Skip to content

[SAASINT-4241] DDS: Proofpoint TAP: Crawler Integration v1.0.0 #20587

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 8 commits into
base: master
Choose a base branch
from

Conversation

shubhamvekariya-crest
Copy link
Contributor

What does this PR do?

This is a initial release PR of Proofpoint TAP integration including all the required assets.

Additional Notes

  • Crawler code for this integration has been committed in its respective repo
  • OOTB detection rules JSON would be shared separately with the required teams as a part of separate repository.
  • Since during the standard attribute remapping we are not preserving the source attributes as per suggested best practices, it would result in filters using these standard attributes populating the values of other integrations as well as per current Datadog behaviour.

Review checklist (to be filled by reviewers)

  • Feature or bugfix MUST have appropriate tests (unit, integration, e2e)
  • Add the qa/skip-qa label if the PR doesn't need to be tested during QA.
  • If you need to backport this PR to another branch, you can add the backport/<branch-name> label to the PR and it will automatically open a backport PR once this one is merged

@torosmassa torosmassa changed the title DDS: Proofpoint TAP: Crawler Integration v1.0.0 [SAASINT-4241] DDS: Proofpoint TAP: Crawler Integration v1.0.0 Jun 26, 2025
iadjivon
iadjivon previously approved these changes Jul 15, 2025
Copy link
Contributor

@iadjivon iadjivon left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for this PR.
This is approved from DOCS with some some edits. Thanks!

## Overview

This check monitors [Proofpoint TAP][1].
[Proofpoint TAP (Targeted Attack Protection)][1] is a cybersecurity solution designed to detect, mitigate, and block advanced threats that target people through email. It leverages a next-generation email security platform to provide visibility into all email communications.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
[Proofpoint TAP (Targeted Attack Protection)][1] is a cybersecurity solution designed to detect, mitigate, and block advanced threats that target people through email. It leverages a next-generation email security platform to provide visibility into all email communications.
[Proofpoint TAP (Targeted Attack Protection)][1] is a cybersecurity solution designed to detect, mitigate, and block advanced threats that target people through email. It uses a next-generation email security platform to provide visibility into all email communications.

As a part of a docs accessibility, we have a list of words/phrases to avoid. Leverage is one of these words, and we replace it with use. Let me know if you have any questions.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done 👍


### Installation
This integration gathers and forwards above mentioned events to Datadog for seamless analysis. Datadog leverages its built-in log pipelines to parse and enrich these logs, facilitating easy search and detailed insights. With preconfigured dashboards, the integration offers clear visibility into activities within the Proofpoint TAP platform. Additionally, it includes ready-to-use Cloud SIEM detection rules for enhanced monitoring and security.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
This integration gathers and forwards above mentioned events to Datadog for seamless analysis. Datadog leverages its built-in log pipelines to parse and enrich these logs, facilitating easy search and detailed insights. With preconfigured dashboards, the integration offers clear visibility into activities within the Proofpoint TAP platform. Additionally, it includes ready-to-use Cloud SIEM detection rules for enhanced monitoring and security.
This integration gathers and forwards above mentioned events to Datadog for seamless analysis. Datadog uses its built-in log pipelines to parse and enrich these logs, facilitating easy search and detailed insights. With preconfigured dashboards, the integration offers clear visibility into activities within the Proofpoint TAP platform. Additionally, it includes ready-to-use Cloud SIEM detection rules for enhanced monitoring and security.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done 👍

"id": 4742521996525905,
"definition": {
"type": "note",
"content": "**[Proofpoint TAP](https://www.proofpoint.com/uk/products/advanced-threat-protection/targeted-attack-protection)** is a cybersecurity solution designed to detect, mitigate, and block advanced threats that target people through email. It leverages a next-generation email security platform to provide visibility into all email communications.\n\nThis dashboard provides a comprehensive summary of proofpoint TAP events.\n\nFor more information, see the [Proofpoint TAP Documentation](https://docs.datadoghq.com/integrations/proofpoint_tap/).\n\n**Tips**:\n - Use the timeframe selector in the upper-right corner of the dashboard to change the default timeframe.\n - Clone this dashboard to rearrange, modify, and add widgets and visualizations.\n\n",
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
"content": "**[Proofpoint TAP](https://www.proofpoint.com/uk/products/advanced-threat-protection/targeted-attack-protection)** is a cybersecurity solution designed to detect, mitigate, and block advanced threats that target people through email. It leverages a next-generation email security platform to provide visibility into all email communications.\n\nThis dashboard provides a comprehensive summary of proofpoint TAP events.\n\nFor more information, see the [Proofpoint TAP Documentation](https://docs.datadoghq.com/integrations/proofpoint_tap/).\n\n**Tips**:\n - Use the timeframe selector in the upper-right corner of the dashboard to change the default timeframe.\n - Clone this dashboard to rearrange, modify, and add widgets and visualizations.\n\n",
"content": "**[Proofpoint TAP](https://www.proofpoint.com/uk/products/advanced-threat-protection/targeted-attack-protection)** is a cybersecurity solution designed to detect, mitigate, and block advanced threats that target people through email. It uses a next-generation email security platform to provide visibility into all email communications.\n\nThis dashboard provides a comprehensive summary of proofpoint TAP events.\n\nFor more information, see the [Proofpoint TAP Documentation](https://docs.datadoghq.com/integrations/proofpoint_tap/).\n\n**Tips**:\n - Use the timeframe selector in the upper-right corner of the dashboard to change the default timeframe.\n - Clone this dashboard to rearrange, modify, and add widgets and visualizations.\n\n",

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done 👍

@temporal-github-worker-1 temporal-github-worker-1 bot dismissed iadjivon’s stale review July 16, 2025 05:08

Review from iadjivon is dismissed. Related teams and files:

  • documentation
    • proofpoint_tap/README.md
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants