Splunk Enterprise Security

How can we monitor if a user clicked on a phishing link or button in an email?

Sasquatchatmars
Communicator

Hi everybody,

We have a stream forwarder which sends every mail that enters in an index. It contains everything from the mail. I want to know if it is possible to see if the receiver of the mail opened the link that is in the mail or in the button?

Thank you,

Sasquatchatmars

 

0 Karma

lakshman239
Influencer

If you have web proxy logs, you can see the urls clicked by the user. You can then link the phishing url/user in proxy logs with the email events to understand how many users have clicked the malicious link

0 Karma

Sasquatchatmars
Communicator

Hi @lakshman239,

Thank you for your reply, can you tell me what the search would look like? 

Thank you,

Sasquatchatmars

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Apart from the emails, what other data do you have in splunk?

0 Karma

Sasquatchatmars
Communicator

Hi thanks for your reply,

I have the security logs of every domain controller. But if it needs other logs we can maybe put in a request to forward them. But in order to do that I need to know what exactly and then know how to search for it. 

Thank you,

Sasquatchatmars

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...