<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert to detect email spoofing - Sender address and reply to address different in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Alert-to-detect-email-spoofing-Sender-address-and-reply-to/m-p/425328#M173463</link>
    <description>&lt;P&gt;Im thinking a eval and if command might work&lt;BR /&gt;
To say if email field x is not the same as email field y then alert...any ideas ?&lt;/P&gt;

&lt;P&gt;Many thanks&lt;/P&gt;</description>
    <pubDate>Wed, 23 Jan 2019 12:30:02 GMT</pubDate>
    <dc:creator>DDewarSplunk</dc:creator>
    <dc:date>2019-01-23T12:30:02Z</dc:date>
    <item>
      <title>Alert to detect email spoofing - Sender address and reply to address different</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Alert-to-detect-email-spoofing-Sender-address-and-reply-to/m-p/425327#M173462</link>
      <description>&lt;P&gt;Morning Splunk Gurus's, I wonder if you can solve a question I have?&lt;/P&gt;

&lt;P&gt;If an email is sent to you and the senders email address has been spoofed, if you click reply the address changes to a fake email address. How do I monitor exchange logs to say if the "From" field in the email email is not the same as the "Return-path" field then alert  me ?&lt;/P&gt;

&lt;P&gt;X-Sender-Id - This is the real sender&lt;BR /&gt;
The "Reply To" header is presented to the end-user but the actual reply goes to a field called "Return-Path" &lt;BR /&gt;
Return Path: This field is what the mail server would use if the end-user chooses to reply to sender&lt;BR /&gt;
From: This is address from someone you know \ trust, the email address of the impersonated sender.&lt;/P&gt;

&lt;P&gt;I've been racking my brain trying to work this out, and would really appreciate any thoughts \ ideas you might have&lt;/P&gt;

&lt;P&gt;Cheers&lt;BR /&gt;
D&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2019 10:25:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Alert-to-detect-email-spoofing-Sender-address-and-reply-to/m-p/425327#M173462</guid>
      <dc:creator>DDewarSplunk</dc:creator>
      <dc:date>2019-01-23T10:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: Alert to detect email spoofing - Sender address and reply to address different</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Alert-to-detect-email-spoofing-Sender-address-and-reply-to/m-p/425328#M173463</link>
      <description>&lt;P&gt;Im thinking a eval and if command might work&lt;BR /&gt;
To say if email field x is not the same as email field y then alert...any ideas ?&lt;/P&gt;

&lt;P&gt;Many thanks&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2019 12:30:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Alert-to-detect-email-spoofing-Sender-address-and-reply-to/m-p/425328#M173463</guid>
      <dc:creator>DDewarSplunk</dc:creator>
      <dc:date>2019-01-23T12:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: Alert to detect email spoofing - Sender address and reply to address different</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Alert-to-detect-email-spoofing-Sender-address-and-reply-to/m-p/425329#M173464</link>
      <description>&lt;P&gt;I was wondering about this as well but want to add an exclusion list into it due to known emails that come in from certain teams that the return path is a team inbox so it will show as sent on behalf and replies go back to the team inbox so that any replies don't get dropped say when they are not at work.  Have you had any luck with what you were trying.,Trying to figure this one out myself but throw a curve ball at it as well because I know some emails come into my environment using a email sent on behalf.  So would have a listed of exclusions I would like to build into the alert.  Have you had any luck figuring this out.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Mar 2020 09:18:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Alert-to-detect-email-spoofing-Sender-address-and-reply-to/m-p/425329#M173464</guid>
      <dc:creator>davidc0805</dc:creator>
      <dc:date>2020-03-01T09:18:37Z</dc:date>
    </item>
    <item>
      <title>Re: Alert to detect email spoofing - Sender address and reply to address different</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Alert-to-detect-email-spoofing-Sender-address-and-reply-to/m-p/425330#M173465</link>
      <description>&lt;P&gt;If you can find that information in the log, you can fix it.&lt;BR /&gt;
In Smtp protocol, there is only sender and recipient.&lt;/P&gt;

&lt;P&gt;the others is all &lt;CODE&gt;data&lt;/CODE&gt;. &lt;/P&gt;

&lt;P&gt;if you can see &lt;CODE&gt;Reply To&lt;/CODE&gt;, you can detect email spoofing.&lt;BR /&gt;
that's great.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Mar 2020 10:26:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Alert-to-detect-email-spoofing-Sender-address-and-reply-to/m-p/425330#M173465</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-03-01T10:26:05Z</dc:date>
    </item>
  </channel>
</rss>

