Proofpoint TAP
Connect Proofpoint TAP to Radiant Security to forward URL Defense click events for AI triage.
Last updated
Was this helpful?
Connect Proofpoint TAP to Radiant Security to forward URL Defense click events for AI triage.
Proofpoint TAP is an email security product that detects and blocks phishing, malware, and credential-theft threats delivered through email. Connecting Proofpoint TAP forwards URL Defense click events to Radiant Security via the Proofpoint API. Radiant uses these events for AI triage, giving analysts visibility into phishing links accessed from unmanaged devices and identifying users who clicked from personal machines.
Looking for the response action connector? See Execute Response Actions with Proofpoint TAP.
At the end of this configuration, you provide Radiant Security with the following values:
Service Principal
Secret
API Base URL
Sign in to the TAP dashboard.
Navigate to Settings > Connected Applications.
Click Create New Credential.
Enter a name for the new credential, then click Generate.
Copy the Service Principal and Secret values from the prompt. You will provide these values to Radiant Security in the next section.
Copy the Secret value now. It cannot be retrieved later.
Sign in to Radiant Security.
From the navigation menu, select Settings > Data Connectors and click + Add Connector.
Search for and select Proofpoint API v2, then click Data Feeds.
Under Select your data feeds, select URL Defense, then click Credentials.
Under Credential Name, enter an identifiable name for this credential (e.g., Proofpoint Credentials).
Under Required Credentials, enter the following:
Service Principal: the value copied in the previous section.
Secret: the value copied in the previous section.
API Base URL: the URL of your Proofpoint TAP dashboard.
Click Add Connector to save the configuration.
After Proofpoint TAP begins forwarding, confirm events are reaching Radiant.
In Radiant, navigate to Log Management.
Filter by rs_connectorType:"proofpoint_url_defense".
Confirm recent events appear.
Allow several minutes for events to be parsed, indexed, and available for search.
Last updated
Was this helpful?
Was this helpful?