mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-09-16 21:05:22 +03:00
Initial commit - 611 cybersecurity skills across all subdomains
This commit is contained in:
@@ -0,0 +1,34 @@
|
||||
# Standards & References: Email Sandboxing with Proofpoint
|
||||
|
||||
## MITRE ATT&CK Coverage
|
||||
- **T1566.001**: Phishing: Spearphishing Attachment (primary detection)
|
||||
- **T1566.002**: Phishing: Spearphishing Link (URL Defense)
|
||||
- **T1204.001/002**: User Execution: Malicious Link/File
|
||||
- **T1059**: Command and Scripting Interpreter (macro detection)
|
||||
- **T1027**: Obfuscated Files or Information
|
||||
|
||||
## NIST Guidelines
|
||||
- **NIST SP 800-177**: Trustworthy Email - attachment security
|
||||
- **NIST SP 800-83 Rev.1**: Guide to Malware Incident Prevention
|
||||
- **NIST SP 800-53**: SI-3 Malicious Code Protection, SI-8 Spam Protection
|
||||
|
||||
## Proofpoint TAP API Endpoints
|
||||
| Endpoint | Description |
|
||||
|---|---|
|
||||
| `/v2/siem/all` | All threat events for SIEM |
|
||||
| `/v2/siem/messages/blocked` | Blocked message events |
|
||||
| `/v2/siem/messages/delivered` | Delivered message events with threats |
|
||||
| `/v2/siem/clicks/blocked` | Blocked URL click events |
|
||||
| `/v2/siem/clicks/permitted` | Permitted URL click events |
|
||||
| `/v2/people/vap` | Very Attacked People list |
|
||||
| `/v2/campaign/{id}` | Campaign details |
|
||||
|
||||
## Sandbox File Types
|
||||
| Category | Extensions | Action |
|
||||
|---|---|---|
|
||||
| Executables | .exe, .dll, .scr, .com | Detonate + Block |
|
||||
| Office docs | .doc(x/m), .xls(x/m), .ppt(x/m) | Detonate |
|
||||
| PDF | .pdf | Detonate |
|
||||
| Archives | .zip, .rar, .7z, .tar.gz | Extract + Detonate |
|
||||
| Scripts | .js, .vbs, .ps1, .bat, .cmd | Block |
|
||||
| Disk images | .iso, .img, .vhd | Detonate |
|
||||
@@ -0,0 +1,69 @@
|
||||
# Workflows: Email Sandboxing with Proofpoint
|
||||
|
||||
## Workflow 1: Attachment Detonation Pipeline
|
||||
```
|
||||
Email with attachment arrives at Proofpoint gateway
|
||||
|
|
||||
v
|
||||
[Pre-filter: Check attachment type]
|
||||
+-- Blocked types (.bat, .ps1, .vbs) --> Quarantine immediately
|
||||
+-- Detonable types --> Send to sandbox
|
||||
+-- Known safe types (.txt, .csv) --> Deliver
|
||||
|
|
||||
v
|
||||
[Sandbox detonation]
|
||||
+-- Execute in multiple environments (Win10, Win11, macOS)
|
||||
+-- Monitor: file system changes, registry, network, process creation
|
||||
+-- Timeout: 60-120 seconds per environment
|
||||
|
|
||||
v
|
||||
[Verdict]
|
||||
+-- MALICIOUS --> Quarantine, alert, extract IOCs
|
||||
+-- SUSPICIOUS --> Quarantine for analyst review
|
||||
+-- CLEAN --> Deliver with dynamic delivery
|
||||
```
|
||||
|
||||
## Workflow 2: URL Defense Time-of-Click
|
||||
```
|
||||
Email with URL arrives
|
||||
|
|
||||
v
|
||||
[URL rewritten to Proofpoint URL Defense proxy]
|
||||
|
|
||||
v
|
||||
[Email delivered to user]
|
||||
|
|
||||
v
|
||||
[User clicks rewritten URL]
|
||||
|
|
||||
v
|
||||
[Proofpoint performs real-time analysis]
|
||||
+-- Reputation check
|
||||
+-- Content analysis
|
||||
+-- Sandbox detonation of landing page
|
||||
|
|
||||
+-- SAFE --> Redirect to original URL
|
||||
+-- MALICIOUS --> Block access, show warning page
|
||||
+-- SUSPICIOUS --> Show interstitial warning, allow proceed
|
||||
```
|
||||
|
||||
## Workflow 3: TAP Dashboard Monitoring
|
||||
```
|
||||
Daily operations:
|
||||
+-- Review TAP Dashboard threat digest
|
||||
+-- Check VAP (Very Attacked People) changes
|
||||
+-- Review campaign clusters
|
||||
+-- Investigate quarantined messages
|
||||
+-- Monitor false positive rate
|
||||
|
|
||||
Weekly:
|
||||
+-- Analyze threat trends
|
||||
+-- Review sandboxing effectiveness
|
||||
+-- Tune policies based on FP/FN data
|
||||
+-- Update blocked file type list
|
||||
|
|
||||
Monthly:
|
||||
+-- Generate executive report from TAP
|
||||
+-- Review VAP list with HR/management
|
||||
+-- Assess ROI and threat prevention metrics
|
||||
```
|
||||
Reference in New Issue
Block a user