Documentation Index

Fetch the complete documentation index at: https://docs.safe.security/llms.txt

Use this file to discover all available pages before exploring further.

Proofpoint Connector Guide

Prev Next

Overview

Proofpoint helps organizations strengthen their human security posture by providing Security Awareness Training (SAT) and phishing simulation programs that educate users and measure susceptibility to social engineering attacks. By continuously assessing user behavior, Proofpoint enables organizations to identify high-risk individuals and tailor training for maximum impact.

The Balbix integration automatically ingests Proofpoint user data and phishing simulation results, normalizes the data, and enriches it with context for accurate risk analysis and prioritization. This integration provides visibility into employee security awareness levels and helps correlate human risk with technical exposures for a holistic security posture.

Balbix leverages AI to aggregate, normalize, and deduplicate data ingested from across your IT and security ecosystem. This unified view of inventory and exposures enriched with operational and business context, enables deployment gap analysis, risk-based exposure management, and cyber risk quantification. These insights help organizations drive faster, more informed, and more scalable risk reduction.

Prerequisites

To obtain Proofpoint service principal and service principal secret string:

  1. Log in to the ProofPoint portal by accessing https://threatinsight.proofpoint.com/.

  2. Click the Settings icon in the upper right corner, then click Connected Applications.

  3. Click Create New Credential.

  4. Specify a name and click Generate.

  5. Record the Service Principal and Secret represented by a string of letters and numbers. 

Field Mappings

Data Mapping

Imported Field

Balbix Field

useremailaddress

user_email

userfirstname

user_first_name

userlastname

user_last_name

datalastupdated

source_last_observed_at

usertags

user_tags

Phishing Event Mappings

Proofpoint Field

Mapped Field

campaignname

user_phishing_campaign_name

campaign_guid

user_phishing_campaign_id

eventtimestamp

user_phishing_evaluation_date


Connector Setup

Follow this procedure to set up your connector:

API Reference Documentation

https://help.proofpoint.com/Threat_Insight_Dashboard/API_Documentation