Hi everybody,
We have a stream forwarder which sends every mail that enters in an index. It contains everything from the mail. I want to know if it is possible to see if the receiver of the mail opened the link that is in the mail or in the button?
Thank you,
Sasquatchatmars
If you have web proxy logs, you can see the urls clicked by the user. You can then link the phishing url/user in proxy logs with the email events to understand how many users have clicked the malicious link
Hi @lakshman239,
Thank you for your reply, can you tell me what the search would look like?
Thank you,
Sasquatchatmars
Apart from the emails, what other data do you have in splunk?
Hi thanks for your reply,
I have the security logs of every domain controller. But if it needs other logs we can maybe put in a request to forward them. But in order to do that I need to know what exactly and then know how to search for it.
Thank you,
Sasquatchatmars