proofpoint_forensics_get_threat
Get forensic evidence for a specific threat, including behavioral analysis, network activity, and file modifications, to support incident investigation.
Instructions
Get forensic evidence for a specific threat. Returns behavioral analysis, network activity, file modifications, and other forensic indicators.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| threat_id | Yes | The threat ID to get forensics for | |
| includeCampaignForensics | No | Include forensics for the entire campaign (default: false) |