Email Security layer: Proofpoint, M365, and correlated phish
Email remains the dominant ingress path. Dual-Strike XISEM Email Security integrations pull message-level and tenant-level signals from Proofpoint, Microsoft 365 Defender for Office, and related paths (see Integrations wiki) into the same correlation graph as agents and identity.
Route: Threat Center · Asset/identity timelines
Signals that matter for correlation
• Blocked phish — User clicked anyway? Check browsing + sign-in
• Impossible travel + mail rule — BEC pattern for COBRA²
• New forward rule — Exfil precursor — pair with DLP/browsing
• Campaign prevalence — Which clients share same IOC set
Investigation pattern: “User reported phish”
1. Email integration shows message ID and verdict
2. Identity timeline shows sign-in from same user 10 min later
3. Browsing Insights shows OAuth grant to unknown SaaS
4. COBRA² BEC / shadow IT rule fires → Threat Center
5. PSA ticket with all three pivots in body
Without correlation, tier 1 resets password and closes — missing the OAuth grant.
Enablement order
1. M365 GDAP or Proofpoint API (per client)
2. Validate events in console within 24h
3. Enable email-adjacent COBRA rules in learning mode
4. Document client runbook in Investigations template
Not an SEG replacement
Keep Proofpoint or M365 ATP as the mail gateway. Dual-Strike XISEM interprets their evidence alongside everything else — compliance, CA intel, PSA.
Docs: Integrations → Proofpoint email · Microsoft 365
Message content bodies are not stored for operator browsing — metadata and verdicts only.


