api-patterns
3CX's native PBX MCP server: the per-PBX endpoint shape (every PBX is its own FQDN and its own OAuth authorization server — there is no shared mcp.3cx.com),…
Proofpoint Targeted Attack Protection (TAP) fundamentals: threat events across URL, attachment, and message-level vectors, click tracking, message disposition, SIEM integration feeds, and campaign correlation.
$ npx -y skills add wyre-technology/msp-claude-plugins --skill tap --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/tapContext preview
The summary Claude sees to decide when to auto-load this skill.
Proofpoint Targeted Attack Protection (TAP) fundamentals: threat events across URL, attachment, and message-level vectors, click tracking, message disposition, SIEM integration feeds, and campaign correlation.
name: "Proofpoint TAP" description: > Proofpoint Targeted Attack Protection (TAP) fundamentals: threat events across URL, attachment, and message-level vectors, click tracking, message disposition, SIEM integration feeds, and campaign correlation. when_to_use: >- When retrieving TAP threat events, click activity, message delivery/blocking data, or SIEM feeds. Use when: proofpoint tap, targeted attack protection, proofpoint threats, email threats, tap events, proofpoint clicks, click tracking, proofpoint messages, message blocked, message delivered, proofpoint siem, tap api, threat events, proofpoint malware, or proofpoint phishing.
Proofpoint TAP is the core threat detection engine in the Proofpoint email security stack. It analyzes email messages, URLs, and attachments in real time using sandboxing, behavioral analysis, and threat intelligence. The TAP SIEM API provides programmatic access to all threat events, click activity, and message disposition data.
TAP identifies three primary threat vectors:
24 hours and it answers an out-of-range window with an empty result, not an error. "Did we see this last week?" needs `proofpoint-forensics` for a specific message or `proofpoint-threat-intel` for a campaign.
delete are `proofpoint-quarantine`; removing delivered mail is `proofpoint-forensics`.
per-user rollup, Attack Index, and VAP list are `proofpoint-people`.
`avanan-threats`, Abnormal is `abnormal-security-threats`, and Mimecast message-level delivery tracking is `mimecast-message-tracking`.
Defense rewriting, click verdicts, and decoding a `urldefense.proofpoint.com` target are `proofpoint-url-defense`; TAP reports the click event without explaining the rewrite.
| Classification | Description | Typical Action | |---------------|-------------|----------------| | `malware` | Known or sandboxed malware payload | Block and quarantine | | `phish` | Credential harvesting or phishing | Block and quarantine | | `spam` | Unsolicited bulk email | Quarantine or tag | | `impostor` | Business Email Compromise (BEC) | Quarantine or warn |
| Disposition | Description | |-------------|-------------| | `allowed` | Message was delivered to the recipient | | `blocked` | Message was blocked before delivery | | `quarantined` | Message was placed in quarantine |
| Verdict | Description | |---------|-------------| | `permitted` | Click was allowed (URL was clean at time of click) | | `blocked` | Click was blocked (URL was malicious at time of click) |
TAP SIEM API supports relative and absolute time windows:
| Parameter | Format | Example | Max Window | |-----------|--------|---------|------------| | `sinceSeconds` | Integer (seconds) | `3600` (1 hour) | 86400 (24 hours) | | `sinceTime` | ISO 8601 | `2024-02-15T00:00:00Z` | 24 hours from now | | `interval` | ISO 8601 duration | `PT1H` (1 hour) | 1 hour |
**Important:** The maximum lookback window is 24 hours. For historical data beyond 24 hours, use the forensics or campaign APIs instead.
| Field | Type | Description | |-------|------|-------------| | `GUID` | string | Unique message identifier | | `QID` | string | Queue ID from the mail server | | `sender` | string | Envelope sender address | | `recipient` | string[] | List of recipient addresses | | `subject` | string | Message subject line | | `messageTime` | datetime | When the message was processed | | `threatsInfoMap` | object[] | Array of threat details | | `malwareScore` | int | 0-100 malware confidence score | | `phishScore` | int | 0-100 phishing confidence score | | `spamScore` | int | 0-100 spam confidence score | | `impostorScore` | int | 0-100 impostor/BEC confidence score | | `cluster` | string | Proofpoint cluster that processed the message | | `messageParts` | object[] | Breakdown of message MIME parts | | `completelyRewritten` | boolean | Whether all URLs were rewritten by URL Defense | | `policyRoutes` | string[] | Policy rules that matched |
| Field | Type | Description | |-------|------|-------------| | `threat` | string | The threat indicator (URL, hash, etc.) | | `threatID` | string | Unique threat identifier | | `threatStatus` | string | `active`, `cleared`, `falsePositive` | | `threatTime` | datetime | When the threat was first identified | | `threatType` | string | `url`, `attachment`, `messageText` | | `classification` | string | `malware`, `phish`, `spam`, `impostor` | | `threatUrl` | string | URL to threat detail in TAP dashboard |
| Field | Type | Description | |-------|------|-------------| | `campaignId` | string | Associated campaign identifier | | `clickIP` | string | IP address of the clicker | | `clickTime` | datetime | When the click occurred | | `GUID` | string | Message GUID containing the URL | | `recipient` | string | Who clicked | | `sender` | string | Who sent the message | | `threatID` | string | Threat identifier for the URL | | `threatTime` | datetime | When URL was classified as threat | | `threatURL` | string | The malicious URL that was clicked | | `url` | string | The original URL before rewrite | | `userAgent` | string | Browser user agent of the clicker | | `classification` | st
One command to supercharge Claude Code for MSP workflows. Then restart Claude Code. That's it. Documentation: mcp.wyre.ai
Repo: wyre-technology/msp-claude-plugins
3CX's native PBX MCP server: the per-PBX endpoint shape (every PBX is its own FQDN and its own OAuth authorization server — there is no shared mcp.3cx.com),…
3CX's live-operations surface: read-only visibility into active calls, recordings, voicemail, department and queue membership, and forwarding/presence…
3CX's read-only directory surface: resolving a caller by email or by exact extension, searching the PBX's own phonebooks, searching contacts synced from an…
3CX's system-and-configuration surface: server time, PBX event log and application log search, service status, database schema and the read-only SELECT-only…
Abnormal Security abuse mailbox cases: user-reported email submissions, case statuses and judgments, the case lifecycle, bulk and remediation actions, and…
Abnormal Security message analysis: message retrieval, email header inspection, attachments, sender reputation, delivery context, and SPF/DKIM/DMARC…