A user with a supervisor role or higher can download an export of the simulated phishing campaigns from the "Statistics > Phishing Report" section.
The global report is updated to include the most recently completed campaign.
The following information, visible in the downloadable Phishing report from the platform, can help identify bot clicks:
- Phished browser: If the browser or its version listed is not used in your environment or is outdated, it could suggest an automated click.
- Operating system not accessible to users: If the operating system shown in the report is not accessible to users in your environment, it could indicate an automated click.
- IP address: If the IP address belongs to a provider of one of your security products, it could be a sign that the click was generated internally by a security tool [this data may not be visible to all roles; if needed, contact Cyber Guru support].
What causes unexpected IP addresses in campaign results?
When a click is registered by Cyber Guru, the IP address from which the "click" originated is recorded. Here are some examples of why you might see unexpected IP addresses:
- Mobile devices: If a user clicks a link using a mobile device, the IP address may reflect the user's cellular service provider.
- Home network: If the user is connected to their home Wi-Fi, the click will be recorded with the IP address provided by their home Internet Service Provider (ISP).
- Public networks: If the user connects to a public Wi-Fi network, the recorded IP address will reflect the user's physical location at the time of the click.
- Use of hosting services like AWS: If the user or their services use a hosting provider, the IP address may come from a different location, sometimes even another country. Some link analysis processes may not happen on the client side, and the link could be "passed" to the security provider's backend processing or analysis center;
- Analysis via services like VirusTotal: When a URL is sent to VirusTotal for analysis, the recorded IP address may come from a different location. This process can be triggered automatically by a security product in use or by the user themselves. When a URL is sent to VirusTotal, it analyzes the URL to determine if it should be added to threat definitions as malicious. Sometimes link analysis is immediate. Other times, it may happen over several hours. These IP addresses may be recorded as security providers or as ISPs.
User Interaction with Simulation Templates
Open
The open event occurs when a user opens the email and/or downloads the images it contains. This action triggers the tracking system embedded in the message to record the interaction.
Note: In some cases, the "Open" event may not be tracked, even if the user interacts with the content. This happens if the recipient's email system blocks automatic image downloads. Tracking will only be activated if the user manually clicks “download images” or marks the sender as trusted, depending on the email client used.
Click
This event is triggered whenever the user clicks on images or links within the template. Unlike the open event, the click can be tracked even if images have not been loaded, making it a more reliable indicator of real engagement.
Reported
The “Reported” event indicates that the user has reported the message as suspicious or potential phishing. The date of the report is recorded.
Submitted_data
This event is triggered when the user enters credentials on a simulated credential capture landing page. The date of the action is recorded.