Exim mail monitor for discovering outgoing spam/viruses
Does anybody know a how I can monitor my organizations outgoing mail to pick up spam/viruses sent from the inside? I just had a situation where an user sent 1222 mails in less that 2 hours, and with 12500 users it's not easy to notice without help from a script. I don't know perl (or any other powerful languages), so I can't make the script on my own.
What I want is a script that monitors the maillog, pulls out a user-name if the user sends more that x mails pr minute, and sends the info to my mailbox.
Has anybody seen anything like this? I've searched freshmeat and the rest of the web without any luck...
|