Complete Guide to Activating PhishPro Attacks
Overview
PhishPro is the Cyber Guru Phishing Add-on that adds three types of simulated attacks (QR Code, USB, Video) and Adaptive Training Remediation. Each attack is activated with its own toggle and only works if your organization has purchased the Add-on.
This guide explains how to activate the Add-on and configure each component, from setup to monitoring results.
| Component | What it does | Who configures it |
|---|---|---|
| Adaptive Training Remediation | Assigns training content to users who display risky phishing behaviors | Customer, after license activation by the CSM |
| QR Code Attack | QR Code printed or inserted in an email, leading to a landing page | Paper: global template already active, the contact prints and distributes. By email: the CSM enables QR Code templates or provides a customizable copy for the customer |
| USB Attack | Physical USB drive with a file that tracks interaction | Customer, independently. The CSM only steps in to review customization requests |
| Video Attack | Email with a link to a video recorded by a senior figure at the customer’s company | Customer records the video, CSM activates the templates |
Activating the PhishPro Add-on
The Add-on is activated from Company Management > Setup > Phishing, in the "Add on Phish Pro" panel, by enabling a toggle for each purchased attack (KB guide).
- Make sure the customer has purchased the PhishPro Add-on.
- Open the company in Company Management > Setup > Phishing.
- In the Add on Phish Pro panel, enable the necessary toggles:
- Enable QR Code Attack
- Enable USB Attack
- Enable Video Attack
- Save and continue with the configuration of each attack (see the following sections).
The general Phishing settings (campaign duration, default landing page, gamification, country templates) remain on the same page but are not required to activate PhishPro. For those, refer to the guide Setup > Phishing: Managing Phishing and PhishPro Settings.
Note: If the customer uses Google infrastructure, the Embed images option must be disabled, as Gmail does not natively support base64 images.
Adaptive Training Remediation
Adaptive Remediation is a PhishPro feature that assigns training content to users who display risky phishing behaviors. Release is instant after approval (KB guide).
Configuration is handled by the customer, after the CSM activates the license.
Prerequisites
- Active PhishPro license and active Awareness license.
- Users with at least 2 clicks in the last 4 regular campaigns.
Step 1 – First: Set up Student Caring
Before starting Remediation, make sure the Student Caring event "New Training Remediation" is active and linked to the correct email template. Without this event, users will see the course in their dashboard but won’t get an email notification. For setup, follow the Student Caring guide.
Step 2 – Start Remediation
- Go to Release Management > Remediation.
- In the Adaptive Remediation section, click Start.
- Review the targets suggested by the system and deselect any you want to exclude.
- Approve: the "Remediation" course is released immediately.
Users will find the content in Training Plan > Modules. The videos are similar in length to Awareness content, do not include tests or scores, but do affect the completion percentage and the user’s alignment status.
Step 3 – Restart
If new eligible users appear later, you can restart Remediation to include them.
Monitoring
- Statistics > Remediation Report: progress percentage and completion status per user, exportable as CSV.
- Statistics > Overview: report of completed activities and participation report.
USB Attacks
The customer sets up the campaign independently and receives a "malicious" Word file by email, which they load onto USB drives and distribute. The platform tracks who opens the file (KB guide).
The CSM should only be involved to review any customization requests, which must be checked and approved.
Prerequisites
- PhishPro Add-on must be properly purchased. Activation for testing or trial purposes is not allowed; if in doubt, contact support before activating.
- Enable USB Attack toggle must be active in Setup > Phishing.
- USB attacks also work on users who have never received attacks before.
Choose the mode
| Mode | What it tracks | Limitation |
|---|---|---|
| With macro | File opened + macro executed: Phished IP (public), Host Name, Host IP (local) | Macros are often blocked by company policies |
| Without macro | Only one click per user with Phished IP (public) | None, but data is aggregated |
Important for macro mode: It’s the customer’s responsibility to check and, if needed, change company policies so the macro can run. LibraCyber does not provide guides or support for reviewing customer policies. If macros are blocked, suggest using the mode without macro or a certified macro managed by the customer.
Setting up the campaign
- Go to Release Management > Remediation and click Start in the USB attack section.
- Choose the USB template. One template per campaign; a newly created template becomes selectable the next day.
- Set the duration:
- Start Date: when interactions start being tracked (not in the past).
- Campaign Duration: tracking period; events outside this window are not counted.
- Campaign Start Time: time when tracking begins.
- Email sending duration: leave blank.
- Enter the email address of the contact who will receive the file. This can be any address, even outside the company.
- Approve. The email with the attached file will be sent to the contact the next day.
After sending
- It’s important to remember the registration dates and times to best plan USB distribution.
- File openings by the contact are also counted in the report.
- Instructions for the attachment are inside the standard file. Any customizations must be submitted to the CSM for review and approval.
- At the end of the campaign, download the report with Phished IP, Host Name, and Host IP.
Video Attacks
The Video Attack is a simulated phishing email that leads to a landing page with a video recorded by the customer. The video is not sent directly: an email is sent, and the video is on the landing page (KB guide).
Prerequisites
- PhishPro Add-on purchased and Enable Video Attack toggle active in Setup > Phishing.
- All users with a PhishPro license can be included, even if they haven’t received previous attacks.
Step 1 – The CSM makes Media templates available
The customer will see Media-type templates and their landing pages in Training Material (filter "Only Media Type") only after the CSM activates them for the company. Preconfigured scenarios available:
- Privacy Notice, with data request via form.
- Company Benefits, with sign-up form.
- Ransomware in the Company, with click for more info.
Step 2 – The customer chooses the scenario and records the video
- The customer contact selects the template and reviews the associated landing page.
- The CSM provides a sample script (editable) on request for a senior figure to read.
- The customer records the video following the script, matching the landing page content.
- The customer uploads the video in Training Material > Media Resources: formats .MOV, .MP4, .AVI, up to 1 GB. The video is only visible to their company. For multilingual companies, it’s best to record in English.
Step 3 – Launch the campaign
- Go to Release Management > Remediation and click Video Attacks.
- Select only one Media template.
- Set the timing: start date, campaign duration, start time, and sending duration (must be shorter than the campaign duration).
- In Manage Target select recipients manually or by organization.
- On the final screen, select the uploaded video: it will be automatically linked to the template’s landing page.
Monitoring
In Remediation Report you can see for each user: email sent, link clicked, and landing page interaction (event "Submitted Data"). Data entered in forms is not saved. Everything can be exported as CSV with Export.
QR Code Attacks
There are two different QR Code attacks, each with separate configurations: the paper QR Code, printed and distributed by the contact, and the QR Code by email, inserted in a phishing email (KB guide).
| Method | Recipients | Tracking | Recommended |
|---|---|---|---|
| Paper | No target: anyone can scan | Anonymous (scan count and IP) or data entered on an intermediate landing page | For physical scenarios |
| By email | Campaign target | Per user, like a regular phishing campaign | Yes, more accurate results |
Prerequisites
- PhishPro add-on must be purchased. Activation for testing or trial is not allowed; if you have any questions, contact support first.
- The Enable QR Code Attack toggle must be active in Company Management > Setup > Phishing.
Paper QR Code
The global paper QR Code template is already active. Its standard landing page is recommended, as it is designed for this type of attack.
Template customization (optional)
Only needed if you want users to land on a different page than the standard one. Otherwise, go straight to campaign setup.
- Go to Training Material, select the company, and open Template.
- Filter by "Only QR code type templates".
- On the global template, click the pencil in the Actions column, open the Actions section, and choose the company's subdomain from the dropdown menu.
- On the copied template, customize the associated landing page.
Campaign setup
- Go to Release Management > Remediation > QR Code Attack and click Start.
- Select the QR Code template: either the global one or your customized copy.
- In the Dates section, set the start date, duration, and start time. Interactions outside the set duration will not be recorded.
- Email sending duration: leave the default value PT2M. The contact person will receive the QR within 2 minutes of starting.
- In the Target section, enter only the contacts (first name, last name, email, language), you can add more than one. Do not enter the attack recipients.
The contact person should print and distribute the QR code immediately to avoid losing days of tracking. Alternatively, set a longer duration for more flexibility.
The paper QR campaign can be launched even if the company has never run regular phishing campaigns.
Monitoring
At the end of the campaign, in Statistics > Remediation Report you can see the IP address from which the click came and any data entered on the intermediate landing page. Passwords are not saved unless capture is explicitly enabled on the landing page.
QR Code by email
The QR Code by email is a phishing template used in regular campaigns. Tracking is per user, just like any email template.
QR Code templates are made available in two ways:
- Templates enforced by the CSM: The CSM enforces the QR Code templates, which are then offered in phishing campaigns.
- Copy of the global template: The CSM provides a copy of the global template in the company. The customer can customize it and enforce it independently in campaigns.