The Attack Simulation Test (AST) allows you to choose between multiple phishing scenarios in one place, including reply-to phishing, social media attacks, and QR code scams. This test shows you how vulnerable your users are across one of these attack vectors.
You don’t need to download or install any software. This free test is limited to 100 users, but you can contact us if you need to send this test to more users.
Create a Free Account
Before you begin this test, you’ll need to create a free account.
- Sign up for a free account here: KnowBe4 Free Phishing Security Test.
-
On the Attack Simulation Test page, enter your information and click Submit. Then, click Get Started.
-
You’ll be redirected to a sign-in page. Enter your work email address, then click Continue to create your free account.
- You’ll receive an email asking you to activate your account. Click the link in the email to activate your free account.
- Next, you’ll need to set up your free account. Enter your first name, last name, and a password for the account. Click Save & Continue.
- As the first person to log in under your domain, you’ll be automatically set up as the account owner.
Set Up the Test
- Log in to your free KnowBe4 account.
-
In the Free Attack Simulation Test section, click Get Started.
-
Select your Industry and Company Size. Entering this data allows you to compare your test results to others in your industry. Click Next Step.
-
Select your phishing language and select the type of phishing email you want to send. You can click each subtab to view more options, see a preview, or send a test email. By default, the templates are displayed in English. If you select a different language, the templates can be previewed and sent in the selected language. You can click through each subtab to see our template types:
- Popular: These templates are basic templates you can use if you’re unsure of which type to send.
- Mail Server: These templates are three variations of the Password Change request template, which match Microsoft 365, Google Workspace, and Microsoft Exchange mail environments.
-
Reply: These templates allow you to track how many users reply to phishing emails.
Note: Our reply templates will never save any of the information included in a reply. We only track whether the user replied, not the contents of that reply. We recommend spoofing someone from your own organization for more accurate results, but make sure you get their permission first. - Social Media: These templates allow you to track how many users will click a phishing link and enter their social media credentials. If they enter credentials and try to log in, they’ll be redirected to an error page.
- QR Code: These templates allow you to track how many of your users will scan QR codes in phishing emails.
- After you make your template selection, click Next Step.
-
Set your campaign settings. From the Random Domain drop-down menu, select the domain you want the phishing emails to be sent from. From the Sending Period section, select when you want the phishing emails to be sent. When you’re done, click Next Step.
-
Choose who you would like to send this phishing test to. You can import up to 100 email addresses from your organization. Enter or paste the email addresses into the box, one per line, with no commas or spaces. When you’re done, click Next Step.
-
Choose which landing page your users will see if they fail the test. You can select either a Social Engineering Indicators (SEI) landing page, which lets the user know they failed a phishing test and then instructs them on the red flags that they should have looked out for on this particular phishing email, or a 404 error page, so the user may assume they clicked on a broken link. If you skip this step, the SEI landing page will be selected by default.
-
Click Preview & Send Test Email to see a sample of what your email will look like when your users receive it. You can select a button to display the red flags, preview the landing page, and send yourself a test email by clicking the Send Me a Test Email button in the top-right corner of the pop-up window.
- After sending the test email, check your inbox to make sure you received the test. This can take up to 10 minutes. If you didn’t receive the email, double-check your whitelisting or review our Whitelisting Guide. If you need further assistance, contact our support team.
-
Click the Start Free AST button to begin testing your users.
Analyzing Your Results
After you run the test, you can return to your account at any time to view the results on the Dashboard page. You’ll be able to see your Phish-prone Percentage (PPP), showing your vulnerability if a similar phishing attack were to occur within your organization. You can also see how your PPP compares with others in your industry after one year of combined computer-based security awareness training and simulated phishing.
After 24 hours, you’ll automatically receive a PDF report in your email inbox. If you want to know which users clicked links or scanned QR codes, contact your sales rep or reseller. If you don’t know who your sales rep is, submit a support ticket.
With this knowledge, you can help protect your organization by teaching your users about the dangers of these types of attacks. With KnowBe4's security awareness training and simulated phishing platform, you can significantly reduce your security risks and train your users to spot the warning signs and keep their skills sharp by sending fake phishing attacks much like the ones in this free tool. For more information, request a demo here.
/FreeAST.png)
/FreeAST_SignIn.png)
/FreeAST_GetStarted.png)
/FreeAST_Industry.png)
/FreeAST_SelectTemplate.png)
/FreeAST_CampaignSettings.png)
/FreeAST_ChooseRecepients.png)
/FreeAST_LandingPage.png)
/FreeAST_Preview.png)
/FreeAST_Review.png)
/FreeAST_Report.png)