Skip to main content

Riot in Darktrace

Updated over a month ago

1️⃣ Introduction

Riot sends phishing simulation emails.

If your Darktrace solution is not properly configured, some of these emails may be blocked by filters, which could distort your campaign statistics.

Here’s how to allow Riot’s IPs and ensure your test campaigns run smoothly.

2️⃣ Definition

Darktrace is an AI-based detection solution that analyzes email traffic and can block suspicious messages.

Without proper configuration, your Riot simulation emails might be mistakenly filtered.

3️⃣ Configuration steps

  1. Go to Detection > Models

  2. Click New model > Global Model

  3. Fill in the following information:

  4. Select Model is active + Automatic actions + Applies to outbound

  5. Add a new component input (blue circle) and drag it into the model logic

  6. Set the following parameter:

    • Connection + IP Address

    • Positive Equals: 159.135.234.25

  7. Under Model actions, select Do not hold or alter

  8. Click Save

Did this answer your question?