tcpdump: how to monitor SMTP traffic abuse from LAN?

Viewed 7840

I am the sysadm of a small enterprise.

Our company has quite loose security policies, despite my many recommendations... :-) I can't control what's installed on client desktops.

I would like to setup a monitor to be - at least - warned (by email, for example) that spam email is originated from our domain... (problem already happened in the past... :-()

I have currently come to this command:

tcpdump -v -s 1500 -i eth0 port 25 2> /dev/null | grep --line-buffered 'smtp: S' | perl -MPOSIX -pe 'print strftime "%F %T", localtime; print " "; s/(.*?\)) (.*?)\.\d+ \>(.*)/$2/;'

Which simply prints out each connection to port 25 (timestamp and client name).

Is there a reliable check I can perform on this output to identify SMTP abuse?

Or, are there better approaches to this problem?

1 Answers
Related