Splunk Enterprise Security

How can we monitor if a user clicked on a phishing link or button in an email?

Sasquatchatmars
Communicator

Hi everybody,

We have a stream forwarder which sends every mail that enters in an index. It contains everything from the mail. I want to know if it is possible to see if the receiver of the mail opened the link that is in the mail or in the button?

Thank you,

Sasquatchatmars

 

0 Karma

lakshman239
Influencer

If you have web proxy logs, you can see the urls clicked by the user. You can then link the phishing url/user in proxy logs with the email events to understand how many users have clicked the malicious link

0 Karma

Sasquatchatmars
Communicator

Hi @lakshman239,

Thank you for your reply, can you tell me what the search would look like? 

Thank you,

Sasquatchatmars

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Apart from the emails, what other data do you have in splunk?

0 Karma

Sasquatchatmars
Communicator

Hi thanks for your reply,

I have the security logs of every domain controller. But if it needs other logs we can maybe put in a request to forward them. But in order to do that I need to know what exactly and then know how to search for it. 

Thank you,

Sasquatchatmars

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...