Define email search criteria and request a search
As a user with the sn_si.analyst role, set up search criteria and submit an email search request based on incident details on a security incident record.
Before you begin
Role required: sn_si.analyst
About this task
The status of individual messages that match the search query and the results of the search are reported on the security incident record. If email notifications are enabled, you can view the search results from an email message.
Search criteria may include message sender addresses, recipient addresses, or subject names. The following combinations of message Subject, Sender, and Recipient search parameters are often used for finding phishing-related email messages that may be part of a single phish campaign:
- Find all original emails sent by a phishing account: Search by sender.
- Find all original emails for a single phishing campaign: Search by subject and sender.
- Find all emails received for a single phishing campaign (original and forwarded, any sender): Search by subject.
- Find all forwarded emails for a single phishing email from a single user: Search by recipient + subject.
- Find all phishing-related emails sent to a single user: Search by sender + recipient.
Note: Searches are conducted on emails sent or received within last 30 calendar days, unless a shorter search window is configured during the initial setup. A successful email search is required before you can delete emails.
Procedure
Navigate to All > Security Incident > Show All Incidents and locate the security incident that you're working with.
Alternatively, follow these steps to set and run a filter so that only security incidents created by phishing events are displayed.
Navigate to Security Incident > Show All Incidents to open the Security Incidents list.
In the upper-left corner of the list that is displayed, select the filter icon.
In the fields that are displayed, select Short description > contains from the choice lists, then enter user reported phishing and select Run.
The phishing-related security incidents are displayed.
Use the text in the Short description column to help you locate the security incident that you're working with.
In the Number column, select a security incident to open a record.
Scroll to the bottom of the Security Incident record and select the Email Search related list.
If the Email Search related list is not displayed, select the Show All Related Lists related link to display this related list.
In the Email Search related list, select New to create a new email search record.
The Email Search form is displayed. If you determine that you want to rerun this search query for the same phishing-related incident with minor modifications, you can use this search query record again. However, it is unlikely that you would use this search for a different phishing-related incident, because phishing campaigns are dynamic and the sender and message fields often change.
To edit an existing search query record, select Edit.
On the Email Search form, fill in the fields.
Field Description Name Information to describe the type of search. For this example, a name for a From + Subject search is Phish "log in to your account".Description Information about the search in the email server. An example for this search is From=phisher@cbazyx.com + Subject=log in to your account.Select Submit.
The security incident is displayed and the name of the email search is displayed in the Email search column in the Email Search related list. Before you can use this new search query, search criteria must be defined for the search record.
To define search criteria, with the Email Search related list selected, in the Email search column, select Phish "log in to your account".
On the Email search record that is displayed, select the Email Search Criteria related list, and select New.
On the Email Search Criteria form, fill in the fields.
An example of a completed form follows the table.
| Field | Description |
|---|---|
| Email search | Field is populated automatically with the name that you entered for the Email Search record. |
| Search icon | Lookup using list. A list of saved searches. select the icon to open a list of saved email searches. select an item in this list to remove the current search and select a previously saved email search. |
| Information icon | Icon used to view the Email Search record. select the icon to view the email search record. |
| Search field | Search criterion (Subject, From, or Recipient). Select the search criterion from the choice list and define a value that you want to search for in the text field. For this example, start with From phisher@cbazyx.com (the email address of the sender of the phishing email). |
| Active | Option for activating the search.The search is activated by default. If you clear this option, this record is not included in a search. |
| Operator | Operators (AND, OR) to further define your search. AND: The system searches for the conditions separated by AND and returns results only if all the conditions are met. For the sender-plus-subject search, use the AND operator so that both search conditions are met during the email search. For this example, use the AND operator so that the query is From (Sender) = OR: The system searches and returns results if any of the conditions separated by OR are met. An example is From (Sender) = |
| Order | If you enter more than two search conditions, use Order to prioritize the conditions. 100 is the default. Enter a value between 1 and 100 for each condition, for example, 100, 95, 90, 80. The condition with the lowest number assigned has the highest search priority within a group of conditions. |
| Search text | The text values \(key words\) for the search \(email addresses or subject lines\).The search field contains the text used in the search, for example, `phisher@cbazyx.com`. For the search to return results accurately for Sender \(From\) and recipient searches, the search strings must match exactly. For subject searches, the search string can contain key words that are part of a larger string. For example, a subject may contain the exact search string that is matched in a forwarded or a response message header such as `FW: log in to your account and change your password immediately`. For example, `Log in to your account` are exact key words in the string `log in to your account and change your password immediately`. No wildcard \(\*\) designation is required to support a contains type of search. Currently, no filtering method exists for matching an exact search string that is not part of a larger text string. |
Select Submit.
The Email Search record is displayed. In the Query from criteria field, the search criteria you added for the Sender (From) is displayed.
To update this email search criteria with more information so that the query includes the subject-plus-sender condition that you want, follow the steps to add another search condition.
In the Email Search Criteria related list, select New.
From the Search fieldlist on the Email Search Criteria record that is displayed, select Subject.
From the Operator list, selectAND or OR.
If you select OR, the search returns results if either key words in the subject line text string are matched, or the email address condition is matched. AND is selected for this example so that the search returns results only for emails that contain the key words of the subject text string and that match the email address of the sender.
In the Search text field, enter the value for subject line text,
log in to your account.Select Submit.
The new condition is displayed in the Email Search Criteria related list, and both conditions are displayed in the Query from criteria field separated by the AND operator.
If you have more than two search conditions, and you select AND to separate each condition, set the order value to prioritize them.
Continue to add, modify, or remove search criteria as desired and select Update to save your changes to the record.
Choose one option to continue.
| Option | Description |
|---|---|
| Update | Update and save your changes to the record. |
| Search on Email Server(s) | Initiate a search on the servers with the criteria that you saved on the Email Search Criteria record. |
| Delete | Delete this Email Search record from your ServiceNow AI Platform instance. This action does not delete the actual email messages. It only deletes the search record used for finding messages.A dialog box is displayed. If you select Delete, the email search results and email search criteria for this search record are deleted. Image omitted: ms-924-confirm-delete-rcd.png Confirmation dialog box to delete an email search record.</p> If a record has search results, the following warning is displayed. Image omitted: ms-warning-dialog.png Confirmation dialog box for search result record.</p></td></tr></tbody>
Parent Topic:Microsoft Exchange Online integration Previous topic:Configure the Microsoft Exchange Online integration Next topic:Request delete approval for emails on Microsoft Exchange online service |