Agent skill

Implementing Proofpoint Email Security Gateway

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Deploy and configure Proofpoint Email Protection as a secure email gateway to detect and block phishing, malware, BEC, and spam before messages reach user inboxes.

Apache-2.0Auto-check passedSecurity

Install Implementing Proofpoint Email Security Gateway

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-proofpoint-email-security-gateway -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-proofpoint-email-security-gateway --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-proofpoint-email-security-gateway .claude/skills/implementing-proofpoint-email-security-gateway && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-proofpoint-email-security-gateway
GitHub stars
34k
Token cost
~1.8k tokens
SKILL.md length
718 words
Files
8 (incl. scripts, references, assets)
Skills in repo
637
Repo updated
First seen
Licence
Apache-2.0

At a glance

Deploy and configure Proofpoint Email Protection as a secure email gateway to detect and block phishing, malware, BEC, and spam before messages reach user inboxes.

  • Works in 6 steps: Plan Mail Flow Architecture → Configure Proofpoint Policies → Deploy Email Authentication → …
  • Tasks that involve Email management
  • SKILL.md covers Overview, When to Use, Prerequisites and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Implementing Proofpoint Email Security Gateway is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Deploy and configure Proofpoint Email Protection as a secure email gateway to detect and block phishing, malware, BEC, and spam before messages reach user inboxes.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Security, covering Email management. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Email management

Example prompts

  • “/implementing-proofpoint-email-security-gateway”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Plan Mail Flow Architecture
  2. Configure Proofpoint Policies
  3. Deploy Email Authentication
  4. Enable Advanced Threat Protection
  5. Migrate MX Records
  6. Tune and Optimize

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Proofpoint Email Security Gateway loads about 1.8k tokens when it runs, and up to ~4.2k if it reads all its reference files. Until then it costs about 53 tokens; SKILL.md has 718 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 718 words, ~1,778 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-proofpoint-email-security-gateway/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
implementing-proofpoint-email-security-gateway
description
Deploy and configure Proofpoint Email Protection as a secure email gateway to detect and block phishing, malware, BEC, and spam before messages reach user inboxes.
domain
cybersecurity
subdomain
phishing-defense
tags
email-security, proofpoint, secure-email-gateway, phishing, anti-spam, anti-malware, bec, email-filtering
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.AT-01, DE.CM-09, RS.CO-02, DE.AE-02
mitre_attack
T1566, T1598, T1534, T1036, T1027
mitre_f3.version
1.1
mitre_f3.tactics
reconnaissance, initial-access, stealth, positioning

Implementing Proofpoint Email Security Gateway

Overview

Proofpoint Email Protection is a cloud-native secure email gateway (SEG) that acts as a security checkpoint where all inbound and outbound mail traffic routes through the gateway before reaching user inboxes. It combines signature-based detection for known malware, machine learning algorithms for emerging threats, real-time threat intelligence feeds, URL rewriting with time-of-click sandboxing, and behavioral analysis for BEC detection. Proofpoint processes over 2.8 billion emails daily and blocks over 1 million extortion attempts per day.

When to Use

  • When deploying or configuring implementing proofpoint email security gateway capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Proofpoint Email Protection license (PPS on-premises or Proofpoint on Demand cloud)
  • Administrative access to DNS management for MX record changes
  • Microsoft 365 or Google Workspace email environment
  • Understanding of mail flow architecture and SPF/DKIM/DMARC
  • Network firewall rules permitting Proofpoint IP ranges

Key Concepts

Deployment Models
  1. MX-Based Gateway (Traditional SEG): All mail routes through Proofpoint via MX record changes; intercepts threats before delivery
  2. API-Based Integration: Connects directly to Microsoft 365 or Google Workspace via API; no MX changes required; can be operational within 48 hours
  3. Hybrid Deployment: Combines gateway and API for layered protection
Core Detection Technologies
  • Impostor Classifier: ML model detecting BEC/impersonation with no malicious URLs or attachments
  • URL Defense: Rewrites URLs and performs real-time sandboxing at time of click
  • Attachment Defense: Sandboxes suspicious attachments in virtual environments
  • Nexus Threat Graph: Cross-customer threat intelligence correlation engine
  • Supplier Threat Detection: Identifies compromised vendor email accounts
Protection Layers
LayerTechnologyThreat Type
ConnectionIP reputation, rate limitingSpam botnets
AuthenticationSPF, DKIM, DMARC enforcementSpoofing
ContentML classifiers, NLP analysisBEC, phishing
URLRewriting + time-of-click sandboxCredential theft
AttachmentStatic + dynamic sandboxingMalware, ransomware
Post-deliveryTRAP (auto-retraction)Weaponized after delivery

Workflow

Step 1: Plan Mail Flow Architecture
  • Document current MX records and mail flow path
  • Identify all legitimate sending sources (marketing platforms, CRM, ticketing systems)
  • Map inbound connectors and transport rules in Microsoft 365 or Google Workspace
  • Plan IP allowlisting for Proofpoint egress IPs on receiving infrastructure
  • Configure SPF record to include Proofpoint: v=spf1 include:spf.protection.outlook.com include:spf-a.proofpoint.com -all
Step 2: Configure Proofpoint Policies
  • Create organizational units matching business structure
  • Define inbound mail policies: anti-spam, anti-virus, impostor detection
  • Configure Smart Search quarantine with end-user digest notifications
  • Set up Proofpoint Encryption for sensitive outbound messages
  • Enable Targeted Attack Protection (TAP) for URL and attachment sandboxing
Show full SKILL.md (302 more words)Show less
Step 3: Deploy Email Authentication
  • Configure DKIM signing through Proofpoint for outbound messages
  • Set DMARC policy to monitor mode initially: v=DMARC1; p=none; rua=mailto:dmarc@company.com
  • Enable inbound DMARC enforcement to reject spoofed messages
  • Configure anti-spoofing rules for executive impersonation protection
Step 4: Enable Advanced Threat Protection
  • Activate URL Defense with rewriting enabled for all inbound messages
  • Configure Attachment Defense sandbox policies (safe attachment mode)
  • Enable Threat Response Auto-Pull (TRAP) for post-delivery remediation
  • Set up TAP Dashboard alerts for targeted attack campaigns
  • Configure Supplier Risk monitoring for vendor email compromise
Step 5: Migrate MX Records
  • Lower MX record TTL to 300 seconds 48 hours before cutover
  • Update MX records to point to Proofpoint: company-com.mail.protection.proofpoint.com
  • Configure connector restrictions in Microsoft 365 to accept mail only from Proofpoint IPs
  • Monitor mail flow through Proofpoint Message Trace for 48-72 hours
  • Verify no legitimate mail is being blocked or delayed
Step 6: Tune and Optimize
  • Review quarantine and false positive/negative rates weekly for first month
  • Adjust spam thresholds based on organizational tolerance
  • Add approved senders and safe lists for legitimate bulk mail
  • Configure data loss prevention (DLP) rules for outbound sensitive content
  • Enable email warning banners for external sender identification

Tools & Resources

  • Proofpoint TAP Dashboard: Real-time threat visibility and campaign tracking
  • Proofpoint TRAP: Automated post-delivery email retraction
  • Proofpoint SER (Spam/End-user Release): Self-service quarantine management
  • Proofpoint Closed-Loop Email Analysis (CLEAR): Phishing report button integration
  • MX Toolbox: DNS record verification and mail flow testing

Validation

  • All inbound email routes through Proofpoint (verify MX records and message headers)
  • TAP Dashboard shows threat detections and blocked campaigns
  • URL Defense rewrites links in test messages and sandboxes at click time
  • Attachment Defense detonates test malware samples in sandbox
  • TRAP successfully retracts test phishing message from inboxes post-delivery
  • False positive rate below 0.1% after initial tuning period
  • DMARC/SPF/DKIM authentication passes for all legitimate outbound mail

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/implementing-proofpoint-email-security-gateway of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing Proofpoint Email Security Gateway next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Proofpoint Email Security Gateway compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Proofpoint Email Security Gateway this skillmukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.0
Working With ScoutsPostHog/posthog40k—~8.7kAutomated safety check: PassCustom licence
Wakewire Setuphashgraph-online/awesome-codex-plugins1.2k—~1.4kAutomated safety check: PassApache-2.0
Agent Email Inboxviclafouch/meme-studio1102 repos~10kAutomated safety check: WarnNone
Google Workspace CLIalirezarezvani/claude-skills28k—~3kAutomated safety check: NotesMIT
Deliverability Incident Responsegrowthenginenowoslawski/coldoutboundskills742—~3.5kAutomated safety check: PassMIT

Similar skills

  • Working With Scouts

    PostHog/posthog

    Official

    Work with PostHog Signals scouts: scheduled agents that monitor a project and write reports into the Signals inbox.

    40k GitHub stars~8.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Wakewire Setup

    hashgraph-online/awesome-codex-plugins

    Set up wakewire end to end — install/start the local daemon, wire a first GitHub or Gmail route into a Codex thread, and verify with a test delivery.

    1.2k GitHub stars~1.4k tokensUpdated yesterday
    Productivity & AutomationAuto-check passed
  • Agent Email Inbox

    viclafouch/meme-studio

    A skill your agent uses when setting up an email inbox for an AI agent (Moltbot, Clawdbot, or similar) - configuring inbound email, webhooks, tunneling for local development, and implementing…

    110 GitHub starsUsed in 2 repos~10k tokens
    Backend & APIsAuto-check: warnings
  • Google Workspace CLI

    alirezarezvani/claude-skills

    Google Workspace administration via the gws CLI (github.com/googleworkspace/cli).

    28k GitHub stars~3k tokensUpdated 1 mo ago
    Documents & OfficeAuto-check: notes
  • Deliverability Incident Response

    growthenginenowoslawski/coldoutboundskills

    Triage playbook for when cold email deliverability breaks. An agent skill from growthenginenowoslawski/coldoutboundskills.

    742 GitHub stars~3.5k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Openclaw Docker Setup

    LeoYeAI/openclaw-master-skills

    Install and configure a fully operational Dockerized OpenClaw instance on macOS from scratch.

    2.2k GitHub stars~4.7k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 637 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Implementing Proofpoint Email Security Gateway

What does Implementing Proofpoint Email Security Gateway do?

Deploy and configure Proofpoint Email Protection as a secure email gateway to detect and block phishing, malware, BEC, and spam before messages reach user inboxes. Implementing Proofpoint Email Security Gateway is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Deploy and configure Proofpoint Email Protection as a secure email gateway to detect and block phishing, malware, BEC, and spam before messages reach user inboxes.

When should I use Implementing Proofpoint Email Security Gateway?

Implementing Proofpoint Email Security Gateway fits situations like: tasks that involve Email management.

How do I install Implementing Proofpoint Email Security Gateway in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-proofpoint-email-security-gateway -a claude-code`. Or copy the skill folder (skills/implementing-proofpoint-email-security-gateway in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-proofpoint-email-security-gateway in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Proofpoint Email Security Gateway in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-proofpoint-email-security-gateway -a codex`. Or copy the skill folder (skills/implementing-proofpoint-email-security-gateway in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-proofpoint-email-security-gateway in your project. Codex loads it when a task matches its description.

Can I use Implementing Proofpoint Email Security Gateway in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-proofpoint-email-security-gateway -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-proofpoint-email-security-gateway, .gemini/skills/implementing-proofpoint-email-security-gateway, .github/skills/implementing-proofpoint-email-security-gateway and .opencode/skills/implementing-proofpoint-email-security-gateway in your project.

What does Implementing Proofpoint Email Security Gateway need to run?

Going by SKILL.md and its folder, Implementing Proofpoint Email Security Gateway needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Implementing Proofpoint Email Security Gateway access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Implementing Proofpoint Email Security Gateway safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Proofpoint Email Security Gateway use?

Implementing Proofpoint Email Security Gateway is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Proofpoint Email Security Gateway use?

About 1.8k tokens (SKILL.md is roughly 7.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.

What are the alternatives to Implementing Proofpoint Email Security Gateway?

Skills that share tags, products or a category with Implementing Proofpoint Email Security Gateway: Working With Scouts (PostHog/posthog, 40k stars), Wakewire Setup (hashgraph-online/awesome-codex-plugins, 1.2k stars), Agent Email Inbox (viclafouch/meme-studio, 110 stars) and Google Workspace CLI (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Proofpoint Email Security Gateway?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,922 GitHub stars. The repository holds 637 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.