Proofpoint ET Intelligence
Check the public IP addresses and domains Guard discovers against Proofpoint ET Intelligence and flag any tied to malware activity.
The Proofpoint ET Intelligence integration checks your attack surface against Proofpoint's Emerging Threats (ET) Intelligence in the Praetorian Guard Platform (PGP). When Guard discovers a new public IP address or domain, it asks ET Intelligence whether malware has been seen contacting it, and raises a risk when it has. This guide walks you through connecting ET Intelligence to Guard.
What the integration does
Once connected, Guard checks each newly discovered asset that is a public IPv4 address, public IPv6 address, or domain. Private and reserved IP addresses and invalid domain names are skipped. Assets that were already in Guard when you connected ET Intelligence are not checked. For each asset, Guard looks up in ET Intelligence:
- URLs that malware has requested on that IP address or domain.
- Malware samples ET Intelligence has linked to it, identified by their MD5 hashes.
When either lookup returns results, Guard adds an informational risk to the asset, titled Proofpoint ET Intelligence related malware activity. The risk's threat intelligence data lists the URLs, the MD5 hashes of the malware samples, the ET Intelligence API paths that matched, and when Guard retrieved them.
Guard keeps the infrastructure ET Intelligence reports only as evidence on the risk. It never adds it to your assets.
The integration only reads from ET Intelligence.
Prerequisites
- A Proofpoint ET Intelligence subscription and API key. Manage keys at etadmin.proofpoint.com/api-access.
- Permission to add integrations in Guard.
Connect ET Intelligence in Guard
- In Guard, go to Integrations and open Threat Intelligence → Proofpoint ET Intelligence.
- In ET Intelligence API Key, enter your API key.
- Click Connect.
Before saving, Guard makes a test request to ET Intelligence with your key. If it fails, Guard shows the error and does not save the integration.
Verify the integration
After Guard discovers new public assets, go to Vulnerabilities and search for proofpoint-et-intelligence. Matching risks are titled Proofpoint ET Intelligence related malware activity. Guard only raises this risk when ET Intelligence links an asset to malware, so no results can simply mean nothing matched.
Troubleshooting
If you need help with this integration, contact support@praetorian.com.