proofpoint detects phishing attempts in email. It triggers when emails are quarantined with the phish rule, have a high phish score (90+), or contain active phishing threats in the threats map.
T1566,T1598 - Proofpoint Virus Detected source high: This rule alerts when Proofpoint detects a virus in an email that cannot be disinfected. It triggers when emails are quarantined to the Virus folder or have the notcleaned quarantine rule applied.
T1204,T1566
Other Index Content
This content is indexed for research but excluded from the detection-rule headline.Kusto #
T1566, T1566.001T1566, T1566.002