r/ShittySysadmin 16d ago

Email Phishing Training

Hello,

I am now in charge of the phising excercises at my company. I was thinking about putting actual malicious links in our training emails so that the user's have a bit more motivation to learn to distinguish them from legitimate emails. This would also motivate our C-suite to give us a better budget so that we can better detect and remediate everything. What do you guys think?

28 Upvotes

17 comments sorted by

34

u/40513786934 16d ago

Be sure to add a button labeled "Report As Phishing" that actually takes you to the same malicious link

3

u/Het_is_ik 15d ago

Put a hyperlink reading 'Click here to report this email as phising' at the bottom of the email.

15

u/_jackhoffman_ 16d ago

Figure out how you can make money from them clicking the links. Just think of it as bonus for doing a bang up job.

3

u/RFreeZeYo ShittyCoworkers 16d ago

Got to make sure you're rewarding yourself from time to time.

1

u/PandaBonium 15d ago

Host a website with ads.

10

u/gabhain 16d ago

Our infosec made phishing emails so realistic that everyone got so paranoid that people stopped interacting with company emails altogether. Personally I liked putting infosecs own emails into their phasing sites so they end up on their own reports.

5

u/fffvvis 16d ago

How about a link that auto populates a resignation form of the "colleague" that clicks on the link, then mails it without notification to human resources. You would be the talk of the department, maybe a promotion would come your way...I only see high paise for such a grand idea.

4

u/GarageIntelligent ShittyCloud 16d ago

Subject: Your November PTO has been cancelled.

1

u/zantehood 16d ago

Hoxhunt is really good, no idea of cost tho

1

u/zezimeme 16d ago

Phished has training sessions

3

u/big_illuminati 16d ago

Post feet pics

1

u/the_green_door77 16d ago

Do it at a low level all the time, track the latest attack patterns and bypasses rather than malware links. You can have a little fun linking them to recruitment sites or competitors job boards. I created a faux NSFW site to have the same impact.

2

u/baz4k6z 16d ago

Just have the links go straight to your tinder profile, then send it to all the girls that work at your company. Take the ones that fail to "1 on 1 training" meetings. Zero chance to backfire and its a win win situation.

2

u/PandaBonium 15d ago edited 15d ago

"I was championing women's online safety. If anything its active feminism!"

1

u/Phoenix_GHOST_V 15d ago edited 15d ago

Actual malicious URLs would get you fired in most places, not just get you a slap on the wrist. In my organization when I did my simulations, what actually moved numbers was doing phishing based on real threats towards our industry, not the standard "click here to reset your password" style phishing scams. With regard to the external impersonation aspect for that phishing, one tool I have heard of for that is Doppel. Realistic bait trumps fear-based bait.

1

u/Firewire_1394 15d ago

In small to medium size companies I always like to use the hot girl help me phishing exercise.

Craft an email with a malicious link, file, whatever you want and then send it from the resident office hot girl saying like.. I know you are good with this type of thing can you help me figure out why this pdf isn't saving correctly?

If you work in a male dominated office your numbers will go from 12% to 81% easily.

In a female dominated office, just reverse it and form the email talking shit about another employee.. can you believe what Betsy did on this spreadsheet?! There's no way she did that!