TriageMTTR

Proofpoint Phishing Triage

Classifies a reported message against a known threat campaign and opens one case for the campaign rather than the report.

Part of Phishing report triage

Tools

Proofpoint, Jira Service Management, Slack

Outcomes

One case per campaign • All recipients listed • Block request sent for approval

Documentation

Instruction-ready detail below

When <in:email>a submitted message</in:email> matches a known campaign, <jira>open one ticket</jira> listing every recipient, then <slack>ask</slack> an analyst to approve the campaign-wide block.

Instruction file

When <in:email>a submitted message</in:email> matches a known campaign, <jira>open one ticket</jira> listing every recipient, then <slack>ask</slack> an analyst to approve the campaign-wide block.

Setup requirements

Tools

Proofpoint, Jira Service Management, Slack

Trigger

When a submitted message matches a known threat campaign

Setup time

15 minutes

Download

Start with one instruction file.

Download the app and begin with drafts and checklists before you write anything back.

  • •Plain-language instructions
  • •Runs on your machine
  • •Works with your existing setup
  • •Reviewable activity history
Download