Jump to content

Recommended Posts

Posted

Hi

We currently use a service called KNOWBE4 which lets us create fake phishing emails and if the end use CLICKS the fake link, it records this.

Offending users then automatically get enrolled on a training course.

 

Its always worked fine, but now when a staff member (correctly) forwards a Simulated phishing emails it counts as a click :(

 

So, I am looking for an alternative to KNOWBE4 - does anyone know one ?

 

THANKS

Posted

We use BoxPhish, through @Net-Ctrl. Includes quick bite-sized training as well, which I feel balances out the simulations. Great reporting as well, so you can see who is (or is not) doing what.

 

Could it be one of your systems is following the link to test for nasties? When we setup BoxPhish there were instructions how to add the service to Exchange to stop it being blocked or scanned, leading to false results.

 

In theory best practice is not to forward potential phishing emails as it spreads the risk, even if it is to the IT department. BoxPhish does also come with an Outlook plugin (web and app) that allows reporting with the attached headers and code, rather than the whole email.

  • Thanks 1
Posted
Would also reccomend Boxphish via NetCtrl, the training is pretty good and some of the simulations are very well done. Also allows you to send additional courses/simulations on demand.
  • Thanks 1
Posted

Thank you both for the mentions!

@njreynolds if you would like to arrange a demo of Boxphish, please send me a PM or email [email protected]. Boxphish are constantly building on their platform, which is great to see.

 

They recently added a module that monitors stolen data and leaked credentials (this is a bolt-on product).

Posted

We used to use Sophos Phish, not extensively (and not for a while if I'm honest...), so I can't probably give you the level of detail you require (and can't give you cost as it's bundled with the subscription).

 

However, it worked well for us, it has pretty much what I'd expect... training, lots of templates, breakdowns of who did what etc.

 

We've been on GMail for a few years and found their Spam/Phishing filters to be really good and I guess I've got a little complacent, so you actually reminded me to fire it up and test one today.

 

I guess Spam/Phishing getting through must be quite rare these days as I've already had 3 staff members come to me and tell me they've got a dodgy email (although I'll admit it was a very easy one as I hadn't done it in a long time).

Posted
I used a trial of Sophos Phish a while back, as we use them for our AV. It worked well, and the UI was easy to navigate. I am unsure of the actual cost though, I have also looked into Secure Schools, and Boxphish which appear to be good alternatives.
Posted
Awesome, thanks for this info. I really like Wonde, it just works

 

Yeah, we've found the templates more aimed at schools with fake Arbor or any MIS emails as one example.

 

Boxphish did have a lot of templates but the majority were generic where staff work accounts it may not be relevant!

We'd still get the clicks on a DPD delivery if they hadn't ordered anything!!!

Posted
Previous academy I worked at also used Boxphish, seems very common in LA's. Here we use usecure's uPhish and uLearn Security Awareness training. The reports and customisation is fantastic.
Posted
Its always worked fine, but now when a staff member (correctly) forwards a Simulated phishing emails it counts as a click :(

 

We use the same phishing simulation system, which we find generally works well. However, if users forward an email to our Trello-based helpdesk, Trello tries to follow any links it sees in emails to get a page title / favicon, etc, which triggers the you-followed-a-dodgy-link process. We now have a few reports of the same thing happening when people use the "report phishing" button in GMail, although we need to double-check that is actually what is happening. I would prefer users to report any suspicious-looking emails they see to us rather than not, so I'm reluctant to tell them not to forward suspected phishing emails to the helpdesk. It does also make me think the best way to actually get someone to click on a real phishing email these days would be to make it look like a report from a phishing email test - "You clicked on one of our phishing test emails, please click this dodgy link to do some training, or this equally dodgy link if you think this is in error"...

Posted

We've been using KnowBe4 for 2 years and never had this issue before. Yesterday we issues a Phishing test to 200 people. 30 clicked the link, but another 70 forward it to me & it counted as a click.

I am 100% sure it didn't do this before. I contacted support, but they said thats how it works :(

Thanks

Posted (edited)

I really liked Knowbe4 at my old school, when combined with its phishing reporting tool users would be shown a "congratulations you spotted a simulated phish" message or it would forward the message to our helpdesk if it wasn't simulated, it was setup to send everyone a mail from a pool of messages. The links in the messages were visibly dodgy but didn't relate to Knowbe4 at all.

 

My new school/trust is using BoxPhish, everyone receives the same message spread over a few days and we get half the staff forwarding them to us asking whether they're genuine or not, after a couple of days everyone is expecting the message. All of the urls within the messages point towards boxphish making it far too easy to spot.

 

I trialed the sophos solution but found it to be far too cartoon based which I felt wouldn't go down so well with our staff, both KnowBe4 and Pox Phish training was pretty good.

 

James

Edited by Jamman960
  • Thanks 1
Posted

My new school/trust is using BoxPhish, everyone receives the same message spread over a few days and we get half the staff forwarding them to us asking whether they're genuine or not, after a couple of days everyone is expecting the message. All of the urls within the messages point towards boxphish making it far too easy to spot.

 

Boxphish have some workaround options, including masked URL simulations. If you want to reach out to your Boxphish contact, they’ll be happy to jump on a call and discuss further, or if not sure who that might be send me a PM and I can relay the request and ask them to get in touch. If Boxphish is a new solution to you, I am sure they could run through some user training etc and work with you to get this performing better for you.

Posted
I really liked Knowbe4 at my old school, when combined with its phishing reporting tool

 

Ah, we maybe need to point our users at that, I'll investigate a bit further - thanks.

Posted

I don't find Sophos Phish cartoon like, there's hundreds of templates and they're pretty good...

 

Sophos_Phish.jpg

 

...or do you mean the training? I have to admit I haven't looked at that.

 

Sophos also seems to give you the option to send different templates within a campaign and spread it over a longer period.

 

I didn't do that today and the fact that they all got a dodgy email was apparently the talk of the staff room at lunch time.

 

Still it got awareness up I guess, so that's a good thing and I've now had 5 staff members ask me about it.

Posted

Happy to quote for Sophos and provide info to anyone who’s interested,

 

It’s especially useful if you already have endpoint and Sophos Central as all users are part of the same ecosystem..

 

Cheers

 

Lee

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...