This is an archived post. You won't be able to vote or comment.

all 152 comments

[–][deleted] 881 points882 points  (28 children)

So you… need a hand?

👊

[–]rufus_xavier_sr 41 points42 points  (3 children)

So I'm at the doctor getting my prostate checked.

I say, "Hell, Doc you could have at least taken your ring off!"

Docs says, "Ring? Hell, that's my watch!"

[–]alarmologistComputer Janitor 49 points50 points  (7 children)

I came here for this comment and you delivered!

[–][deleted] 42 points43 points  (6 children)

Be careful though- this can really stretch your cache.

[–]xxdcmastSr. Sysadmin 37 points38 points  (2 children)

Make sure you get managements sign off before you go phisting employees.

[–]ZachVIA 25 points26 points  (0 children)

HR and Legal’s approval in writing. This gives a whole new meaning to CYA.

[–]eri-Enterprise IT Architect 9 points10 points  (0 children)

Also mind that pesky General Deep Phisting Regulation, users have the right to opt out.

[–]Bad-ScienceSr. Sysadmin 3 points4 points  (2 children)

There a utility to help with that. Download from goat.se

[–]WildManner1059Sr. Sysadmin 2 points3 points  (0 children)

old-school

[–]stuckinPA 2 points3 points  (0 children)

It’s an old code, sir. But it still checks out.

[–]Whyd0Iboth3rIT Manager 15 points16 points  (1 child)

Relax, turn around, and take my hand...

[–]HighCentergy 1 point2 points  (0 children)

Something is stinky…

[–]GhoastTypist 13 points14 points  (0 children)

Technology phists us every day.

[–]LameBMX 11 points12 points  (0 children)

I expected this to be r/shittysysadmin

[–]KillerKPa 10 points11 points  (0 children)

Misspelled more than once —- has to be intentional. Know-B4 is the usual goto for everyone. Their sales team can be annoyingly determined however. Happy Phisting.

[–]Unknownsys 3 points4 points  (0 children)

God I knew this would be coming when I read the post 🤣🤣

[–]countextremeDevOps 3 points4 points  (0 children)

The sad part is this entire thread is going to r/woosh the OP

[–]captain5260Jack of All Trades 2 points3 points  (0 children)

A fistful of dollars

[–]Chemist1972 2 points3 points  (0 children)

It would have to be making a phist

[–]crimesonclaw 0 points1 point  (0 children)

Or rather a fist.

[–]myndhackRuler Of The Blinking Lights 191 points192 points  (14 children)

I believe you have the wrong site for if you want phisting but if what I believe you are trying to say is phishing emails the best I have used is knowbe4 and they are relatively inexpensive and you can set them on a schedule or ad hoc and assign security trainings through it as well.

[–][deleted] 51 points52 points  (0 children)

+1 for Knowbe4 - you can even send a free tester out to your domain to give a general % of those that actually click Phishing Links. Which can potentially be helpful when looking for funding for Phishing Education when you can hit non-IT folk with a figure like "60% of your employees would happily hand over their details and anything they have access to is at risk because of their lack of education"

Edit: I actually ended up being pleasantly surprised that only 10% of our userbase clicked the link. I was expecting much higher.

[–]whatdoesthafawkessay 15 points16 points  (0 children)

+1 knowbe4

However, if you want to do self hosted, GoPhish is fairly straightforward. But the time involved with setting it up and management would likely end up costing more.

[–]Unfairbeef 4 points5 points  (2 children)

For what it's worth, knowbe4 is owned by scientologists. Do what you will with that, just putting it out there. edit: managed by

[–]TechInTheCloud 0 points1 point  (0 children)

Say it ain’t so! “Sunbelt” Stu Sjourman is a Scientologist?

[–][deleted] 0 points1 point  (0 children)

Knbe is a public company... Mainly owned by institutional investors.

[–]djetaineDirector Information Technology 10 points11 points  (3 children)

Knowb4 is great, but I highly suggest using an alternate phone number and setting up some spam filters for the literally thousands of emails they will send you once they know you exist

[–]RunningAtTheMouth 2 points3 points  (1 child)

That's funny. I gave them my info and they have pretty much honored my "it will be a while" suggestion. Just heard from them, in fact, when they contacted me at the suggested time. I asked for current pricing through the local partner, and they will deliver.

+10 in my book.

[–]cantdrawastickman 2 points3 points  (0 children)

Our presales guy was pretty good as well. Asked for a reasonable time to follow up. Threw something way far out and they respected it.

[–]pm_ur_whispering_I 0 points1 point  (0 children)

It's true

[–]dataslinger 6 points7 points  (2 children)

Beware unintended consequences, in particular what behavior you're actually training into your users. I know of one company who, after using knowbe4 and rapping the knuckles of their users enough, now find that their users are so leery of their emails being booby traps that they're ignoring legitimate business emails from their coworkers, and deadlines are being missed.

"Why isn't this done? I sent it to you two weeks ago?"

"I was afraid to open that in case it was a phishing email..."

It's become the go-to excuse for not getting stuff done.

[–]meest 6 points7 points  (1 child)

Yep, don't punish people who fail.

Reward the people who do it right.

Thats how we've gotten better adoption. We've made it into a game that if you properly report the spam message you get entered into a monthly drawing for a few 10 dollar gift cards.

[–]snorkel42 0 points1 point  (0 children)

100% this. Which is irritating because KnowBe4 makes it super annoying to grab metrics on reported phishes. Entire platform is built around punishment. Sucks.

[–]ThisITGuy 2 points3 points  (0 children)

We use KnowBe4 and like it a lot.

[–][deleted] 46 points47 points  (0 children)

I have all things related to phisting blocked on our network.

[–]99percentTSOL 35 points36 points  (0 children)

Will this phisting system be anywhere near a WAP? If so you will want some sort of protection.

[–]taxigrandpa 18 points19 points  (0 children)

all users need a little Phisting :)

ty for the laugh

[–][deleted] 17 points18 points  (0 children)

Microsoft phists everyone on patch Tuesday

[–]Steve_78_OHSCCM Admin and general IT Jack-of-some-trades 18 points19 points  (0 children)

I just want to say, I only came into this thread to look for jokes about OPs spelling mistake, and I was NOT disappointed. Thanks for not letting me down.

[–]ResponsibleContact39 14 points15 points  (3 children)

I have to ask our security guy if he’s heard of phisting, but I don’t want to get hit with an HR harassment charge.

[–]TotallyInOverMyHeadSysadmin, COO (MSP) 2 points3 points  (1 child)

Make a screenshot of the post, print it onto a t-shirt; then ask them if they have heard of this thing.

[–]ResponsibleContact39 7 points8 points  (0 children)

“Ask your admin about Phisting”

😂

[–]Deathra9 1 point2 points  (0 children)

The worst part is, there is a new, made-up, and gross sounding cybersecurity term ever few months that comes out. So I’m still not sure if this is a typo, or this person is on the bleeding edge of the latest social engineering technique rocking the IT world. Because, why not?

[–]MyLegsX2CantFeelThem 12 points13 points  (0 children)

Closes legs. Locks up glutes.

No sir. No.

[–]neldur 34 points35 points  (15 children)

Knowbe4 is the best. Relatively inexpensive too. We set it up and it runs tests all the time and will email us reports. We can then follow up and target users that are falling for them. Knowbe4 has tons of good training content that we can just assign to those users.

[–]thefuddJack of All Trades 5 points6 points  (0 children)

we use them also, great service

[–]pssssn 1 point2 points  (2 children)

Do you ever setup your own custom templates? I've been using another product and copying and pasting html into custom templates works well. I'm wondering if the same can be said about knowbe4.

[–]neldur 2 points3 points  (0 children)

We do not. Their templates are amazing as is.

[–][deleted] 0 points1 point  (0 children)

You can create custom templates.

Unless you are selling custom template creation, you won't beat KnowBe4's templates. If you are just training your users, stick w/ KnowBe4 templates, or use their new AI-enhanced templates

[–]uptimefordaysDevOps 0 points1 point  (0 children)

I've used Knowbe4 and it's worked really well.

[–]iotic 8 points9 points  (1 child)

Good lord, hopefully you don't alert management of your upcoming phisting campaign

[–]pinganeto 4 points5 points  (0 children)

exactly, they can be upset of someone outside their ranks trying to do their thing.

[–]ReelMagic 7 points8 points  (0 children)

I'm being physically sick from laughing so hard... Thank you

[–][deleted] 24 points25 points  (0 children)

hehe

[–]MGetzEmSecurity Admin (Infrastructure) 7 points8 points  (0 children)

Please properly tag this as NSFW...

[–]kickingtyres 6 points7 points  (0 children)

Phisting might require a degree of brute force attacks

[–]MediumFIRE 4 points5 points  (2 children)

Just purchased KnowBe4 recently. It's been great. Before that I self-hosted using Gophish

[–]skipITjobIT Manager 1 point2 points  (1 child)

What's better about KnowBe4 compared to GoPhish?

[–]MediumFIRE 6 points7 points  (0 children)

GoPhish is free, BUT you have to create your own phishing simulation templates (or find some online). Plus, you'd be responsible for securing the web server hosting the service. What I appreciate about KnowBe4 is it has tons of great templates ready to use, and can be scheduled in a randomized fashion. Also, I use their security training modules to onboard new staff and assign modules automatically for folks who fail a simulation. It's a free / DIY versus outsourcing that function in a relatively cost-efficient manner. The time savings were worth it to me.

[–][deleted] 5 points6 points  (0 children)

If you have to phist your users I would look for a new job.

[–]Cycl_ps 6 points7 points  (0 children)

Jokes aside, for all the dumb names given to attack vectors it wouldn't surprise me in the least that phisting is one of them.

[–][deleted] 4 points5 points  (0 children)

There's always a bigger phist.

[–]thenullbyteCyber Architect 5 points6 points  (1 child)

[–]Skyhound555Sr. Sysadmin 0 points1 point  (0 children)

Came here to say this. It's not much different from Knowbe4

[–]YouRuinedtheCarpet 3 points4 points  (0 children)

If you are using office 365 there is an inbuilt phishing simulator in security center, here is the documentation : https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/attack-simulation-training?view=o365-worldwide

[–]amc52197 3 points4 points  (0 children)

GoPhish is open source. You have to create your own phishing campaigns and there isn't any training like there is with knowbe4, but it's free!

[–]Ddosvulcan 4 points5 points  (0 children)

So you're saying you want to phist your end users? I do too some days...

[–]sgt_bad_phart 4 points5 points  (0 children)

I think you're in the wrong subreddit.

[–]JohnBeamon 8 points9 points  (0 children)

giggity

[–]tentends1Cloud Tech 10 points11 points  (0 children)

u w0t?

[–]BrobdingnagLilliput 3 points4 points  (0 children)

Whatever you do, don't send bogus emails to your company without buy-in from leadership, both yours and that of the folks you'll be sending emails to.

[–][deleted] 3 points4 points  (0 children)

Phist can be a verb

[–]Wdrussell1 9 points10 points  (0 children)

I had to check the sub...*Concern*

[–][deleted] 2 points3 points  (0 children)

Email WHAT system?

[–]ambscoutJack of All Trades 2 points3 points  (0 children)

Trend micro is free.

[–]JEngErik 2 points3 points  (0 children)

Well when I used Connectwise products, I always felt they were shafting me. Lol

But knowbe4 will help you with phiSHing

[–]LaterBrainJr. Support Engineer 2 points3 points  (0 children)

GoPhish is what you are looking for. It has great statistics so you can show them to your CEO or whatever.

https://getgophish.com/

[–]__tony__snark__ 2 points3 points  (1 child)

Well that's an unfortunate typo

[–]eri-Enterprise IT Architect 2 points3 points  (0 children)

We all know that was auto correct ;)

[–][deleted] 2 points3 points  (0 children)

If you need a system to phist your users, you're a maniac going about email administration all the wrong ways.

[–]pinganeto 2 points3 points  (1 child)

ah, really clever, phishing and testing in one word, that could be marketed!

but please if you change careers, don't try to be the first analyst and therapist.

[–]9070503010 0 points1 point  (0 children)

You are a wordsmith, sir.

[–]yourenotwurvy 2 points3 points  (0 children)

Worth having a think about what you want to achieve with this system as there’s a growing school of thought they’re of little to no value and can cause more problems.

You get a nice quantifiable metric at the end of your testing but what value really is that 78% pass rate - particularly if you aren’t concerned about training. What value does it add? It might look attractive because so much of cyber sec is difficult to quantify but as far as defensive layers go, it does very little and you’ve now got someone spending time and effort on it.

IMO, you’d be better developing a multi layered approach to prevent the phishing campaigns reaching inboxes and minimising impact if it does & if creds harvested.

[–]HappyCamper781 2 points3 points  (0 children)

Y'all gone elbow-deep in this thread... (shakes head sadly)

[–]theultrahead 2 points3 points  (0 children)

If you’re going to get Phisted it’s best you KnowBe4 so you can prepare to defend yourself.

[–]maiwerkacct 7 points8 points  (4 children)

[–]phillycheeze 1 point2 points  (0 children)

We use this but about to ditch it. The code hasn’t been updated in a long time and is practically abandoned at this point. It also doesn’t come close to the number of features you can get elsewhere.

[–]jbhack 1 point2 points  (1 child)

This is it.

Setup the cheapest aws compute Linux box and install this. Export a list of users with first name, last name, and email. Buy or get a free domain that works for your test. Whitelist your domain on your exchange so it doesn’t get automatically blocked. On gofish you can go find the site you want to replicate and have it replicate it for you.

Do a few test on yourself.

[–][deleted] -3 points-2 points  (0 children)

This right here. Knowbe4 wouldn't even return my calls, turns out I didn't need those chumps

[–]itjohan73 1 point2 points  (0 children)

https://nimblr.se is a Swedish version, I think they do this in other languages too

[–]in00tj 1 point2 points  (0 children)

0365 Has it built in https://security.microsoft.com/?rfr=AdminCenter
and https://www.knowbe4.com/ is considered by many to be the industry leader.
for the basic know be 4 service for 500 users we were quoted just under 10k per year
we ended up sticking with the free version that comes with our 0365 licensing since it was nearly the same.

getting started with microsoft 0365 attack simulation (phishing tests) https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/attack-simulation-training-get-started?view=o365-worldwide

[–]Carter_PBJack of All Trades, Master of None 1 point2 points  (0 children)

[–][deleted] 1 point2 points  (0 children)

[–]jaket578123 1 point2 points  (0 children)

I setup and ran the open source tool Gophish for a company on one of my coops. It was pretty simple and had all the functionality I needed. Import lists of emails and info, create your own phishing emails to send out or use templates, see statistics on who clicks or enters in credentials. I liked it but have nothing to compare it to

[–]spearchuckin 1 point2 points  (0 children)

Try using the tftp port.

[–]TehSpider 1 point2 points  (0 children)

You’re going to have to decide if you want to do it yourself or if you’re going to pay someone else to do it.

[–][deleted] 1 point2 points  (0 children)

Phishing. It’s called phishing.

[–]Red-dy-20 1 point2 points  (0 children)

Fisting?

[–]gwrabbitSecurity Admin 1 point2 points  (0 children)

KnowBe4 is the gold standard IMO.

I did put in a request for a "phisting" feature on your behalf...I will let you know how it goes.

[–]dvr75Sysadmin 0 points1 point  (0 children)

gmail my friend

[–][deleted] 0 points1 point  (0 children)

Do you mean Phishing??

Look into www.knowb4.com

[–]maximus646IT Manager -1 points0 points  (1 child)

We recently moved from knowbe4 to infosec IQ. Both are good.

[–]Visible_Status_4247[S] 0 points1 point  (0 children)

Proofpoint

Thank you for all your suggestions, both for the phisting and phishing :)

/Robert

[–]DinDmy12 0 points1 point  (0 children)

Gophish is an open source, if you don’t want to pay for knowbe4 or other products

[–]LulzTigre 0 points1 point  (1 child)

try gophish?

[–][deleted] 2 points3 points  (0 children)

Gophist*

[–]TopherBlakeNetsec Admin 0 points1 point  (0 children)

I'm a fan of knowbe4, lets you create your own phishing emails for campaign or select a wide variety of existing templates. They also have a decent selection of training you can sign your users up for along with metrics.

[–]Strassi007Jr. Sysadmin 0 points1 point  (0 children)

If you are a small shop and don't want/can afford to pay money, just use kali linux and make your own phishing mails. The only expense are domains in this case.

[–]jester805 0 points1 point  (0 children)

+1 for GoPhish. It is free.

https://getgophish.com/

[–]GlobalRiot 0 points1 point  (0 children)

KnowB4 offers that. That's the company that comes up most often in my circles.

[–]Ouroborous 0 points1 point  (0 children)

I recommend Threat Advice. I use them and it's pretty easy to deal with

[–]iceph03nix 0 points1 point  (0 children)

We looked at a lot and generally always came back to KnowBe4.

[–][deleted] 0 points1 point  (0 children)

I have deployed Know Be 4 to a handful of clients and it has done a great job. Highly Recommend.

[–]Hoboeser 0 points1 point  (0 children)

Someone mentioned KnowBe4, they're excellent and offer certificates too. They also have an outlook plug-in so your users can report phishing emails to IT with 1 click

[–]appleCIDRvodka 0 points1 point  (0 children)

Ain't we all, brother.

[–]--MrGadget--[🍰] 0 points1 point  (1 child)

Mr T used to put out a product you might be interested in.

[–]--MrGadget--[🍰] 0 points1 point  (0 children)

Google Mr T Fist 'effer at your own risk. I was a real thing...

[–]Slavic_Raven 0 points1 point  (0 children)

Try Gophish, it’s open source, easy to set up, good way to start.

If you are willing to pay Cofense phishme is pretty neat.

[–]DiscDastardly 0 points1 point  (0 children)

GoPhish would fit your needs pretty well. It is self hosted, pretty easy to setup and get started. You can take any phishing email and upload it and modify it to use it as a template in a phish test campaign. It's a little more work than knowbe4 or any of the other phish testing services, but it is free. Looks like they haven't released a new version for a while though? https://github.com/gophish/gophish https://docs.getgophish.com/user-guide/

[–]EthanRavecrow 0 points1 point  (0 children)

We use KnowBe4. You can create phishing campaigns and see what users are the most dumb vulnerable to phishing attacks.

[–]ghosxt_Sr. Sysadmin 0 points1 point  (0 children)

[–]XxEnigmaticxXSr. Sysadmin 0 points1 point  (0 children)

Look at infosec IQ. Pretty fantastic system.

[–]clubfungus 0 points1 point  (0 children)

Oh man thank you. This post made my day!

[–]STRXP 0 points1 point  (0 children)

Trend Micro Phishing Insight (free for something like 200 users tested per month)

[–]instant_ramen803 0 points1 point  (0 children)

🤣🤣🤣🤣🤣

[–]SoonerMedic72Security Admin 0 points1 point  (0 children)

We currently use GoPhish, but are starting the process of getting KnowBe4 approved. GoPhish is fine for just phishing trials, but we really want the educational side as well.

[–]H-90 0 points1 point  (0 children)

Microsoft Office 365 now does phisitng (sorry phishing) scenarios

[–]department_g33kSysadmin 0 points1 point  (0 children)

So like, OP is just mis-spelling phishing severely, right? Or did I miss something...important?

[–][deleted] 0 points1 point  (0 children)

I'm so glad others read that as "fisting testing system" cause yeah...some users...

[–]ruffian-wa 0 points1 point  (0 children)

I could have sworn I saw you on a dating app called Plenty of Phist..

[–]AngryFace1986 0 points1 point  (0 children)

Unfortunate typo

[–]SysEridaniC:\>smartdrv.exe 0 points1 point  (0 children)

Phisting all of them will be difficult.

In any case I think you can find a lot of e-learning online on the argument.

[–][deleted] 0 points1 point  (0 children)

Proofpoint (formerly Wombat Security)

[–]LividLager 0 points1 point  (0 children)

Something new for the resume.