Splunk Enterprise Security

How can we monitor if a user clicked on a phishing link or button in an email?

Sasquatchatmars
Communicator

Hi everybody,

We have a stream forwarder which sends every mail that enters in an index. It contains everything from the mail. I want to know if it is possible to see if the receiver of the mail opened the link that is in the mail or in the button?

Thank you,

Sasquatchatmars

 

Labels (1)
0 Karma

lakshman239
SplunkTrust
SplunkTrust

If you have web proxy logs, you can see the urls clicked by the user. You can then link the phishing url/user in proxy logs with the email events to understand how many users have clicked the malicious link

0 Karma

Sasquatchatmars
Communicator

Hi @lakshman239,

Thank you for your reply, can you tell me what the search would look like? 

Thank you,

Sasquatchatmars

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Apart from the emails, what other data do you have in splunk?

0 Karma

Sasquatchatmars
Communicator

Hi thanks for your reply,

I have the security logs of every domain controller. But if it needs other logs we can maybe put in a request to forward them. But in order to do that I need to know what exactly and then know how to search for it. 

Thank you,

Sasquatchatmars

0 Karma
Get Updates on the Splunk Community!

Synthetic Monitoring: Not your Grandma’s Polyester! Tech Talk: DevOps Edition

Register today and join TekStream on Tuesday, February 28 at 11am PT/2pm ET for a demonstration of Splunk ...

Instrumenting Java Websocket Messaging

Instrumenting Java Websocket MessagingThis article is a code-based discussion of passing OpenTelemetry trace ...

Announcing General Availability of Splunk Incident Intelligence!

Digital transformation is real! Across industries, companies big and small are going through rapid digital ...