Overview
Nuclei Agents analyze data that is already being captured by Nuclei and identify findings based on the Agent type and configuration you choose. If you want flagged findings delivered to Proofpoint ITM, you must also configure a separate Proofpoint ITM Channel and connect that Channel to the Agent.
There are two distinct connections involved in this setup:
- A Source-to-Agent connection determines which Nuclei data sources the Agent will analyze
- An Agent-to-Channel connection determines where flagged Agent findings will be delivered
A Source connection alone does not send findings to Proofpoint ITM. A Channel connection alone does not cause an Agent to analyze data.
Prerequisites
- At least one Nuclei Source is already configured and syncing under
Configuration > Sources - Access to
Configuration > Agents,Configuration > Channels, and connection settings - A defined Agent use case such as Insider Threat Matrix, AI Governance, Regulatory Compliance, or a Custom Agent
- Proofpoint ITM connectivity has been provisioned for your Nuclei tenant
If Proofpoint ITM has not yet been enabled for your tenant, please contact Nuclei before creating the Channel.
TLDR
- Create and configure the Agent
- Make sure
Enabled By Defaultis turned on for the Agent - Create the Source you want the Agent to analyze
- Create the Proofpoint ITM Channel
- Connect the Agent to the Proofpoint ITM Channel
- Validate that flagged Agent findings are appearing in Proofpoint ITM
Getting Setup
1. Create the Agent
- Go to
Configuration > Agents - Select
New - Choose the Agent Type that matches your use case
- Enter a Description
- Turn
Enabled By Defaulton - Complete the Agent-specific configuration
- Select
Create Agent
Common examples include:
Insider Threat Matrixfor motive-based insider risk detectionAI Governancefor risky or non-compliant GenAI usageRegulatory Compliance Agent - Financial Servicesfor configurable surveillance use casesCustom Agentfor customer-defined review criteria
Depending on the Agent Type, you may be asked to configure items such as:
- Additional Instructions
- Approved Communication Tools
- Banned Communication Tools
- Approved GenAI Tools
- Banned GenAI Tools
- Specific rule groups, motives, or policy categories
Turning Enabled By Default on ensures that Sources created afterward will automatically connect to this Agent.
2. Create the Source
- Go to
Configuration > Sources - Select
New - Configure the Source you want the Agent to analyze
- Complete any required authorization or onboarding steps for that Source
- Save the Source
Because the Agent was created first and is Enabled By Default, the Source will automatically connect to it.
Agents do not collect data directly. They analyze data from connected Nuclei Sources.
3. Create the Proofpoint ITM Channel
- Go to
Configuration > Channels - Select
New - Choose
Proofpoint ITM - Enter a Description
- Set
Enabled By Defaultbased on whether new Agent connections should start active - Select
Create Channel
The Proofpoint ITM Channel does not require additional customer-entered configuration fields in the Nuclei UI.
4. Connect the Agent to the Proofpoint ITM Channel
- Open the Agent, or open the Proofpoint ITM Channel
- In
Connected ChannelsorConnected Agents, selectCreate New Channel ConnectionorCreate New Agent Connection - Choose the Agent and the
Proofpoint ITMChannel - Confirm
Agent Channel Connectionis enabled - Save the connection
This connection controls where flagged Agent findings will be delivered.
Usage
Once setup is complete:
- Nuclei Sources acquire data into the platform
- The connected Agent analyzes data from the Sources automatically connected to it
- Only flagged Agent findings are forwarded through the Proofpoint ITM Channel
- The same Proofpoint ITM Channel can be connected to multiple Agents as needed
If you need to tune detection behavior later, update the Agent configuration rather than the Channel connection.
Validation
- Allow time for the connected Source to sync and for the Agent to run
- Review the Agent and confirm the new Source appears under
Connected Sources - Confirm flagged findings are being generated
- Confirm those flagged findings are appearing in Proofpoint ITM
If no findings are appearing in Proofpoint ITM, confirm all three layers are in place:
- The Source is enabled and syncing
- The Source is connected to the Agent
- The Agent is connected to the Proofpoint ITM Channel
Uninstallation
- Remove the Agent-to-Channel connection if you want to stop sending findings to Proofpoint ITM
- Disable or remove the Source if you want the Agent to stop analyzing that Source
- Disable or delete the Agent or Channel if they are no longer needed
More Information
If you need help enabling Proofpoint ITM for your tenant or validating end-to-end delivery, please contact Nuclei Support or your Nuclei account team.
Comments
0 comments
Article is closed for comments.