proofpoint_forensics_get_threat
Retrieve forensic evidence for a specific threat using its threat ID. Get behavioral analysis, network activity, file modifications, and other indicators to investigate threats.
Instructions
Get forensic evidence for a specific threat. Returns behavioral analysis, network activity, file modifications, and other forensic indicators.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| threat_id | Yes | The threat ID to get forensics for | |
| includeCampaignForensics | No | Include forensics for the entire campaign (default: false) |