I am the sysadm of a small enterprise.
Our company has quite loose security policies, despite my many recommendations... :-) I can't control what's installed on client desktops.
I would like to setup a monitor to be - at least - warned (by email, for example) that spam email is originated from our domain... (problem already happened in the past... :-()
I have currently come to this command:
tcpdump -v -s 1500 -i eth0 port 25 2> /dev/null | grep --line-buffered 'smtp: S' | perl -MPOSIX -pe 'print strftime "%F %T", localtime; print " "; s/(.*?\)) (.*?)\.\d+ \>(.*)/$2/;'
Which simply prints out each connection to port 25 (timestamp and client name).
Is there a reliable check I can perform on this output to identify SMTP abuse?
Or, are there better approaches to this problem?