Splunk Enterprise Security

How can we monitor if a user clicked on a phishing link or button in an email?

Sasquatchatmars
Communicator

Hi everybody,

We have a stream forwarder which sends every mail that enters in an index. It contains everything from the mail. I want to know if it is possible to see if the receiver of the mail opened the link that is in the mail or in the button?

Thank you,

Sasquatchatmars

 

Labels (1)
0 Karma

lakshman239
Influencer

If you have web proxy logs, you can see the urls clicked by the user. You can then link the phishing url/user in proxy logs with the email events to understand how many users have clicked the malicious link

0 Karma

Sasquatchatmars
Communicator

Hi @lakshman239,

Thank you for your reply, can you tell me what the search would look like? 

Thank you,

Sasquatchatmars

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Apart from the emails, what other data do you have in splunk?

0 Karma

Sasquatchatmars
Communicator

Hi thanks for your reply,

I have the security logs of every domain controller. But if it needs other logs we can maybe put in a request to forward them. But in order to do that I need to know what exactly and then know how to search for it. 

Thank you,

Sasquatchatmars

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...