Get started using Attack simulation training - Microsoft Defender for Office 365 (original) (raw)

In organizations with Microsoft Defender for Office 365 Plan 2 (add-on licenses or included in subscriptions like Microsoft 365 E5), you can use Attack simulation training in the Microsoft Defender portal to run realistic attack scenarios in your organization. These simulated attacks can help you identify and find vulnerable users before a real attack impacts your bottom line.

This article explains the basics of Attack simulation training.

Watch this short video to learn more about Attack simulation training.

What do you need to know before you begin?

Note

Attack simulation training offers a subset of capabilities to E3 customers as a trial. The trial offering contains the ability to use a Credential Harvest payload and the ability to select 'ISA Phishing' or 'Mass Market Phishing' training experiences. No other capabilities are part of the E3 trial offering.

Simulations

A simulation in Attack simulation training is the overall campaign that delivers realistic but harmless phishing messages to users. The basic elements of a simulation are:

In Attack simulation training, multiple types of social engineering techniques are available. Except for How-to Guide, these techniques were curated from the MITRE ATT&CK® framework. Different payloads are available for different techniques.

The following social engineering techniques are available:

* The link can be a URL or a QR code.

The URLs that are used by Attack simulation training are listed in the following table:

| | | | | | -------------------------------- | ------------------------------ | ----------------------------- | | https://www.attemplate.com | https://www.exportants.it | https://www.resetts.it | | https://www.bankmenia.com | https://www.exportants.org | https://www.resetts.org | | https://www.bankmenia.de | https://www.financerta.com | https://www.salarytoolint.com | | https://www.bankmenia.es | https://www.financerta.de | https://www.salarytoolint.net | | https://www.bankmenia.fr | https://www.financerta.es | https://www.securembly.com | | https://www.bankmenia.it | https://www.financerta.fr | https://www.securembly.de | | https://www.bankmenia.org | https://www.financerta.it | https://www.securembly.es | | https://www.banknown.de | https://www.financerta.org | https://www.securembly.fr | | https://www.banknown.es | https://www.financerts.com | https://www.securembly.it | | https://www.banknown.fr | https://www.financerts.de | https://www.securembly.org | | https://www.banknown.it | https://www.financerts.es | https://www.securetta.de | | https://www.banknown.org | https://www.financerts.fr | https://www.securetta.es | | https://www.browsersch.com | https://www.financerts.it | https://www.securetta.fr | | https://www.browsersch.de | https://www.financerts.org | https://www.securetta.it | | https://www.browsersch.es | https://www.hardwarecheck.net | https://www.shareholds.com | | https://www.browsersch.fr | https://www.hrsupportint.com | https://www.sharepointen.com | | https://www.browsersch.it | https://www.mcsharepoint.com | https://www.sharepointin.com | | https://www.browsersch.org | https://www.mesharepoint.com | https://www.sharepointle.com | | https://www.docdeliveryapp.com | https://www.officence.com | https://www.sharesbyte.com | | https://www.docdeliveryapp.net | https://www.officenced.com | https://www.sharession.com | | https://www.docstoreinternal.com | https://www.officences.com | https://www.sharestion.com | | https://www.docstoreinternal.net | https://www.officentry.com | https://www.supportin.de | | https://www.doctorican.de | https://www.officested.com | https://www.supportin.es | | https://www.doctorican.es | https://www.passwordle.de | https://www.supportin.fr | | https://www.doctorican.fr | https://www.passwordle.fr | https://www.supportin.it | | https://www.doctorican.it | https://www.passwordle.it | https://www.supportres.de | | https://www.doctorican.org | https://www.passwordle.org | https://www.supportres.es | | https://www.doctrical.com | https://www.payrolltooling.com | https://www.supportres.fr | | https://www.doctrical.de | https://www.payrolltooling.net | https://www.supportres.it | | https://www.doctrical.es | https://www.prizeably.com | https://www.supportres.org | | https://www.doctrical.fr | https://www.prizeably.de | https://www.techidal.com | | https://www.doctrical.it | https://www.prizeably.es | https://www.techidal.de | | https://www.doctrical.org | https://www.prizeably.fr | https://www.techidal.fr | | https://www.doctricant.com | https://www.prizeably.it | https://www.techidal.it | | https://www.doctrings.com | https://www.prizeably.org | https://www.techniel.de | | https://www.doctrings.de | https://www.prizegiveaway.net | https://www.techniel.es | | https://www.doctrings.es | https://www.prizegives.com | https://www.techniel.fr | | https://www.doctrings.fr | https://www.prizemons.com | https://www.techniel.it | | https://www.doctrings.it | https://www.prizesforall.com | https://www.templateau.com | | https://www.doctrings.org | https://www.prizewel.com | https://www.templatent.com | | https://www.exportants.com | https://www.prizewings.com | https://www.templatern.com | | https://www.exportants.de | https://www.resetts.de | https://www.windocyte.com | | https://www.exportants.es | https://www.resetts.es | | | https://www.exportants.fr | https://www.resetts.fr | |

Create simulations

For instructions on how to create and launch simulations, see Simulate a phishing attack.

The landing page in the simulation is where users go when they open the payload. When you create a simulation, you select the landing page to use. You can select from built-in landing pages, custom landing pages that you already created, or you can create a new landing page to use during the creation of the simulation. To create landing pages, see Landing pages in Attack simulation training.

End user notifications in the simulation send periodic reminders to users (for example, training assignment and reminder notifications). You can select from built-in notifications, custom notifications that you already created, or you can create new notifications to use during the creation of the simulation. To create notifications, see End-user notifications for Attack simulation training.

Tip

Payloads

Although Attack simulation training contains many built-in payloads for the available social engineering techniques, you can create custom payloads to better suit your business needs, including copying and customizing an existing payload. You can create payloads at any time before you create the simulation or during the creation of the simulation. To create payloads, see Create a custom payload for Attack simulation training.

In simulations that use Credential Harvest or Link in Attachment social engineering techniques, login pages are part of the payload that you select. The login page is the web page where users enter their credentials. Each applicable payload uses a default login page, but you can change the login page that's used. You can select from built-in login pages, custom login pages that you already created, or you can create a new login page to use during the creation of the simulation or the payload. To create login pages, see Login pages in Attack simulation training.

The best training experience for simulated phishing messages is to make them as close as possible to real phishing attacks that your organization might experience. What if you could capture and use harmless versions of real-world phishing messages that were detected in Microsoft 365 and use them in simulated phishing campaigns? You can, with payload automations (also known as payload harvesting). To create payload automations, see Payload automations for Attack simulation training.

Attack simulation training also supports using QR codes in payloads. You can choose from the list of built-in QR code payloads, or you can create custom QR code payloads. For more information, see QR code payloads in Attack simulation training.

Reports and insights

After you create and launch the simulation, you need to see how it's going. For example:

The available reports and insights for Attack simulation training are described in Reports for Attack simulation training.

Predicted compromise rate

You often need to tailor a simulated phishing campaign for specific audiences. If the phishing message is too close to perfect, almost everyone is fooled by it. If it's too suspicious, no is fooled by it. And, the phishing messages that some users consider difficult to identify are considered easy to identify by other users. So how do you strike a balance?

The predicted compromise rate (PCR) indicates the potential effectiveness when the payload is used in a simulation. PCR uses intelligent historical data across Microsoft 365 to predict the percentage of people who will be compromised by the payload. For example:

PCR allows you to compare the predicted vs. actual click through rates for your phishing simulations. You can also use this data to see how your organization performs compared to predicted outcomes.

PCR information for a payload is available wherever you view and select payloads, and in the following reports and insights:

Tip

Attack Simulator uses Safe Links in Defender for Office 365 to securely track click data for the URL in the payload message sent to targeted recipients of a phishing campaign, even if the Track user clicks setting in Safe Links policies is turned off.

Training without tricks

Traditional phishing simulations present users with suspicious messages and the following goals:

But, sometimes you don't want to wait for users to take correct or incorrect actions before you give them training. Attack simulation training provides the following features to skip the wait and go straight to training:

Tip

Attack simulation training provides the following built-in training options for QR code-based attacks: