Proofpoint ET Intelligence

Check the public IP addresses and domains Guard discovers against Proofpoint ET Intelligence and flag any tied to malware activity.

The Proofpoint ET Intelligence integration checks your attack surface against Proofpoint's Emerging Threats (ET) Intelligence in the Praetorian Guard Platform (PGP). When Guard discovers a new public IP address or domain, it asks ET Intelligence whether malware has been seen contacting it, and raises a risk when it has. This guide walks you through connecting ET Intelligence to Guard.

What the integration does

Once connected, Guard checks each newly discovered asset that is a public IPv4 address, public IPv6 address, or domain. Private and reserved IP addresses and invalid domain names are skipped. Assets that were already in Guard when you connected ET Intelligence are not checked. For each asset, Guard looks up in ET Intelligence:

  • URLs that malware has requested on that IP address or domain.
  • Malware samples ET Intelligence has linked to it, identified by their MD5 hashes.

When either lookup returns results, Guard adds an informational risk to the asset, titled Proofpoint ET Intelligence related malware activity. The risk's threat intelligence data lists the URLs, the MD5 hashes of the malware samples, the ET Intelligence API paths that matched, and when Guard retrieved them.

Guard keeps the infrastructure ET Intelligence reports only as evidence on the risk. It never adds it to your assets.

The integration only reads from ET Intelligence.

Prerequisites

Connect ET Intelligence in Guard

  1. In Guard, go to Integrations and open Threat Intelligence → Proofpoint ET Intelligence.
  2. In ET Intelligence API Key, enter your API key.
  3. Click Connect.

Before saving, Guard makes a test request to ET Intelligence with your key. If it fails, Guard shows the error and does not save the integration.

Verify the integration

After Guard discovers new public assets, go to Vulnerabilities and search for proofpoint-et-intelligence. Matching risks are titled Proofpoint ET Intelligence related malware activity. Guard only raises this risk when ET Intelligence links an asset to malware, so no results can simply mean nothing matched.

Troubleshooting

Message

What to do

Missing Required Field

Enter your ET Intelligence API key.

Authentication Failed: Proofpoint ET Intelligence rejected the supplied API key

Check the key at etadmin.proofpoint.com/api-access.

License Required: Proofpoint ET Intelligence authenticated the API key, but the subscription is not entitled to this endpoint or has expired

Renew your ET Intelligence subscription, or confirm it includes API access.

Connection Failed: Proofpoint ET Intelligence rate limited the request after bounded retries

Wait a few minutes and try again. Guard spaces and retries its requests.

Connection Failed: Proofpoint ET Intelligence remained unavailable after bounded retries

ET Intelligence is unavailable. Try again later.

Connection Failed: Could not validate Proofpoint ET Intelligence

Guard could not complete the test request. Try again later.

Validation Failed: ET Intelligence API returned HTTP followed by a status code

Check the API key and try again.

An asset was never checked

Guard checks only public IP addresses and domains discovered after you connected ET Intelligence.

If you need help with this integration, contact support@praetorian.com.