Skip to main content

Creating a phishing simulation from a reported email

When an employee reports a genuine phishing attempt, you are looking at a real attack that has landed in your inboxes, specifically targeted at your staff. You can turn it into a training simulation without leaving the ticket.

👍 Prerequisite: to use this feature you need a subscription to the Inbox module, and it must be enabled on your platform.

1️⃣ Why this is useful

A catalogue template is realistic, but an attack your teams actually received turns your simulation into a real test: your tools, your suppliers, your internal vocabulary. It is the most relevant training material you have, and it costs nothing to produce.

2️⃣ How to do it

👉 Step 1: Open the ticket concerned in Inbox.

👉 Step 2: Click Create a simulation.

👉 Step 3: Choose the destination campaign. You can target an existing campaign — draft, active, paused or scheduled — or create a new one.

👉 Step 4: Riot generates the template from the email: converting the content, detecting the service being impersonated, inserting Smart Variables and replacing links with safe simulation URLs.

👉 Step 5: Save. The template is added to the campaign you chose.

👍 Good to know: the links from the original email are always replaced. The generated template never points to the attacker's infrastructure.

3️⃣ The limits of this first version

  • Attachments are not recreated. If the attack relied on a document, the generated template won't include one.

  • If several employees reported the same attack, the first report on the ticket is used as the source.

In both cases the generated template remains editable: you can adjust it before launching the campaign.

4️⃣ Two pieces of advice before launching

👉 Let some time pass. Sending an attack back as a simulation a few days after it circulated skews the result: employees will recognise it, and you will be measuring their memory rather than their vigilance.

👉 Check the difficulty of the generated template. A well-built real attack often ends up rated Hard. Sent to a population that is just starting out, it risks discouraging more than it teaches. See Template difficulty: Easy, Medium, Hard.

Key takeaways

  • It all starts from an Inbox ticket: nothing to do on the Simulation side.

  • Links are replaced with safe simulation URLs.

  • Attachments are not carried over in this first version.

  • Wait before sending the attack back, and check its difficulty.

Did this answer your question?