Check Point Harmony Email & Collaboration malicious URL clicked by user
이 페이지는 아직 한국어로 제공되지 않습니다. 번역 작업 중입니다.
현재 번역 프로젝트에 대한 질문이나 피드백이 있으신 경우
언제든지 연락주시기 바랍니다.Goal
Detects instances where a user clicks on a malicious URL within an email (for example, Office 365 Mail, or Gmail) or a collaboration platform (for example, Google Drive, SharePoint, or Microsoft Teams). This may indicate a phishing attempt, malware delivery, or an attempt to steal user credentials.
Strategy
This rule monitors user activity related to URL clicks and raises an alert when a malicious URL is accessed by the same user, suggesting potential exposure to a security threat.
Triage and Response
- Review the user email address
{{@event.security_event.saas_info.saas_actor_payload.email}} and the platform involved {{@saas_name}}, and verify the source of the malicious URL. - Analyze if the URL is associated with known phishing campaigns, malware distribution, or credential theft.
- If the URL is confirmed to be malicious, initiate remediation actions such as blocking the domain, revoking access tokens, and scanning the user’s device for potential compromise.
- Notify the user and provide security awareness guidance to prevent future incidents.