Microsoft has recently add a new feature to Attack Simulator :
- Advanced reporting capabilities. The ability to see data such as the fastest (or slowest) time to open an attack simulation email message, the fastest (or slowest) time to click a link in the message, and more visualizations.
Even if Microsoft does not announce yet a new feature, we can see it in our tenant :
- Attachment payload phishing simulation. The ability to use an attachment as the payload for phishing simulation in place of a URL.
![Attack Simulator - new phishing simulation feature [EN] 2019 12 10 22 46 36 1024x192](https://thibaultchatiron.fr/wp-content/uploads/2019/12/2019-12-10_22-46-36-1024x192.jpg)
It is quite the same configuration that the Credentials Harvest simulation
Launch the attack
For the test, I will just use a template
![Attack Simulator - new phishing simulation feature [EN] 2019 12 10 22 51 49 1024x340](https://thibaultchatiron.fr/wp-content/uploads/2019/12/2019-12-10_22-51-49-1024x340.jpg)
You will have to select people to send phishing email to
Then, provide email details
As you can see below, the new configuration is related to Attachment type and name :
![Attack Simulator - new phishing simulation feature [EN] Image 1024x560](https://thibaultchatiron.fr/wp-content/uploads/2019/12/image-1024x560.png)
You will be able to choose one of three types :
- DOC
- DOCX
You will be able to compose the email body as you used to
![Attack Simulator - new phishing simulation feature [EN] Image 1 1024x393](https://thibaultchatiron.fr/wp-content/uploads/2019/12/image-1-1024x393.png)
So, what about the user ?
The target receive the email with the attachment
![Attack Simulator - new phishing simulation feature [EN] Image 2 1024x382](https://thibaultchatiron.fr/wp-content/uploads/2019/12/image-2-1024x382.png)
Result
Report
As an admin, you want to know if your victims open the attachment or not.
See below an example of report that you will be able to have during your campaings
![Attack Simulator - new phishing simulation feature [EN] Image 3 1024x574](https://thibaultchatiron.fr/wp-content/uploads/2019/12/image-3-1024x574.png)
Explanation
I used OWA to check the mails and thus, I opened the documentation in the browser.
Attack simulator do not see that
So, I click on download in order to open the documentation.
I have to also “Enable the modification” for Attack Simulator refresh the attack details
![Attack Simulator - new phishing simulation feature [EN] Image 4 1024x453](https://thibaultchatiron.fr/wp-content/uploads/2019/12/image-4-1024x453.png)
Quite the same for PDF as an attachement type, due to the fact that the user has to allow the document to communicate with a website
![Attack Simulator - new phishing simulation feature [EN] Image 5 1024x713](https://thibaultchatiron.fr/wp-content/uploads/2019/12/image-5-1024x713.png)
To conclude, keep in mind that in the succeed attempts, you will see the users who do more that just open the attachment 😉