Jump to content

Recommended Posts

Posted

Hi All,

 

We use Office 365 A1 for facility in our school.

 

We would like to carry out Phishing attempt, so that we can see if staff actually 'fall fail' of the email.

 

What services are there in place and what do you use in your school?

 

Many Thanks

 

Robert

Posted

Many Thanks - The Office 365 Advanced Threat Protection Plan 2 looks good, as it provides the simulation and also improves email security.

 

What are you thoughts on this? Thanks

Posted
We've recently signed up for Sophos Phishing. Can create campaigns then target automatic training for all those who get caught. Works well and is quite cheap.
Posted
We've recently signed up for Sophos Phishing. Can create campaigns then target automatic training for all those who get caught. Works well and is quite cheap.

 

That's part of my plan; we're just moving to Central.

Posted
We've recently signed up for Sophos Phishing. Can create campaigns then target automatic training for all those who get caught. Works well and is quite cheap.

 

How much you are paying for Sophos phishing?

Posted

PhishStats.png

 

I'm pretty impressed with our staff.

 

Of the 209 which have gone out, around 40 have forwarded or questioned them verbally.

 

Only 17 have actually filled in their credentials; words will be had!

 

(I asked permission to name and shame on the staff noticeboard, but that's been declined)

Posted
How much you are paying for Sophos phishing?

 

 

We paid around £530 ex VAT for 110 users, for 21 months (strange I know but this brought it in line with the rest of our Sophos licensing).

  • Thanks 1
Posted
We paid around £530 ex VAT for 110 users, for 21 months (strange I know but this brought it in line with the rest of our Sophos licensing).

 

We do use Sophos central here anyway. How does it work ?

Posted
We do use Sophos central here anyway. How does it work ?

 

Basically, you create a campaign based on either phising, credential harvesting or luring an end user to open and email attachment. You can then choose the type of attack - there are lots of templates to choose from, from Paypal, to Barclays, Currys or HMRC etc etc, which you can tweak and customise if required. You then choose a training modules (videos, quizzes etc), that any user who get's caught is enrolled onto. You then choose your users or groups of users from your existing Sophos Central account, to target the campaign and schedule when to send it. Once sent, you can view stats from the dashboard, to see who's opened the email, who's clicked on links etc etc.

  • Thanks 1
Posted
Basically, you create a campaign based on either phising, credential harvesting or luring an end user to open and email attachment. You can then choose the type of attack - there are lots of templates to choose from, from Paypal, to Barclays, Currys or HMRC etc etc, which you can tweak and customise if required. You then choose a training modules (videos, quizzes etc), that any user who get's caught is enrolled onto. You then choose your users or groups of users from your existing Sophos Central account, to target the campaign and schedule when to send it. Once sent, you can view stats from the dashboard, to see who's opened the email, who's clicked on links etc etc.

 

[emoji106]

Posted
[ATTACH=CONFIG]53318[/ATTACH]

 

I'm pretty impressed with our staff.

 

Of the 209 which have gone out, around 40 have forwarded or questioned them verbally.

 

Only 17 have actually filled in their credentials; words will be had!

 

(I asked permission to name and shame on the staff noticeboard, but that's been declined)

 

 

lol, nice. Problem is only one failure can infect a network if there are e.g. SMB vulnerabilities still open. We had Emotet that was not picked up by Sophos, and SCCM Endpoint only picked up 50%. I ended up just outright blocking all mails from Russia, Vietnam, Africa etc.

 

I have trained staff NEVER to open any e-mail that asks for macros, credentials, etc; saying it will be 100% malware no exceptions.

Then the LEA sends out a stats spreadsheet that requires clicking on an e-mail link, entering credentials, and enabling edit mode / turning macro security to low.

The same thing from one of the schools partners.

 

So they don't know what to think. Sometimes they shouldn't follow links from e-mails, then other times they should; it is no wonder they get caught up.

Posted
Turns out humans are too stupid to check what site they're putting passwords into, so we need to automate it. Never type a password in, only allow automatic password managers to auto log in on the correct sites. Or FIDO, or SQRL.
  • 2 weeks later...
Posted (edited)

Hi,

 

Does anybody use a Raspberry Pi for Gophish ?

 

Will be used for around 30 users.

 

Thanks

Edited by rlculver
Posted
Hi,

 

Does anybody use a Raspberry Pi for Gophish ?

 

Will be used for around 30 users.

 

Thanks

 

Probably would be fine, written in Go, you're unlikely to have >1 visitor at once either

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...