Attack Simulator – new phishing simulation feature [EN]

Microsoft has recently add a new feature to Attack Simulator :

  • Advanced reporting capabilities. The ability to see data such as the fastest (or slowest) time to open an attack simulation email message, the fastest (or slowest) time to click a link in the message, and more visualizations.

Even if Microsoft does not announce yet a new feature, we can see it in our tenant :

  • Attachment payload phishing simulation. The ability to use an attachment as the payload for phishing simulation in place of a URL.
2019 12 10 22 46 36 1024x192

It is quite the same configuration that the Credentials Harvest simulation

Launch the attack

For the test, I will just use a template

2019 12 10 22 51 49 1024x340

You will have to select people to send phishing email to
Then, provide email details

As you can see below, the new configuration is related to Attachment type and name :

Image 1024x560

You will be able to choose one of three types :

  • DOC
  • DOCX
  • PDF

You will be able to compose the email body as you used to

Image 1 1024x393

So, what about the user ?

The target receive the email with the attachment

Image 2 1024x382

Result

Report

As an admin, you want to know if your victims open the attachment or not.
See below an example of report that you will be able to have during your campaings

Image 3 1024x574

Explanation

I used OWA to check the mails and thus, I opened the documentation in the browser.
Attack simulator do not see that

So, I click on download in order to open the documentation.

I have to also “Enable the modification” for Attack Simulator refresh the attack details

Image 4 1024x453

Quite the same for PDF as an attachement type, due to the fact that the user has to allow the document to communicate with a website

Image 5 1024x713

To conclude, keep in mind that in the succeed attempts, you will see the users who do more that just open the attachment 😉

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top