Attack types & features

One campaign engine.
Eight ways in.

Phishing stopped being a fake login form years ago. Phishtime simulates the techniques that actually get used and measures each one on its own terms. "Approved a push prompt" and "typed a password" are different failures with different fixes.

Tracked link

An email with a tracked call-to-action button. The click is recorded and the recipient lands on the campaign's landing page: a realistic sign-in screen, an MFA prompt, a consent dialog, whatever the campaign is testing.

Measures: delivery, open, click, submit, with a 60-second dedupe window so mail-client prefetching can't inflate the numbers.

QR code - quishing

The same campaign, delivered as a QR code rendered into the email body. The employee scans it with a personal phone: outside your MDM, outside your proxy, outside the endpoint agent's view. That is why attackers use it.

Measures: the scan, as a click, so quishing exposure shows up in the same funnel as everything else.

Q3_Invoice_Overdue.docx184 KB · finance-shared@

Tracked attachment

Phishtime generates the file itself: HTML, TXT, DOCX or XLSX, and attaches it to the campaign email. Choose whether it beacons the moment it is opened, or carries the tracked link inside the document.

Measures: who opens attachments from outside the organisation, separately from who then acts on them.

Your parcel couldn't be delivered. Reschedule now: post-track.example/r/8k2 Today 14:02
Messaging

SMS & Viber

Short message, tracked link, your own registered sender. Smishing arrives on the device that has none of your email controls in front of it, and lands in the same results view as an email campaign.

Requires: Pro or Enterprise, a verified phone number, and your own provider account. Message bodies are scanned before they can be sent.

Landing pages: four different failures

A credential form tells you who types passwords. It tells you nothing about who approves a push at 7am.

Credential capture

The realistic sign-in page. The form posts, the interaction is recorded, and the values are discarded before storage. Only the field's name is kept, so you know what was asked for, never what was typed.

Approve sign-in?
Ljubljana, SI · new device
Deny Approve

MFA push approval

"Approve this sign-in?" with Approve and Deny. Records the two answers separately, so MFA-fatigue exposure is a number you can track over time instead of a worry.

Expense Sync wants access
Read your mail Read your contacts
Cancel Allow

OAuth app consent

A mimicked consent screen for a third-party app requesting access. Consent phishing steals a token without a password ever being typed, and rotating passwords afterwards fixes nothing. That is what makes it worth training for.

Enter code to continue
WXTQ-4821
↳ microsoft.com/devicelogin

Device code

A lure that mimics a shared-document notification, "Finance shared a file with you", leading not to a document but to a real-looking device code and sign-in flow. It is the current technique of choice for several real intrusion sets, and almost no awareness programme covers it.

Win + R → Run
powershell -w hidden -c "iwr hxxp://…

ClickFix - the fake CAPTCHA

"Verify you're human: run this command." The page detects the device and shows matching instructions: Win+R on Windows, Spotlight into Terminal on a Mac, a terminal shortcut on Linux. Phishtime's version records the beacon a real payload would have fired, so you learn exactly who would have run it without anything running.

The campaign engine

Everything around the lure

Authoring

✓30+ ready-made templates with matching landing pages, maintained by us
✓Clone any of them into your own workspace and edit freely
✓Visual editor with a live split-screen preview, or raw HTML if you prefer
✓Personalisation variables, name, surname, email, employee ID
✓Multi-language content, one template, per-locale text

Targeting & delivery

✓Target groups, or everyone, materialised at launch from the live roster
✓Send immediately, drip every N seconds, or spread across a window
✓Schedule a launch for a future date and time
✓Managed mail, or your own SMTP relay with your own DKIM
✓Test-send the fully rendered mail to yourself before anyone else sees it

Tracking

✓Opens, clicks, submissions, approvals, consents, beacons and reports
✓Per-recipient opaque tokens, no guessable identifiers in a URL
✓Engagement state that only ever moves forward, so a reload can't rewrite history
✓Security-scanner hits excluded from employee metrics
✓Register your office, VPN or data-centre IP ranges and every event is tagged internal or external, who clicked from inside the building versus a personal device off-network
✓Live funnel, per-minute timeline, per-person event chain

Training that follows the click

✓Awareness page shown at the moment of failure, listing the indicators that were there to spot
✓Follow-up awareness email with the same content
✓Delivered in each employee's own training language
✓Your logo, name and support address on every training surface

Employees

✓CSV import, or directory sync from Entra ID scoped to chosen groups
✓Groups by department, office, risk, however you want to slice results
✓Scores and reward points: penalties for falling for it, credit for resisting
✓Self-service portal with personal history and rank
✓Leaderboard privacy control, names, initials, or off

Reporting & evidence

✓Phish-prone percentage, net of reporters
✓Reporting rate, repeat-clicker rate, time-to-click and time-to-report
✓CSV export, per-campaign PDF, cross-campaign period reports by department
✓Append-only audit log with CSV export and a SIEM API
✓SOC mailbox ingest, Outlook "Report Phishing" captured and matched automatically

See it against your own environment

Sign up free, load your own domain and a handful of test addresses, and run one of these for real. No card, no call.