Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Proofpoint

ASecurity

Expert agent for Proofpoint Email Protection. Covers SEG, Targeted Attack Protection, URL Defense, Very Attacked People, TRAP post-delivery remediation, and email DLP. WHEN: \"Proofpoint\", \"Proofpoint SEG\", \"TAP\", \"Targeted Attack Protection\", \"URL Defense\", \"TRAP\", \"Nexus People Risk\", \"Very Attacked People\", \"VAP\", \"Proofpoint quarantine\", \"Proofpoint DLP\".

4 stars
0 votes
0 copies
0 views
Added 9/24/2026
securityrustgoswiftgitapisecurity

Works with

cliapi

Security Analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned 9/24/2026

$npx -y skills add chrishuffman5/domain-expert --skill proofpoint --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Proofpoint?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Proofpoint
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-proofpoint/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-proofpoint)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: proofpoint
description: "Expert agent for Proofpoint Email Protection. Covers SEG, Targeted Attack Protection, URL Defense, Very Attacked People, TRAP post-delivery remediation, and email DLP. WHEN: \"Proofpoint\", \"Proofpoint SEG\", \"TAP\", \"Targeted Attack Protection\", \"URL Defense\", \"TRAP\", \"Nexus People Risk\", \"Very Attacked People\", \"VAP\", \"Proofpoint quarantine\", \"Proofpoint DLP\"."
license: MIT
---

# Proofpoint Email Protection

This skill covers Proofpoint's email security platform, covering the full product suite: Secure Email Gateway (SEG), Targeted Attack Protection (TAP), URL Defense, Nexus People Risk Explorer, and Threat Response Auto-Pull (TRAP). Proofpoint secures email for approximately 83% of the Fortune 100.

## How to Approach Tasks

When you receive a request:

1. **Classify** the request:
   - **SEG configuration** — Policies, rules, filtering, quarantine management
   - **TAP/URL Defense** — Sandbox configuration, URL rewriting, click tracking
   - **Investigation** — Message trace, TRAP remediation, threat hunting
   - **People risk** — VAP analysis, Nexus People Risk Explorer
   - **DLP/encryption** — Email DLP policies, email encryption (Proofpoint Encryption)
   - **Architecture** — Deployment model, connector configuration, MX setup

2. **Identify the deployment** — Cloud (Proofpoint hosted), on-premises, or hybrid. Cloud API vs. SEG deployment.

3. **Load context** — For architecture and product integration questions, read `references/architecture.md`.

4. **Recommend** — Provide Proofpoint-specific guidance including UI navigation paths, policy rule syntax, and SmartSearch query examples.

## Proofpoint SEG Architecture

### Mail Flow

Proofpoint SEG operates as an inline gateway — the organization's MX record points to Proofpoint's infrastructure, not directly to the mail server.

**Inbound flow:**
```
Internet → Proofpoint SEG (MX: *.pphosted.com) → Filtering → Customer mail server (M365/Google/on-prem)
```

**Outbound flow:**
```
Customer mail server → Proofpoint SEG (SMTP smarthost) → Internet
```

**MX record (Proofpoint hosted):**
```
example.com  MX  10  mail.pphosted.com.
```

**Locking M365 to Proofpoint (prevent SEG bypass):**
In Exchange Admin Center → Mail flow → Connectors:
- Create inbound connector: From "Partner organization" to "Office 365"
- Restrict to Proofpoint IP ranges
- Require TLS

### Filtering Stack (Inbound, in order)

1. **Connection-level filtering** — IP reputation, senderscore, blocklists (Cloudmark, Spamhaus, Proofpoint's own)
2. **Reputation scoring** — Dynamic Reputation (DR) — ML-based IP and domain reputation
3. **Anti-virus** — Multiple AV engines (McAfee, Sophos, Proofpoint's own)
4. **Anti-spam** — Machine learning + rules; configurable spam threshold (score 0-100)
5. **TAP Sandbox** — Detonation for suspicious attachments (if TAP licensed)
6. **URL Defense** — URL rewriting and analysis (if TAP licensed)
7. **Content policies** — Custom rules, DLP, regulatory compliance
8. **Email authentication** — SPF, DKIM, DMARC verification and enforcement

### Policy and Rule Framework

Proofpoint policies are organized hierarchically:

**Policy Routes:** Define which policy applies to which traffic (based on sender domain, recipient domain, IP, etc.)

**Policy (Filter) Rules:** Within a route, rules are processed in order (priority). Each rule can:
- Match on: sender, recipient, subject, body, attachments, headers, authentication results, spam score
- Take action: deliver, quarantine, block, tag subject, add header, redirect, discard, encrypt

**Rule action precedence:** Block > Quarantine > Discard > Encrypt > Deliver (higher severity wins when multiple rules match)

**Quarantine folders:**
- Default: Spam, Bulk, Adult, Virus, Impostor, Phish
- Custom quarantine folders can be created per policy
- Users can access Proofpoint End User Spam Digest (daily email with quarantined message summary)

## Targeted Attack Protection (TAP)

TAP provides sandboxing and URL analysis for advanced threats that evade traditional signature-based detection.

### TAP Attachment Defense

**Supported file types for sandbox detonation:**
- Office documents (`.doc`, `.docx`, `.xls`, `.xlsx`, `.ppt`, `.pptx`, `.xlsm`, `.docm`)
- PDFs
- Archives (`.zip`, `.rar`, `.7z` — one level)
- Executables (`.exe`, `.dll`)
- Scripts (`.js`, `.vbs`, `.ps1`, `.bat`)
- Image files with embedded macros

**Detonation process:**
1. Message arrives with attachment
2. Attachment submitted to TAP sandbox (cloud-based, multiple OS environments)
3. Behavioral analysis: file system, network, process, registry activity
4. Static analysis: code patterns, embedded URLs, macros
5. Verdict returned: Malicious / Suspicious / Clean
6. Action applied per TAP policy

**TAP policies:**
- **Allow on timeout:** If detonation times out, deliver or hold. Recommendation: Hold to prevent time-sensitive attacks.
- **Malicious action:** Quarantine (recommended) — deliver a quarantine notification
- **Suspicious action:** Deliver with warning tag or quarantine

### URL Defense

URL Defense rewrites all URLs at delivery time and performs time-of-click analysis.

**Rewritten URL format:**
```
Original: https://attacker.com/malware
Rewritten: https://urldefense.proofpoint.com/v2/url?u=https-3A__attacker.com_malware&d=...&c=...&r=...&m=...&s=...
```

**Version 3 (newer) format:**
```
https://urldefense.com/v3/__https://attacker.com/malware__;<signature>
```

**Time-of-click analysis:**
When a user clicks a URL Defense-wrapped link:
1. Request hits Proofpoint URL Defense servers
2. URL checked against Proofpoint's threat intelligence
3. Redirect chain followed, final URL checked
4. Page detonated if unknown/suspicious
5. Block or pass based on verdict

**Click tracking (TAP dashboard):**
- All URL clicks logged with timestamp, user identity, URL, verdict, action
- Used to identify who clicked malicious links post-incident
- Available via API for SIEM integration

**URL Defense bypass list:** Add trusted URLs that should not be rewritten (internal tools, SSO URLs that break with rewriting, banking partner URLs with signature validation).

**Configuring URL Defense policy:**
```
TAP → Email Filtering → URL Defense
- Enable URL rewriting: On
- Rewrite all URLs: On (not just suspicious)
- Follow redirects: On
- Block malicious clicks: On
- Allow suspicious with warning: Configurable
- Permitted click-throughs: Off (strictest)
```

## Nexus People Risk Explorer

Nexus integrates threat data with identity to quantify human risk across the organization.

### Very Attacked People (VAP)

VAP identifies users who are disproportionately targeted by advanced threats (credential phishing, malicious attachments, targeted attacks — not bulk spam).

**VAP calculation factors:**
- Volume of targeted attacks received (weighted by attack sophistication)
- Percentage of attacks in top percentile
- Attack types: credential phishing, malware delivery, BEC
- Time trend (increasing or decreasing targeting)

**Use cases:**
- Prioritize security awareness training for VAPs
- Apply stricter email policies to VAP group (e.g., force sandbox all attachments)
- Provide security coaching to high-VAP executives
- Feed VAP list to incident response prioritization

**VAP API integration:**
Nexus exposes VAP data via REST API for integration with HR systems, PAM tools, and SIEM:
```
GET /v2/people/vap
Authorization: Bearer {api_key}
Response: [{email, firstName, lastName, vap_score, attack_count, ...}]
```

### Attack Index

Normalized attack severity scoring per user. Combines:
- Attack volume
- Attack sophistication (TAP sandbox hits weighted more than spam)
- Trend direction
- Historical baseline

Enables comparison across departments and peer groups.

## TRAP — Threat Response Auto-Pull

TRAP automates post-delivery email remediation, removing malicious messages from user mailboxes after they have been delivered.

### How TRAP Works

**Trigger sources:**
1. TAP detection — malicious verdict on delivered message
2. Manual submission by analyst
3. Automated playbook from SIEM/SOAR integration
4. Proofpoint Threat Intelligence feed

**TRAP remediation flow:**
1. Malicious message identified (by hash, message ID, or TAP verdict)
2. TRAP queries mail server for all mailboxes containing the message
3. TRAP connects to mail server via API (EWS for Exchange, Graph API for M365, IMAP for Google)
4. Message moved to Deleted Items or permanently deleted based on policy
5. Forwarded copies (if message was forwarded by user) also remediated
6. Audit trail maintained for all actions

**TRAP for M365:**
```
TRAP → Microsoft Graph API → Exchange Online mailboxes
Authentication: Service account or app registration with Mail.ReadWrite permission
```

**TRAP for Google Workspace:**
```
TRAP → Gmail API → Google Workspace mailboxes
Authentication: Service account with domain-wide delegation
```

### TRAP Abuse Mailbox Integration

TRAP can automate processing of user-reported phishing (from abuse/phishing@example.com mailbox):

1. Users forward suspicious emails to phishing@example.com
2. TRAP monitors the abuse mailbox
3. TRAP analyzes reported messages
4. If confirmed malicious: automatically remediate from all mailboxes
5. If uncertain: route to analyst queue
6. Always send reporter feedback (confirmed phish / not malicious)

**Abuse mailbox workflow configuration:**
- Define disposition rules (malicious threshold for auto-remediation)
- Configure reporter notifications
- Set escalation to Proofpoint or analysts for borderline cases
- Track reporter accuracy over time (gamification for security awareness)

## Email DLP

Proofpoint Email DLP scans outbound email (and optionally inbound) for sensitive data.

### Policy Configuration

**Data types (built-in):**
- Credit card numbers (Luhn algorithm)
- Social Security Numbers
- HIPAA-regulated terms (PHI indicators)
- PCI DSS cardholder data
- GDPR personal data identifiers
- Financial data (ABA routing numbers, IBAN, SWIFT)

**Custom dictionaries:**
Define organization-specific sensitive terms, product names, project code names. Weight terms by sensitivity level.

**DLP actions:**
- **Quarantine:** Hold for compliance review
- **Block:** Reject with NDR
- **Encrypt:** Automatically encrypt the message (requires Proofpoint Encryption)
- **Tag:** Add header or subject prefix for downstream processing
- **Notify:** Alert sender, manager, compliance officer
- **Log only:** Record match without blocking (for monitoring/baselining)

**DLP policy example — SSN detection:**
```
Rule: Outbound SSN Detection
Match: Body or attachment contains SSN pattern (9-digit format) AND count >= 5
Action: Quarantine to "DLP Review" folder
Notification: Alert compliance@example.com
Exception: If recipient is HR@example.com or Payroll@example.com
```

## Proofpoint Encryption

On-demand or policy-based email encryption for regulatory compliance.

**Encryption modes:**
- **Push:** Recipient receives notification, clicks link to Proofpoint Secure Reader portal to view message
- **Pull:** Recipient receives encrypted message as attachment (TLS-wrapped ZIP) — requires password or M365 identity
- **S/MIME / PGP:** Proofpoint can sign/encrypt with S/MIME if certificates are available

**Auto-encryption triggers:**
- DLP policy match (encrypt instead of block)
- Keyword in subject (e.g., [ENCRYPT], CONFIDENTIAL)
- Recipient domain in encryption list (for specific partner relationships)
- User-initiated (Outlook plugin button)

## Proofpoint SIEM Integration

**Log types available:**
- **Message logs:** All processed messages, filtering decisions, scores
- **Tap Syslog (SIEM format):** Threat events, click events, blocked messages
- **TRAP audit logs:** Remediation actions

**Proofpoint SIEM API (TAP):**
```
GET https://tap-api-v2.proofpoint.com/v2/siem/all
?format=json&sinceSeconds=3600
Authorization: Basic {encoded_credentials}
```

Response includes: `messagesDelivered`, `messagesBlocked`, `clicksPermitted`, `clicksBlocked`

**Supported SIEM integrations:**
- Splunk (Proofpoint App for Splunk, available on Splunkbase)
- Microsoft Sentinel (Proofpoint connector)
- IBM QRadar (Proofpoint DSM)
- Generic syslog CEF format

## SmartSearch — Message Investigation

Proofpoint's SmartSearch provides detailed message tracing and filtering.

**Key search fields:**
- `sender` — From address or domain
- `recipient` — To address or domain
- `subject` — Subject line (supports wildcards)
- `disposition` — delivered, quarantined, discarded, blocked
- `message_id` — RFC 2822 Message-ID header value
- `routing` — Policy route matched
- `spam_score` — Score range filter
- `date_range` — Time window

**Investigation workflow:**
1. SmartSearch → locate message by sender/recipient/subject/date
2. View message details: headers, filtering decisions, rule matches, scores
3. View related messages: same campaign, same sender, same attachment hash
4. Take action: release from quarantine, block sender, submit to TAP
5. Export message for forensic analysis

## Reference Files

Load for deep product architecture knowledge:

- `references/architecture.md` — Proofpoint SEG architecture, TAP Nexus threat intelligence, URL Defense v3 format, TRAP API integration, Proofpoint on-premises vs. cloud deployment.

Attribution

chrishuffman5chrishuffman5
View sourceSee grades on GitHubMore from chrishuffman5 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Springboot Security

Java Spring Boot 服务中关于身份验证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全的 Spring Security 最佳实践。

2456590 votes

Security Review

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

2456590 votes

Paperclip Evals

Choose, inspect, validate, and report Paperclip Runner or Product E2E evaluations while preserving evidence, provenance, cost, and failure classification.

953190 votes

Paperclip Task Bridge

Create, comment on, update, and list Paperclip tasks from Hermes using scoped Paperclip API credentials.

953190 votes

Summarize Status

Write a short, colloquial summary for a Paperclip summary slot: open with the 1–3 specific, concrete actions the reader needs to take right now to unblock the work, then a brief plain-language status, streaming progress as it works.

953190 votes
View all in security →