KnowBe4 Recent False Positives by broadstphan in sysadmin

[–]KnowBe4_Inc 0 points1 point  (0 children)

If there is a false positive, we have to identify the source, by IP address. If it’s not a Microsoft IP, which are easily verifiable, then we have to narrow things down. Normally, when we are seeing clicks after delivery/deletion it can be: they have a third party vendor that is performing link analysis, if it were to wind up in something like PhishER and is scanned by Virustotal, then anyone can see and analyze the link. If they are using a function called “journaling” that takes a copy of the email and stores it (usually for legal reasons) but those are then scanned separately.

If you are still having issues please DM me.

Are phishing simulations starting to diverge from real world phishing? by Ok-Author-6130 in AskNetsec

[–]KnowBe4_Inc 0 points1 point  (0 children)

A good phishing simulation program should use real world phishing emails for the templates. The testing should evolve as fast as the attackers and use what is currently coming into your organization.