proofpoint_threat_get_iocs
Fetch indicators of compromise for a specific campaign or time range to reveal malicious URLs, IPs, domains, and file hashes.
Instructions
Get indicators of compromise (IOCs) for a specific campaign or time range. Returns URLs, IPs, domains, file hashes associated with threats.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| interval | No | Predefined interval: "PT30M" or "PT1H" | |
| sinceTime | No | ISO 8601 date/time to fetch IOCs since | |
| campaign_id | No | Campaign ID to get IOCs for | |
| threat_type | No | Filter by threat type |