Forcepoint Security Service Edge high volume of emails from a sender
Set up the forcepoint-security-service-edge integration.
Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel,
n'hésitez pas à nous contacter.
Goal
Identify and respond to incidents where a high volume of emails are sent from a single sender, which may indicate spam activity, compromised accounts, or policy violations.
Strategy
Monitor Forcepoint SSE logs for high email volumes from individual senders.
Triage and Response
- Review the log details to identify the sender -
{{@emailfrom}}
responsible for the high email volume. - Confirm whether the sender is an internal user, an authorized external contact, or an unknown entity and also check for any recent changes to the sender’s account, such as password resets or suspicious login locations.
- Analyze the content and recipients of the emails to determine if they align with normal business activity.
- Cross-check the sender’s recent activity logs for other anomalies, such as unusual login times or IP addresses and determine if the activity was intentional (e.g., a legitimate bulk email campaign) or accidental (e.g., a misconfiguration).
- If the sender is an internal user and the activity is suspicious, disable the account temporarily and strengthen authentication measures (e.g., multi-factor authentication) for user accounts.