proofpoint_threat_get_iocs
Retrieve indicators of compromise (IOCs) such as URLs, IPs, domains, and file hashes for a specific campaign or time range to identify associated threats.
Instructions
Get indicators of compromise (IOCs) for a specific campaign or time range. Returns URLs, IPs, domains, file hashes associated with threats.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| interval | No | Predefined interval: "PT30M" or "PT1H" | |
| sinceTime | No | ISO 8601 date/time to fetch IOCs since | |
| campaign_id | No | Campaign ID to get IOCs for | |
| threat_type | No | Filter by threat type |