find-contact
Resolve a 3CX contact or extension by email, extension, or name
View recent TAP threat events including blocked messages, delivered threats, and click activity
$ npx -y skills add wyre-technology/msp-claude-plugins --agent claude-codeHow it fires
How this command gets triggered: by you, by Claude, or both.
/check-threatsContext preview
What this command does when you run it.
View recent TAP threat events including blocked messages, delivered threats, and click activity
description: View recent TAP threat events including blocked messages, delivered threats, and click activity argument-hint: "[window] [type] [classification] [status]" arguments: [window, type, classification, status]
View recent Proofpoint TAP threat events to monitor email security posture.
1. **Parse time window**
2. **Fetch threat events**
3. **Filter and aggregate results**
4. **Format and display**
| Parameter | Type | Required | Default | Description | |-----------|------|----------|---------|-------------| | window | string | No | 1h | Time window (1h, 6h, 12h, 24h) | | type | string | No | all | url/attachment/message/all | | classification | string | No | - | malware/phish/impostor/spam | | status | string | No | all | blocked/delivered/all |
/check-threats
/check-threats --window 24h --classification phish
/check-threats --window 6h --status delivered
/check-threats --window 12h --type attachment
/check-threats --window 1h --classification malware --status all
Proofpoint Threat Summary - Last 1 Hour Threats Blocked: 47 Threats Delivered: 2 [!] Clicks Blocked: 3 Clicks Permitted: 1 [!] By Classification: Phishing: 28 blocked, 1 delivered Malware: 12 blocked, 0 delivered Spam: 5 blocked, 1 delivered Impostor: 2 blocked, 0 delivered By Threat Type: URL: 31 Attachment: 14 Message: 4 ACTION REQUIRED: 2 threats delivered, 1 click permitted
DELIVERED THREATS (Requires Attention) 1. [PHISH] Invoice Payment Required Sender: billing@spoofed-domain.com Recipient: cfo@acmecorp.com Time: 2024-02-15 09:23:00 Threat: Credential harvesting URL Score: Phish: 92, Malware: 15 Campaign: TA505-Feb2024 Action: Consider search-and-destroy 2. [SPAM] Special Offer - Act Now Sender: promo@bulk-sender.com Recipient: sales@acmecorp.com Time: 2024-02-15 09:45:00 Threat: Spam with tracking pixels Score: Spam: 78, Phish: 12 Action: Low priority, monitor PERMITTED CLICKS 1. [PHISH] cfo@acmecorp.com clicked on credential harvester Click Time: 2024-02-15 09:35:00 URL: https://fake-login.evil.com/office365 Campaign: TA505-Feb2024 Action: URGENT - Initiate password reset
Proofpoint Threat Summary - Last 1 Hour No threats detected in the past hour. All clear - email security posture is healthy. Last threat detected: 2024-02-15 07:12:00 (2 hours ago)
Error: Invalid time window "48h" Maximum window is 24 hours (24h). Valid formats: 1h, 6h, 12h, 24h, or seconds (e.g., 3600)
Error: TAP API access not available Your Proofpoint license may not include TAP API access. Contact your Proofpoint administrator or account manager.
Rate limited by Proofpoint TAP API Current usage: 998/1000 requests per hour Retrying in 60 seconds...
One command to supercharge Claude Code for MSP workflows. Then restart Claude Code. That's it. Documentation: mcp.wyre.ai
Repo: wyre-technology/msp-claude-plugins
Resolve a 3CX contact or extension by email, extension, or name
Search for specific threat patterns in Abnormal Security by sender, recipient, attack type, or keywords
Triage recent email threats detected by Abnormal Security by severity and attack type