Hub
Email

Kaspersky Security for Linux Mail Server CEF

Kaspersky Security for Linux Mail Server ScanLogic records as CEF in event.original of an ECS JSON event: a mail-authentication (SPF, DKIM, DMARC) record and an antivirus record for every processed message from 43 senders of five kinds, about 13,400 messages a day. Recurring episodes send one high-value mailbox three rejected spoofed messages within 180 seconds: two clean lures, then an infected payload.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/email-kaspersky-klms/generator.yml \
  --id klms \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
MA ViolationNotFoundLMS_EV_SCAN_LOGIC_MA_STATUS with SPF, DKIM and DMARC verdicts, none failing; action Skip38.9% share (38.9% background only)email
MA ViolationFoundLMS_EV_SCAN_LOGIC_MA_STATUS with at least one failing verdict; action Reject11.1% share (11.1% background only)email
AV CleanLMS_EV_SCAN_LOGIC_AV_STATUS antivirus result for the same message; action Skip49.5% share (49.6% background only)malware
AV InfectedLMS_EV_SCAN_LOGIC_AV_STATUS infected result; action Reject, severity High0.5% share (0.4% background only)malware

Realism Features

  • Every processed message produces two records, MA then AV, with the same message ID, size, relay, sender, recipient and one-second UTC processing timestamp. The pairing, MA-first order and identical timestamp are explicit scenario assumptions, not confirmed native ordering.
  • MA and antivirus scanning run for one recipient under the Default rule. The selected policy rejects each SPF, DKIM or DMARC violation and clean results use Skip; act is the engine action, not a delivery outcome, so an AV result can accompany an authentication rejection and a clean AV result does not imply delivery.
  • About 13,400 messages (26,800 records) a day, varying by about 3% from day to day. Ordinary senders follow a daily curve from 0.6 of their mean hourly rate at night to 1.4 of it around 13:00 UTC, while spoofing senders are active at a flat rate round the clock; the busiest hour carries about 780 messages and the quietest about 345.
  • 43 senders of five kinds open SMTP sessions at random moments, each with a share set by its weight, with no fixed period or cooldown: 24 partners (53.0% of messages), 5 notification senders (17.7%), 5 bulk mailers (about 13%), 3 forwarders that break SPF (9.6%) and 6 spoofing senders (about 7%). A bulk mailing reaches its recipients a median of 6 seconds apart (90% within 20 seconds) and the messages of a spoofing sender are about half a minute apart, rather than the sub-second spacing a fast sender can reach. Message sizes are log-normal per kind, and infected messages are larger.
  • Ordinary traffic in both modes repeats all-fail messages from one spoofing sender to one high-value mailbox within minutes (154 same-flow pairs and 45 triples within 180 seconds per 28 hours of background-only output) and infected all-fail messages that follow such a failure. An ordinary all-fail message that would follow two all-fail clean messages of the same flow within 180 seconds is always scanned clean. The total message count is the same in both modes, but each episode adds its own messages, so counts of all-fail spoofed messages to a high-value mailbox and of infected results after such failures are about three and one per episode higher than in background.
  • CEF extension values escape equals signs, backslashes and line breaks, and header values escape pipes; relays may be IPv4 or IPv6. The ECS object joins native identities and adds no authenticated user, transport envelope, threat name or delivery verdict.
  • Keys and statuses follow the KLMS ScanLogic key table and verdict catalogs, but no complete MA or AV ScanLogic record was found: event names, severities, act/outcome wire vocabulary, cs1 form, product build (illustrative 8.0MP2), pair order and timestamps and syslog framing are inferred, and no PRI is invented. The stream is separate from Kaspersky Secure Mail Gateway; rates, session shapes, verdict weights and sizes are synthetic, and with no Elastic integration sample the ECS mapping is inferred.

Sample Output

{
  "@timestamp": "2026-09-25T07:00:23+00:00",
  "ecs": {
    "version": "8.17.0"
  },
  "email": {
    "from": {
      "address": [
        "ceo.office@examp1e.test"
      ]
    },
    "local_id": "adf1b964db344ebc",
    "to": {
      "address": [
        "accounting@example.test"
      ]
    }
  },
  "event": {
    "action": "reject",
    "category": [
      "malware"
    ],
    "code": "LMS_EV_SCAN_LOGIC_AV_STATUS",
    "dataset": "kaspersky.klms",
    "kind": "event",
    "original": "September 25, 2026 07:00:23 mail-01.example.test CEF:0|AO Kaspersky Lab|Kaspersky Linux Mail Security|8.0MP2|LMS_EV_SCAN_LOGIC_AV_STATUS|antivirus scan status|High|cs1=adf1b964db344ebc cs1Label=MessageId src=192.0.2.199 act=Reject fsize=72259 suser=ceo.office@examp1e.test duser=accounting@example.test cs2=Default cs2Label=Rules outcome=Infected",
    "type": [
      "info"
    ]
  },
  "kaspersky": {
    "klms": {
      "class_id": "LMS_EV_SCAN_LOGIC_AV_STATUS"
    }
  },
  "observer": {
    "hostname": "mail-01.example.test",
    "product": "Kaspersky Linux Mail Security",
    "vendor": "Kaspersky",
    "version": "8.0MP2"
  },
  "source": {
    "ip": "192.0.2.199"
  }
}

Parameters

ParameterDefaultDescription
anomaly_modetruePeriodic campaign enabled; `false` emits background only
anomaly_interval_hours6Hours from one actual episode start until the next episode is due; values below 1 are raised to 1
mail_hostmail-01.example.testSynthetic hostname with no whitespace or line breaks
product_version8.0MP2Illustrative vendor header value, not a verified live build

Related Generators