rlculver Posted May 8, 2019 Posted May 8, 2019 Hi All, We use Office 365 A1 for facility in our school. We would like to carry out Phishing attempt, so that we can see if staff actually 'fall fail' of the email. What services are there in place and what do you use in your school? Many Thanks Robert
CHSGM Posted May 8, 2019 Posted May 8, 2019 I'm conducting one today for the MAT I manage and I am using GoPhish. Completely free. 3
Gurtlush Posted May 8, 2019 Posted May 8, 2019 we have used the trendmicro one https://phishinsight.trendmicro.com/en/simulator Be prepared for alot of grief! there are still members of staff not talking to us. (which could be seen as a win?)
Arthur Posted May 8, 2019 Posted May 8, 2019 Attack Simulator in Office 365 (if you also have Office 365 Advanced Threat Protection Plan 2?) Google also do this.. https://phishingquiz.withgoogle.com
howartp Posted May 8, 2019 Posted May 8, 2019 Excellent timing, this is on my list having been approved last week!
rlculver Posted May 8, 2019 Author Posted May 8, 2019 Many Thanks - The Office 365 Advanced Threat Protection Plan 2 looks good, as it provides the simulation and also improves email security. What are you thoughts on this? Thanks
colly72 Posted May 8, 2019 Posted May 8, 2019 We've recently signed up for Sophos Phishing. Can create campaigns then target automatic training for all those who get caught. Works well and is quite cheap.
howartp Posted May 8, 2019 Posted May 8, 2019 We've recently signed up for Sophos Phishing. Can create campaigns then target automatic training for all those who get caught. Works well and is quite cheap. That's part of my plan; we're just moving to Central.
MS2011 Posted May 9, 2019 Posted May 9, 2019 We've recently signed up for Sophos Phishing. Can create campaigns then target automatic training for all those who get caught. Works well and is quite cheap. How much you are paying for Sophos phishing?
howartp Posted May 9, 2019 Posted May 9, 2019 I'm pretty impressed with our staff. Of the 209 which have gone out, around 40 have forwarded or questioned them verbally. Only 17 have actually filled in their credentials; words will be had! (I asked permission to name and shame on the staff noticeboard, but that's been declined)
colly72 Posted May 9, 2019 Posted May 9, 2019 How much you are paying for Sophos phishing? We paid around £530 ex VAT for 110 users, for 21 months (strange I know but this brought it in line with the rest of our Sophos licensing). 1
MS2011 Posted May 9, 2019 Posted May 9, 2019 We paid around £530 ex VAT for 110 users, for 21 months (strange I know but this brought it in line with the rest of our Sophos licensing). We do use Sophos central here anyway. How does it work ?
colly72 Posted May 9, 2019 Posted May 9, 2019 We do use Sophos central here anyway. How does it work ? Basically, you create a campaign based on either phising, credential harvesting or luring an end user to open and email attachment. You can then choose the type of attack - there are lots of templates to choose from, from Paypal, to Barclays, Currys or HMRC etc etc, which you can tweak and customise if required. You then choose a training modules (videos, quizzes etc), that any user who get's caught is enrolled onto. You then choose your users or groups of users from your existing Sophos Central account, to target the campaign and schedule when to send it. Once sent, you can view stats from the dashboard, to see who's opened the email, who's clicked on links etc etc. 1
MS2011 Posted May 9, 2019 Posted May 9, 2019 Basically, you create a campaign based on either phising, credential harvesting or luring an end user to open and email attachment. You can then choose the type of attack - there are lots of templates to choose from, from Paypal, to Barclays, Currys or HMRC etc etc, which you can tweak and customise if required. You then choose a training modules (videos, quizzes etc), that any user who get's caught is enrolled onto. You then choose your users or groups of users from your existing Sophos Central account, to target the campaign and schedule when to send it. Once sent, you can view stats from the dashboard, to see who's opened the email, who's clicked on links etc etc. [emoji106]
mikes Posted May 14, 2019 Posted May 14, 2019 [ATTACH=CONFIG]53318[/ATTACH] I'm pretty impressed with our staff. Of the 209 which have gone out, around 40 have forwarded or questioned them verbally. Only 17 have actually filled in their credentials; words will be had! (I asked permission to name and shame on the staff noticeboard, but that's been declined) lol, nice. Problem is only one failure can infect a network if there are e.g. SMB vulnerabilities still open. We had Emotet that was not picked up by Sophos, and SCCM Endpoint only picked up 50%. I ended up just outright blocking all mails from Russia, Vietnam, Africa etc. I have trained staff NEVER to open any e-mail that asks for macros, credentials, etc; saying it will be 100% malware no exceptions. Then the LEA sends out a stats spreadsheet that requires clicking on an e-mail link, entering credentials, and enabling edit mode / turning macro security to low. The same thing from one of the schools partners. So they don't know what to think. Sometimes they shouldn't follow links from e-mails, then other times they should; it is no wonder they get caught up.
mavhc Posted May 14, 2019 Posted May 14, 2019 Turns out humans are too stupid to check what site they're putting passwords into, so we need to automate it. Never type a password in, only allow automatic password managers to auto log in on the correct sites. Or FIDO, or SQRL.
rlculver Posted May 22, 2019 Author Posted May 22, 2019 (edited) Hi, Does anybody use a Raspberry Pi for Gophish ? Will be used for around 30 users. Thanks Edited May 22, 2019 by rlculver
mavhc Posted May 22, 2019 Posted May 22, 2019 Hi, Does anybody use a Raspberry Pi for Gophish ? Will be used for around 30 users. Thanks Probably would be fine, written in Go, you're unlikely to have >1 visitor at once either
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now