PhishBrain for MSPs
PhishBrain is a very effective phishing awareness tool that MSPs can use to perform assessments on clients and demonstrate vulnerabilities within their user bases.
Part 1. Setting up the Tenant of your Client
Log into PhishBrain
Go under Tenants > New Tenant
- Name: Enter name of Client
- License Limit: Enter number of emails or sends (according with your license type) you want to assign to the new tenant. If your license have "smishing" option, you can optionally enable it and assign sends to the new tenant.
- Click Save
After Saving, you will see the new Tenant under the Tenants page.
Next, click the Blue Users button under the Actions
Next, click New User
Add details of Primary Administrator of the new tenant (likely to be someone from the MSP)
- The Username and the Email Address should be within the domain you intend to verify and send phishing emails to
- Check role of Administrator
- Click Save
Next, you will set up the Client’s tenant so that you can send phishing campaigns.
Go to Tenants and click the Users button (button with people under Actions)
Then click the Switch User button (Last button with arrows under Actions) next to newly created user (msp_admin@libracyber.com, in the example)
You will now be logged into the Tenant of your Client (Test Tenant, in the example), impersonating the tenant Administrator
Part 2. Preparing the Client’s tenant for Phishing Campaigns
First you must verify* ownership of the domain, in which you intend to send phishing emails.
* We require verifying ownership of the domain in order to prevent abuse. Without this verification, anyone signing up could send simulated phishing emails to anyone in the world, risking damage to PhishBrain’s domain reputation and rendering the entire service unusable.
Go to Domains > New Domain
- Enter the domain name (desmotechsolutions.com, in our example)
After entering the domain, you will see instructions for verifying the domain with your registrar.
Visit your registrar and create a new DNS entry with TXT record type (GoDaddy example below).
PhishBrain checks for DNS updates every 5 minutes, so you may need to wait a couple minutes until the domain’s status becomes Verified.
Next, go to Lists > New List
- Select how you’d like to populate your list of recipients
-
Address List would be the quickest and easiest method
- Easily import from a CSV file or manually enter details
After all the recipients’ details are entered, click Save.
Part 3. Performing your first Assessment / Phishing Awareness campaign
There are many options when sending a campaign. In this example, you will set up a basic campaign with a simulated phishing email and landing page.
Click Campaigns > New Campaign
Step 1. Name and configure the campaign (for more details about options, see specific manual page)
Step 2. Choose the target list (C-Suite, in the example)
Step 3. Choose your template/s (if you select multiple templates, they will be randomly assigned to targets at launch time). We’ve chosen “DocuSign Service” in the example.
Step 4. Schedule the campaign. We’ve selected the default settings.
You can send a Test email from the Summary page (must be an email within the verified domain of the tenant).
Click Save to finish setting up the campaign and click the Launch button when ready to start.
To see the results of the Assessment / Campaign, head to the Dashboard of the tenant.
The Dashboard will give you real-time results of the campaign, and at any time, you can click on the campaign on the bottom-left of the Dashboard to get it's Overall Risk Score.