-
公开(公告)号:US20240236098A1
公开(公告)日:2024-07-11
申请号:US18533517
申请日:2023-12-08
申请人: KnowBe4, Inc.
发明人: Anand Dinkar Bodke , Eric Howes , Mark William Patton , Greg Kras , Christopher Cline , Brandon Scott Smith , Steffan Perry
IPC分类号: H04L9/40
CPC分类号: H04L63/101
摘要: Described herein are systems and methods to provide for blocklist recommendations based on reported threats. In an example embodiment, a method is described for receiving a selection of one or more messages from a plurality of messages identified as threats and identifying, based at least on the one or more messages, one or more candidate blocklist entries (BLEs). The method further includes determining, based at least on the one or more candidate BLEs, a recommendation of one or more BLEs to add to a blocklist. The method includes adding, by the one or more servers, the one or more BLEs to the blocklist, where the blocklist is used by an email system to block messages that match at least the one or more BLEs on the blocklist.
-
公开(公告)号:US12019741B2
公开(公告)日:2024-06-25
申请号:US17986856
申请日:2022-11-14
申请人: KnowBe4, Inc.
发明人: Greg Kras , Adam Alessandrini
CPC分类号: G06F21/552 , G09B19/0053 , H04L51/08 , H04L63/1483
摘要: Systems and methods are described for providing customized message content to be displayed to a user of an email client, responsive to the user selecting, via a plug-in or agent of the email client, to report an email as a potential phishing email. In examples, the user may be an employee of an organization and the systems and methods may facilitate a determination by the plug-in or agent of the email client that the reported email is one that does not pose a security risk, such as a simulated phishing email sent by the organization itself, or an email sent from a trusted partner of the organization. The systems and methods may facilitate a customization of the message content that is displayed to the user. In examples, the customized message content may be included or specified within one or more SMTP extension headers of an SMTP email.
-
公开(公告)号:US11943253B2
公开(公告)日:2024-03-26
申请号:US17986861
申请日:2022-11-14
申请人: KnowBe4, Inc.
发明人: Greg Kras , Chris Cline
IPC分类号: H04L9/40
CPC分类号: H04L63/1433 , H04L63/1483
摘要: Systems and methods are described for using secured groups for simulated phishing campaigns to obfuscate data for levels of privacy based on protected criteria classes. Initially, a group to resolve members of the group based on multiple users matching one or more group criteria is established. It is then determined that at least one criteria of the one or more criteria has been configured as one of multiple protected criteria classes. Responsive to the determination, the group is identified as a secured group. A query of the group is then executed to identify one or more users of the multiple users as members of the group based on the users matching the criteria of the secured group at the time of execution of the group and information of the one or more users resulting from the execution of the secured group is obfuscated in accordance with the protected criteria class.
-
公开(公告)号:US11856025B2
公开(公告)日:2023-12-26
申请号:US17888415
申请日:2022-08-15
申请人: KnowBe4, Inc.
发明人: Greg Kras
IPC分类号: H04L9/40 , H04L51/08 , H04L67/306 , H04L51/42 , H04L51/212 , H04L51/216
CPC分类号: H04L63/1483 , H04L51/08 , H04L51/212 , H04L51/216 , H04L51/42 , H04L63/1416 , H04L63/1433 , H04L67/306
摘要: Systems and methods are disclosed for simulating a phishing attack involving an email thread. An email thread of a plurality of email threads of an entity for use in a simulated phishing attack is identified. A simulation system generates a converted reply simulated phishing email to an email of the email thread. The converted reply simulated phishing email is generated to be from a user that is one of a recipient or a sender of one or more emails of the email thread and is communicated to a target user's email account, the converted reply simulated phishing email.
-
公开(公告)号:US20230308471A1
公开(公告)日:2023-09-28
申请号:US18113179
申请日:2023-02-23
申请人: KnowBe4, Inc.
发明人: Greg Kras
IPC分类号: H04L9/40
CPC分类号: H04L63/1433 , H04L63/1483
摘要: Systems and methods are provided for determining template difficulty based on user security maturity. In an example, a method includes communicating one or more simulated phishing communications to a plurality of users. Each of the users are assigned a user security maturity level of a plurality of user security maturity levels. The one or more simulated phishing communications are generated using a simulated phishing template. The method includes recording the user security maturity level of a user and a type of user interaction for each of the responses to the one or more simulated phishing communications from the users and determining, a failure rate of the simulated phishing template at each user security maturity level of the plurality of user security maturity levels based on the type of user interaction for each of the responses from one or more users assigned to each user security maturity level.
-
公开(公告)号:US11729206B2
公开(公告)日:2023-08-15
申请号:US18094632
申请日:2023-01-09
申请人: KnowBe4, Inc.
发明人: Mark William Patton , Daniel Cormier , Greg Kras
IPC分类号: H04L9/40
CPC分类号: H04L63/1433 , H04L63/1483
摘要: Systems and methods are described for verifying whether simulated phishing communications are allowed to pass by a security system of an email system to email account of users. One or more email accounts of the email system with the security system may be identified to use for a delivery verification campaign. Further, one or more types of simulated phishing communications may be selected from a plurality of types of simulated phishing communications. The delivery verification campaign may be configured to include the selection of the one or more types of simulated phishing communications from the plurality of types of simulated phishing communications. The selected one or more types of simulated phishing communications of the delivery verification campaign may be communicated to the one or more email accounts. Further, whether or not each of the one or more types of simulated phishing communications was allowed by the security system to be received unchanged at the one or more email accounts.
-
7.
公开(公告)号:US20230224328A1
公开(公告)日:2023-07-13
申请号:US18117664
申请日:2023-03-06
申请人: KnowBe4, Inc.
发明人: Alin Irimie , Greg Kras , David Austin , Benjamin Dalton
IPC分类号: H04L9/40 , G06F40/186 , H04L51/18 , H04L51/52
CPC分类号: H04L63/1483 , H04L63/1433 , G06F40/186 , H04L51/18 , H04L51/52
摘要: Systems and methods are provided for performing simulated phishing attacks using social engineering indicators. One or more failure indicators can be configured in a phishing email template, and each failure indicator can be assigned a description about that failure indicator through use of a markup tag. The phishing email template containing the markup tags corresponding to the failure indicators can be stored and can be used to generate a simulated phishing email in which the one or more markup tags are removed.
-
公开(公告)号:US20230222411A1
公开(公告)日:2023-07-13
申请号:US18116404
申请日:2023-03-02
申请人: KNOWBE4, INC.
发明人: Greg Kras , Alin Irimie , Perry Carpenter , Suzanne Gorman
CPC分类号: G06Q10/06314 , H04L63/1483
摘要: Methods, systems and apparatus for implementing a security awareness program are provided which allow a device of a security awareness system to receive attributes of an implementation of a security awareness program from an entity, such as a company. Responsive to the attributes, the device determines a configuration for each of a baseline simulated phishing campaign, electronic based training of users of the entity for security awareness and one or more subsequent simulated phishing campaigns. The device initiates execution of the baseline simulated phishing campaign to identify a percentage of users of the entity that are phish-prone.
-
公开(公告)号:US11641375B2
公开(公告)日:2023-05-02
申请号:US17233269
申请日:2021-04-16
申请人: KnowBe4, Inc.
发明人: Greg Kras , Alin Irimie
IPC分类号: H04L9/40 , H04L51/046 , H04L51/42 , H04L51/212 , G09B19/00
摘要: Systems and methods are described for leveraging the knowledge and security awareness of well-informed users in an organization to protect other users and train them to identify new phishing attacks. Initially, a report of a message being suspicious may be identified and it may be determined whether message is a malicious phishing message. In an example, a well-informed user of an organization may report the message as suspicious. Further, on determining the message to be a malicious phishing message, a simulated phishing message or a template may be created. The simulated phishing message may then be communicated to one or more devices of one or more users.
-
公开(公告)号:US20230012756A1
公开(公告)日:2023-01-19
申请号:US17953195
申请日:2022-09-26
申请人: KnowBe4, Inc.
发明人: Greg Kras
IPC分类号: H04L9/40
摘要: Systems and methods are described for using a template for simulated phishing campaigns based on predetermined date from a date associated with a user. The predetermined date may by an event, an anniversary or a milestone associated with employment of the user with a company. The campaign controller may identify a date associated with the user and based on the identification of the date associated with the user, the campaign controller may select one or more templates for one or more simulated phishing campaigns to be triggered by a predetermined date related to the date associated with the user.
-
-
-
-
-
-
-
-
-