Sightings searches on user-reported phishing and malware attacks
Perform sightings searches on emails or observables to determine how often certain types of attacks, such as phishing attacks or communications with a malicious IP or URL occur in your network. Each occurrence is considered a sighting. Sightings searches for observables must be configured for your log stores or security information and event management (SIEM).
Watch this three-minute video to learn how to use the sighting search feature to locate phished users, and track phishing and malware observables within the log store on your network.
- Phished user: A user who has received a phishing email.
- Victim user: A user who has interacted with the phishing URL, typically by clicking a link in the phishing email. This action potentially exposes credentials to the attacker.
- Navigate to and click on a security incident.
- Click Show IoC under Related Links. A list of observables is displayed.
- Select an observable from the list and from the Actions list, select either of the following options:
- Run Web Traffic Sightings Search
- Run Email Traffic Sightings Search
- Specify the time frame and click Search to perform a sightings search.
Saved sighting search configurations
Perform an email sightings search for user-reported phishing attacks
Search for users who have received phishing emails based on observables such as email subject, sender name, or message ID. You can then contain and eradicate these phishing emails from your organization.
Before you begin
Role required: sn_si.analyst
About this task
- This implementation of sightings search for email-based observables has been tested only with the Splunk Enterprise log store.
- The Splunk log events must be Common Information Model (CIM) compliant for the sightings search query to return accurate results.
Procedure
Result
Perform an observable sightings search for user-reported phishing and malware attacks
Perform sightings searches on observables to find out how many users have visited a malicious or suspicious website within a specific period.
Before you begin
Role required: sn_si.analyst
About this task
- This implementation of sightings search for observables has been tested only with the Splunk Enterprise log store.
- The Splunk log events must be Common Information Model (CIM) compliant for the sightings search query to return accurate results.
Procedure
Result
Create sightings search configuration records
Create multiple sightings search configuration records and use them while querying multiple log stores or varying the search parameters.
Before you begin
Role required: sn_si.admin
- The CIM add-on must be installed on the Splunk instance.
- Saved Searches and Inplace queries are supported for Splunk Integration only.
About this task
- Create custom searches that combine multiple event records.
- Design-efficient and effective searches.
- Use parametrized inputs in the Splunk saved search.
The base system includes the sample configurations.
To verify if the saved search configuration matches the configuration defined on your Splunk instance:
- Navigate to .
- Change App Context to All.
A list of search reports is displayed.
- Confirm that the saved search query is present in the list.
In your Splunk instance, define the saved search with the same name, Default Saved Search - Emails, and the same search parameters for the email address and email subject. If the name and search parameters are not the same, sightings search does not generate accurate result.
Procedure
Result
What to do next
After defining the search query, select Generate Sightings Search Test Query, and specify a list of observable values to generate a test query based on this saved search configuration.