Defender Attack Simulation SOP

Created by Liam Davids, Modified on Mon, 3 Jun, 2024 at 2:05 PM by Liam Davids


Attack simulation training enables organizations to measure and manage social engineering risk by allowing the creation and management of phishing simulations that are powered by real-world, harmless phishing payloads. Hyper-targeted training, helps improve knowledge and change employee behaviour.

To create a simulation automation, do the following steps:

  • Open the defender portal and click on Attack and Simulation training.

A screenshot of a computer

Description automatically generated

  • Click on SimulationsA screenshot of a computer

Description automatically generated

 

  • Click Launch a Simulation

A screenshot of a computer

Description automatically generated

  • Select the technique you require for the simulation depending on the requirement. 
  • Give it a name and description for reference purposes.

A screenshot of a web page

Description automatically generatedA screenshot of a computer

Description automatically generated

 

  • Select a payload for the simulation. This will be the content of the email received by the end user. Recommended that the payload selected be one that looks legitimate, so that user awareness is accurately gauged.

A screenshot of a computer

Description automatically generated

  • Select target users. This can either be an existing EntraID group, a department, or individuals.
  • Click on add users.

A screenshot of a computer

Description automatically generatedA screenshot of a computer

Description automatically generated

  • Assign training to users who fail the simulation. Recommended to use MS training experience, as the training assigned will be based on user’s previous simulation results and history.
  • Select the number of days by which training should be completed.

A screenshot of a computer

Description automatically generated

  • Select a landing page. This will be the page that opens if a user clicks on a link in the simulation email.

 

  • Select whether you require notifications/reminders to be sent to users who require training.

A screenshot of a screen

Description automatically generated

 

 

 

  • Select your language and preferred notification settings. Click on the preview icons to view what the notifications will look like.

A screenshot of a computer

Description automatically generated

  • Select to schedule or launch the simulation immediately.

A screenshot of a computer

Description automatically generated

  • Click Send a test button to test the operation of the simulation. The logged in user will receive the test. Click on submit if the test is received as expected.

 

  • Once submitted, click on the simulation to view the results. The results include whether the email has been delivered, opened, link clicked, training completed etc. This is useful as risky user’s can be identified and appropriate training assigned or provided to them. 

A screenshot of a computer

Description automatically generated

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article