Attack Simulation Test
One Tool. Four Vectors. Better Risk Visibility.
Attackers target the workforce across a variety of different phishing vectors, from malicious QR codes to fake LinkedIn requests, continuously searching for an exploitable gap. Where is your workforce most vulnerable?
This free attack simulation test gives you a dedicated sandbox to test your workforce against the full spectrum of modern phishing techniques, including email phishing, reply phishing, social media phishing and QR code phishing. Upload your target list once and deploy a targeted simulation for the vector of your choosing.
Once you run the test, you’ll get a report that quantifies your workforce’s vulnerability against the chosen phishing vector.
Here's How the Attack Simulation Test Works
- Select the test you want to run and add up to 100 users. You can start immediately without talking to anyone from KnowBe4.
- Select from 20+ languages and customize the phishing test template based on your organization and users.
- Choose the landing page your users will see if they fall for the phish. You can show users which red flags they missed, or a 404 page.
- Look for a report in your inbox 24 hours after it starts. This PDF shows your Phish-prone Percentage and benchmarks for your industry.
- Share with management to demonstrate your vulnerability against major phishing vectors.
Get Instant Access to the Attack Simulation Test
The Phish-prone Percentage metric helps you stop guessing and start quantifying your workforce’s vulnerability to specific phishing vectors. Fill out the form, set up your test and get the hard numbers you need to justify more investment into your attack simulation and security awareness training.
Attack Simulation Test FAQs
How Is an Attack Simulation Conducted?
What Types of Phishing Scenarios Are Used in Tests?
Should I Run a Phishing Test If I Already Have a SAT Vendor?
Should Small Businesses Perform an Attack Simulation?
Who Should Conduct Attack Simulations?
How Often Should Attack Simulations Be Run?
Get your Free Test

Phishing Defined
Emails claiming to be from popular social websites, banks, auction sites, or IT administrators are commonly used to lure the unsuspecting public. It’s a form of criminally fraudulent social engineering.
Phishing FAQs
- Understand the risks you face
- Develop adequate policies
- Keep systems up-to-date
- Ensure you have good and recent backups
- Deploy anti-phishing solutions
- Implement best practices for user behavior
- Use robust threat intelligence
Additionally, here are our top 10 prevention tips to share with your users to help keep them safe from anywhere:
- Keep informed about phishing techniques
- Think before you click!
- Install an anti-phishing toolbar
- Verify a site’s security
- Check your online accounts regularly
- Keep your browser up to date
- Use firewalls
- Be wary of pop-ups
- Never give out personal information if you're unsure
- Use antivirus software
Your last line of defense against phishing attacks is your users. That's why the most important step you can take towards prevention is a new-school security awareness training program combined with regular simulated phishing tests.
Phishing and training your users as your last line of defense is one of the best ways to protect yourself from attacks. Here are the 4 basic steps to follow:
- Baseline Testing to assess the Phish-prone percentage of your users before training them. You want to know the level of attack they will and won't fall for as well as have data to measure future success.
- Train Your Users with on-demand, interactive, and engaging training so they really get the message.
- Phish Your Users at least once a month to reinforce the training and continue the learning process.
- See The Results for both training and phishing, getting as close to 0% Phish-prone as you possibly can
An additional 5 points to consider:
- Awareness in and of itself is only one piece of defense-in-depth, but crucial
- You can't and shouldn't do this alone
- You can't and shouldn't train on everything
- People only care about things that they feel are relevant to them
- The ongoing process is to help employees make smarter security decisions
...and what we've found to be the 5 best practices to embrace:
- Have explicit goals before starting
- Get the executive team involved
- Decide what behaviors you want to shape - choose 2 or 3 and work on those for 12-18 months
- Treat your program like a marketing effort
- Phish frequently, once a month minimum
Phishing your users is actually FUN! You can accomplish all of the above with our security awareness training program. If you need help getting started, whether you're a customer or not you can build your own customized Automated Security Awareness Program (ASAP) by answering 15-25 questions about your organization
Cybercriminals are constantly updating their phishing techniques. While the content of phishing emails have come a long way and continue to evolve over the years, here are a few basic variations that are most common:
- Classic Phishing Email: Over the past few years, online service providers have gone the route of messaging customers when they detect unusual or worrisome activity on their users' accounts. Not surprisingly, the bad guys are using this to their advantage. Many are designed poorly with bad grammar, etc. but others look legitimate enough for someone to click if they weren't paying close attention.
- Social Media Exploits: Many users have publicly available information on platforms like Facebook, LinkedIn, and Twitter. The bad guys scrape this information to craft targeted spear phishing emails against your users and your organization. These emails are part of campaigns designed to hijack accounts, damage your organization's reputation, or gain access to your network.
- Infected Attachments: Malicious .HTML attachments aren't seen as often as .JS or .DOC file attachments, but they are desirable for a couple of reasons. First, there is a low chance of antivirus detection since .HTML files are not commonly associated with email-borne attacks. Second, .HTML attachments are commonly used by banks and other financial institutions so people are used to seeing them in their inboxes.
Malicious macros in phishing emails have also become an increasingly common way of delivering ransomware. These documents too often get past antivirus programs with no problem. The phishing emails contain a sense of urgency for the recipient. If users fail to enable the macros, the attack is unsuccessful. - CEO Fraud Scams: CEO fraud is a type of scam in which cybercriminals spoof company email accounts and impersonate executives to try and fool an employee in accounting or HR into executing unauthorized wire transfers, or sending out confidential tax information. Typically, cybercriminals have gathered enough data to know who they want to target.
KnowBe4's free Phishing Security Test can determine the vulnerability level of your network by giving you an indication of how many people may be susceptible to an email-borne social engineering attack.
It can also be used to supplement and reinforce training received in the KnowBe4 training modules by giving your users real world “practice” in recognizing social engineering attacks and responding to them appropriately.
It works like this: The PST sends one email to each user in your organization. In our initial, free phishing security test, the email sent is a link test, which involves some text meant to lure the user into clicking an embedded link. Once the link is clicked, the user is directed to a Landing Page. Our Basic Landing Page tells the user they have been part of a simulated phishing test and gives them some rules to apply when inspecting emails in their inbox.
The results of the test include the number of users who failed the test divided by the number of users to whom the test was delivered. This gives you a Phish-Prone Percentage – the percentage of your users who “failed” the PST.
After you run the test, you can return to your account at any time to view the results on the Dashboard page. You will be able to see your Phish-Prone Percentage, showing your vulnerability if a similar phishing attack were to occur within your organization. You will also see how your Phish-Prone Percentage compares with others in your industry, after one year of combined computer-based security awareness training and simulated phishing.
A PDF report will also be emailed to you automatically after 24 hours. If you would like to know who clicked, your rep or reseller can get you that information!
Armed with this knowledge, you can help protect your organization by teaching your users about the dangers of these types of attacks. Enrolling in KnowBe4's new school security awareness training can help you achieve this goal. Through KnowBe4, you can train your users to spot the warning signs and keep their skills sharp by sending fake phishing attacks much like the ones in this free tool.
Attacks on mobile devices are nothing new, however they are gaining momentum as a corporate attack vector.
Attackers now take advantage of SMS, as well as some of today’s most popular and highly used social media apps and messaging platforms, such as WhatsApp, Facebook Messenger, and Instagram, as a means of phishing. Security professionals who overlook these new routes of attack put their organizations at risk.
Here are just a few phishing related risks posed by mobile device use:
- Apps - lack built-in security. Free apps usually ask for a lot of access they shouldn’t need.
- WiFi - your device typically picks up the strongest signal, which may be a rogue WiFi that seems legitimate but is actually an attacker just waiting to monitor, intercept or even alter communications from your device.
- Bluetooth - can be used to spread viruses, and hackers can use it to hack into phones to access and exploit your organization’s data.
- Human error - thieves sell lost and stolen devices to buyers who are more interested in the data than the device itself.
- Smishing - aka phishing conducted via SMS. Similar to phishing emails, an example of a smishing text might attempt to entice a victim into revealing personal information. asking the recipient to take action on any number of seemingly mundane activities, i.e., the user’s bank claiming it has detected unusual activity or a congratulatory notice saying the person has won a prize from their favorite store.