Skip to content

Proofpoint TAP

You can integrate Proofpoint TAP with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

Proofpoint TAP product overview

Proofpoint TAP is a cloud-based email security tool that safeguards users against advanced email threats, including targeted phishing attacks, malware, and Business Email Compromise (BEC). It leverages advanced analytics and machine learning to detect and block threats that typically bypass conventional defenses, offering a holistic approach to email threat prevention.

What we ingest

Sophos XDR collects Proofpoint TAP data over HTTPS by polling Proofpoint's TAP SIEM API for your account, using the Service Principal and Secret from the integration. Proofpoint returns each event category as JSON, and we ingest the entries in the order Proofpoint delivers them for each requested time window, following Proofpoint's pagination until the range is complete. We use the following Proofpoint TAP event categories:

  • Messages delivered: Messages that TAP analyzed and delivered, including any threat indicators retroactively associated with them.
  • Clicks permitted: User clicks on TAP-rewritten URLs that were permitted at click time, including the URL and the user.

Proofpoint sends these records exactly as the SIEM API returns them. Which categories and fields appear depends on which Proofpoint TAP features are licensed and enabled in your tenant (for example, URL Defense and Attachment Defense) and which event types your SIEM API service principal is authorized to get.

Event and data types

We ingest the following event and data types from Proofpoint TAP:

Note

The same email envelope (message ID, sender, recipient, subject, headers, threat classification, and verdict) is present across the categories. Click categories additionally carry URL context.

  • Email messages delivered: TAP-delivered email messages with sender, recipient, subject, message identifiers, and any threat indicators TAP later associated with the message. Normalized to email telemetry.
  • URL clicks permitted: TAP-rewritten URL click events that TAP permitted at click time, including the original URL, the rewritten URL, the user, and the click outcome. Normalized to email telemetry and HTTP telemetry.

Data provided by this integration

Data provided by Proofpoint TAP gets normalized to the following schemas:

  • email
  • http

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation