patented
Spear-Phishing-Engine

Patented technology for authentic spear phishing simulations

The patented spear phishing engine is an unique technology to automatically generate company-, department- and employee-specific phishing scenarios. Publicly available data from social networks and other media is used for the phishing content (OSINT).

IT-Seal Team

USING OSINT TECHNOLOGY FOR PHISHING SIMULATIONS

The basis for our patented spear phishing engine is an OSINT analysis. OSINT stands for Open Source Intelligence and means combing through publicly available information for usable data. For example, profiles of your employees on social networks or your company profile on employer rating sites are analyzed.

This collected data can be used for a attack potential analysis that shows how vulnerable your organization is to publicly available information.

Mainly, the spear phishing engine uses the collected OSINT data for realistic spear phishing simulations: Like a real attacker, it uses individual information of your employees:inside to create fully automated spear phishing emails. These are harmless to your workforce, but effectively teach them how to recognize real phishing emails. In parallel, you can monitor the IT security behavior of your employees live in your dashboard.

The advantages

Effective training of your employees

A common mistake many people make is to assume that they themselves will not fall victim to cyberattacks or that attackers have no interest in attacking them. But this apparent security is deceptive!

Today's phishing emails are becoming more and more sophisticated: based on personal information, deceptively real emails are created that can hardly be identified as phishing. Phishing simulation of the same quality makes it clear to employees that anyone can fall for phishing if they are not vigilant. They are effectively trained to recognize and ward off phishing attacks.

 

Employee and Company OSINT

IT-Seal's spear phishing engine uses publicly available information to create targeted and authentic phishing emails. To do this, it uses information about individual colleagues to create highly individualized content. This data is researched, for example, in professional networks such as LinkedIn and Xing.

In addition, the Spear Phishing Engine can also use cross-company information and thus also create targeted spear phishing emails. This information comes from company rating portals such as Kununu. Information used can be, for example, a canteen, company sports or company benefits.

In general, we have built up a huge pool of different phishing scenarios over the years, which we regularly expand.

Determine phishing intensity yourself

With IT-Seal's spear phishing engine, you retain full control over the intensity of phishing emails for your employees at all times. Both short-term throttling of the intensity level and long-term interruption can be implemented quickly and easily. 

Your personal awareness consultant will be happy to advise you and set up the phishing campaign according to your company and employee needs.

Individual explanation page for maximum learning effect

If a colleague receives a phishing simulation from IT-Seal and opens a link or file attachment or enters login data on fake pages, he is redirected to the IT-Seal explanation page.

The example of the opened e-mail shows specifically how he could have recognized the phishing attempt. In this moment of misconduct, the employees are particularly receptive to a sustainable explanation: The so-called "Most Teachable Moment" can fully unfold its learning effect. Frequently used psychological tricks (curiosity, fear, habit, ...) are also explained.

Focus on employees and data privacy

Employees and data privacy are always at the forefront of IT-Seal's phishing campaigns, which is why the results are always evaluated on a group basis and anonymously. By department, hierarchy or region – decide for yourself which groups you want to compare.

gdpr compliant
YouTube

By downloading the video you accept the YouTube privacy policy.
Learn more

Load video

PGlmcmFtZSB0aXRsZT0iRGVyIEVtcGxveWVlIFNlY3VyaXR5IEluZGV4IChFU0nCrik6IFNlY3VyaXR5IEF3YXJlbmVzcyBtZXNzZW4iIHdpZHRoPSI4MDAiIGhlaWdodD0iNDUwIiBzcmM9Imh0dHBzOi8vd3d3LnlvdXR1YmUtbm9jb29raWUuY29tL2VtYmVkL2JaUjkwRVRlaXlFP2ZlYXR1cmU9b2VtYmVkIiBmcmFtZWJvcmRlcj0iMCIgYWxsb3c9ImFjY2VsZXJvbWV0ZXI7IGF1dG9wbGF5OyBjbGlwYm9hcmQtd3JpdGU7IGVuY3J5cHRlZC1tZWRpYTsgZ3lyb3Njb3BlOyBwaWN0dXJlLWluLXBpY3R1cmUiIGFsbG93ZnVsbHNjcmVlbj48L2lmcmFtZT4=

Monitoring of the training success with the Employee Security Index (ESI®)

To measure the success of your phishing campaign with IT-Seal, we have developed the Employee Security Index, or ESI® for short. This standardized indicator enables you to regularly monitor the development of IT security awareness in your company and to compare departments with each other as well as to check the development over time.

Thus, there is transparency about the progress of your employees and the security culture of your company.

Interested in contacting us?



    I want to stay in touch and am interested in receiving occasional updates from IT-Seal (bi-monthly newsletter).



    Test us without obligation: