Automate Email Threat Response and Quarantine Management.
Proofpoint catches threats. Kognitos automates what happens next, quarantine review, user notification, and incident documentation without manual SOC intervention.
Describe It in English.
It Runs Deterministically.
Overview
Pull quarantined messages from Proofpoint Essentials, analyze threat indicators, auto-release false positives matching safe-sender policies, and escalate confirmed threats with a forensic summary.
Execution Steps
Review Quarantine Queue
- Pull all messages quarantined by Proofpoint in the past 24 hours
- Classify each by threat type: phishing, malware, spam, or impersonation
Apply Release Policies
- Check quarantined messages against the approved safe-sender and domain allowlist
- Auto-release messages matching the allowlist and log the release decision
Escalate Confirmed Threats
- For confirmed phishing or malware, extract IOCs (URLs, hashes, sender domains)
- Create a security incident with the forensic summary and notify the SOC team
Enterprise
Use Cases
Automated Quarantine Triage
Review and classify quarantined emails automatically, release safe messages and escalate real threats without SOC analyst intervention.
Phishing Forensics
Extract indicators of compromise from Proofpoint-flagged messages and cross-reference against threat intelligence feeds.
User Notification Automation
Notify users when their quarantined messages are released or confirmed malicious, with clear guidance on next steps.
Frequently asked
questions.
Kognitos is a leading US-based artificial intelligence platform designed to transform how businesses operate by automating repetitive tasks and enhancing efficiency. Our AI automation platform allows users to automate complex business processes simply by communicating their goals in plain English. Leveraging advanced technologies like a proprietary LLM-based interpreter, Intelligent Document Processing (IDP), Optical Character Recognition (OCR), and Natural Language Processing (NLP), Kognitos enhances productivity, speed, and accuracy. Unlike traditional automation solutions that require complex coding, Kognitos offers unparalleled adaptability and scalability, empowering businesses to streamline workflows and eliminate manual tasks without extensive technical knowledge.
Process automation refers to the use of technology to automate repetitive, manual tasks within a business or organization. The goal is to streamline and optimize workflows, increase efficiency, reduce errors, and save time and resources. This can be achieved through the implementation of various technologies, such as RPA, Workflow Automation, Machine Learning and Artificial Intelligence.
Security is a core principle of Kognitos' architecture, built on state-of-the-art cloud services with strong security foundations. Critical business processes run on the Kognitos platform, and we prioritize the security of both the processes and their data. Kognitos employs serverless, cloud-based services with the principle of least privilege access. For example, a service without a need to access a database does not have access to it. Kognitos has achieved the SOC 2 Type II certification for our best-in-class security controls and compliance with the AICPA's Trust Services Criteria. Learn more
Related
Integrations
Proofpoint Essentials automation questions.
What can I automate between Kognitos and Proofpoint Essentials?
Inbound message triage, structured-data extraction from message bodies and attachments, response drafting with deterministic policy enforcement, and audit-trail writeback. Kognitos reads from Proofpoint Essentials, applies the policy you wrote in plain English, and writes back deterministically with a full audit trail, no probabilistic LLM action.
How does Kognitos connect to Proofpoint Essentials?
Through Proofpoint Essentials's official API using scoped credentials (OAuth or API key, depending on which Proofpoint Essentials supports). Kognitos stores credentials in a managed secret store with rotation; permissions are limited to what your automation actually needs.
What events in Proofpoint Essentials can trigger a Kognitos automation?
Common triggers include an inbound email or message, a thread update, a webhook from the messaging provider, or a scheduled sweep. Kognitos supports both event-driven (webhook) and scheduled execution, and you can mix both inside a single automation.
Can business users build Kognitos + Proofpoint Essentials automations without code?
Yes. The Kognitos Builder Agent walks you through the process in conversation; you describe what you want in English (e.g., "every weeknight, reconcile Proofpoint Essentials records against the warehouse and email me anything that doesn't match") and Kognitos generates and runs the automation. No drag-and-drop, no Python, and no third-party iPaaS.
Is Proofpoint Essentials data safe with Kognitos?
Yes. Kognitos is SOC 2 Type II, HIPAA-attested, ISO 27001-certified, and GDPR-aligned. Proofpoint Essentials data is processed inside the customer tenant, encrypted in transit and at rest, never used to train upstream models, and every decision is captured in an immutable English-language audit log.
How do I get started with the Kognitos + Proofpoint Essentials integration?
Book a 30-minute demo. We'll help you connect Proofpoint Essentials, pick a real bottleneck from your team's backlog, and ship a working automation written in plain English in the first session, no procurement runway required.





