Systems and methods for intelligent phishing threat detection and phishing threat remediation in a cyber security threat detection and mitigation platform
US-2024414198-A1 · Dec 12, 2024 · US
US10291649B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10291649-B2 |
| Application number | US-201715720566-A |
| Country | US |
| Kind code | B2 |
| Filing date | Sep 29, 2017 |
| Priority date | Jun 28, 2016 |
| Publication date | May 14, 2019 |
| Grant date | May 14, 2019 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Systems and methods for performing a simulated phishing attack are provided. A simulated attack server can send a simulated attack email including a unique identifier to a target. The simulated attack server can receive a reply email including the unique identifier from the target. The simulated attack server can extract the unique identifier from the reply email. The simulated attack server can determine a match between the unique identifier and an identity of the target. The simulated attack server can record a target failure, responsive to determining the match between the unique identifier and the identity of the target.
Opening claim text (preview).
What is claimed is: 1. A method for identifying users that reply to a simulated phishing email, the method comprising: (a) establishing, by one or more servers comprising one or more processors coupled to memory, a unique identifier for each user of a plurality of users identify each user separately from an email account from which each user replies to a simulated phishing email; (b) embedding, by the one or more servers, the unique identifier of a user in one of a body, a subject line or an attachment of a simulated phishing email to be communicated to that user, the simulated phishing email comprising an email address to be used in a to field of a reply email that corresponds to the one or more servers; (c) receiving, by the one or more servers, the reply email to the email address communicated responsive to the simulated phishing email being communicated to the email account of at least one user of the plurality of users, the reply email comprising the unique identifier and the reply email received from a second email account of the at least one user different from the email account to which the simulated phishing email was communicated; and (d) determining, by the one or more servers, that a user has replied to the simulated phishing email by identifying the unique identifier embedded in the reply email as the unique identifier established by the one or more servers for the user. 2. The method of claim 1 , wherein (a) further comprises establishing, by the one or more servers, the unique identifier to identify the user corresponding to one or more email accounts. 3. The method of claim 1 , wherein (b) further comprises embedding the unique identifier of the user in at least one of a subject line of the simulated phishing email, a body of the simulated phishing email or an attachment of the simulated phishing email. 4. The method of claim 1 , wherein (b) further comprises generating, by the one or more servers, the simulated phishing email to comprise the unique identifier of the user embedded in at least one of a subject line of the simulated phishing email, a body of the simulated phishing email or an attachment of the simulated phishing email. 5. The method of claim 1 , wherein (b) further comprises embedding the unique identifier of the user to be invisible in the body of the simulated phishing email. 6. The method of claim 1 , wherein (b) further comprises embedding the unique identifier of the user in a file name of the attachment. 7. The method of claim 1 , wherein (b) further comprises embedding the unique identifier of the user in content of the attachment. 8. The method of claim 1 , wherein (c) further comprises communicating, by the one or more servers, the simulated phishing email to an email account of each user of the plurality of users. 9. The method of claim 1 , wherein (d) further comprises receiving, by the one or more servers, the reply email sent to a domain of or a domain hosted by the one or more servers. 10. The method of claim 1 , wherein (d) further comprises comparing the unique identifier embedded in the reply email to the unique identifier established by the one or more servers for the user. 11. The method of claim 1 , wherein (d) further comprises identifying, by the one or more servers, the unique identifier embedded in in at least one of the subject line of the simulated phishing email, the body of the simulated phishing email or the attachment of the simulated phishing email. 12. A system for identifying users that reply to a simulated phishing email, the system comprising: one or more servers comprising one or more processors coupled to memory, and configured to establish a unique identifier for each user of a plurality of users to identify each user separately from an email account from which each user replies to a simulated phishing email; a campaign manager of the one or more servers configured to embed the unique identifier of a user in one of a body, a subject line or an attachment of a simulated phishing email to be communicated to that user, the simulated phishing email comprising an email address to be used in a to field of a reply email that corresponds to the one or more servers; and wherein the one or more servers are configured to receive the reply email to the email address communicated responsive to the simulated phishing email being communicated to the email account of at least one user of the plurality of users, the reply email comprising the unique identifier and the reply email received from a second email account of the at least one user different from the email account to which the simulated phishing email was communicated; and wherein the campaign manager is configured to determine a user has replied to the simulated phishing email by identifying the unique identifier embedded in the reply email as the unique identifier established by the one or more servers for the user. 13. The system of claim 12 , wherein the one or more servers are further configured to establish the unique identifier to identify the user corresponding to one or more email accounts. 14. The system of claim 12 , wherein the one or more servers are further configured to embed the unique identifier of the respective user in at least one of a subject line of the simulated phishing email, a body of the simulated phishing email or an attachment of the simulated phishing email. 15. The system of claim 12 , wherein the one or more servers are further configured to generate the simulated phishing email to comprise the unique identifier of the user embedded in at least one of a subject line of the simulated phishing email, a body of the simulated phishing email or an attachment of the simulated phishing email. 16. The system of claim 12 , wherein the one or more servers are further configured to embed the unique identifier of the user to be invisible in the body of the simulated phishing email. 17. The system of claim 12 , wherein the one or more servers are further configured to embed the unique identifier of the user in a file name of the attachment. 18. The system of claim 12 , wherein the one or more servers are further configured to embed the unique identifier of the user in content of the attachment. 19. The system of claim 12 , wherein the one or more servers are further configured to communicate the simulated phishing email to an email account of each user of the plurality of users. 20. The system of claim 12 , wherein the one or more servers are further configured to receive the reply email sent to a domain of or a domain hosted by the one or more servers. 21. The system of claim 12 , wherein the one or more servers are further configured to compare the unique identifier embedded in the reply email to the unique identifier established by the one or more servers for the user. 22. The method of claim 1 , wherein (d) further comprises identifying, by the one or more servers, the unique identifier embedded in in at least one of the subject line of the simulated phishing email, the body of the simulated phishing email or the attachment of the simulated phishing email. 23. A method for identifying users that reply to a simulated phishing email, the method comprising: (a) establishing, by one or more servers comprising a processor coupled to memory, a unique identifier for each user of a plurality of users to identify each user separately from an email account from which each user replies to a simulated phishing email; (b) embedding, by the one
Commands or executable codes · CPC title
Vulnerability analysis · CPC title
service impersonation, e.g. phishing, pharming or web spoofing (detection of rogue wireless access points H04W12/12) · CPC title
Electricity · mapped topic
Traffic logging, e.g. anomaly detection · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.