One campaign engine.
Eight ways in.
Phishing stopped being a fake login form years ago. Phishtime simulates the techniques that actually get used and measures each one on its own terms. "Approved a push prompt" and "typed a password" are different failures with different fixes.
Tracked link
An email with a tracked call-to-action button. The click is recorded and the recipient lands on the campaign's landing page: a realistic sign-in screen, an MFA prompt, a consent dialog, whatever the campaign is testing.
Measures: delivery, open, click, submit, with a 60-second dedupe window so mail-client prefetching can't inflate the numbers.
QR code - quishing
The same campaign, delivered as a QR code rendered into the email body. The employee scans it with a personal phone: outside your MDM, outside your proxy, outside the endpoint agent's view. That is why attackers use it.
Measures: the scan, as a click, so quishing exposure shows up in the same funnel as everything else.
Tracked attachment
Phishtime generates the file itself: HTML, TXT, DOCX or XLSX, and attaches it to the campaign email. Choose whether it beacons the moment it is opened, or carries the tracked link inside the document.
Measures: who opens attachments from outside the organisation, separately from who then acts on them.
SMS & Viber
Short message, tracked link, your own registered sender. Smishing arrives on the device that has none of your email controls in front of it, and lands in the same results view as an email campaign.
Requires: Pro or Enterprise, a verified phone number, and your own provider account. Message bodies are scanned before they can be sent.
Landing pages: four different failures
A credential form tells you who types passwords. It tells you nothing about who approves a push at 7am.
Credential capture
The realistic sign-in page. The form posts, the interaction is recorded, and the values are discarded before storage. Only the field's name is kept, so you know what was asked for, never what was typed.
MFA push approval
"Approve this sign-in?" with Approve and Deny. Records the two answers separately, so MFA-fatigue exposure is a number you can track over time instead of a worry.
OAuth app consent
A mimicked consent screen for a third-party app requesting access. Consent phishing steals a token without a password ever being typed, and rotating passwords afterwards fixes nothing. That is what makes it worth training for.
Device code
A lure that mimics a shared-document notification, "Finance shared a file with you", leading not to a document but to a real-looking device code and sign-in flow. It is the current technique of choice for several real intrusion sets, and almost no awareness programme covers it.
ClickFix - the fake CAPTCHA
"Verify you're human: run this command." The page detects the device and shows matching instructions: Win+R on Windows, Spotlight into Terminal on a Mac, a terminal shortcut on Linux. Phishtime's version records the beacon a real payload would have fired, so you learn exactly who would have run it without anything running.
Everything around the lure
Authoring
Targeting & delivery
Tracking
Training that follows the click
Employees
Reporting & evidence
See it against your own environment
Sign up free, load your own domain and a handful of test addresses, and run one of these for real. No card, no call.