Skip to main content

AI Templates: create your own templates

How to generate a simulation template (email + landing page) from a real .eml email, an Inbox alert, or a free-form text description.

1️⃣ What AI Templates are for ?

The Riot catalogue covers the most common attacks. AI Templates let you go further: create your own simulation templates, modelled on the tools and the attacks your teams actually see. Riot generates the email and the landing page, then adds the template to your catalogue, ready to use in your campaigns.

👉 Three possible starting points

1. A simple description. You write the email you want in one sentence, and Riot builds it. Ideal when you have no example to hand.

​

2. An .eml file, that is, a real email exported from your mailbox. Ideal for replaying an attack your teams have just received.

3. A threat reported in Inbox, see Create a phishing simulation from a reported email.

In all three cases, the resulting template joins your catalogue and stays editable like any Riot template.

2️⃣ Creating a template from a simple description

👉 Step 1: open the Templates section of your campaign. This is where you choose the templates that will be sent.

👉 Step 2: describe the email you want. One sentence is enough, in the description field (512 characters maximum).

👉 Three example descriptions

"An email flagging suspicious activity on the employee's Payhawk account."

"A Microsoft 365 alert: the mailbox is almost full, click to free up space."

"An unpaid invoice from a supplier such as Qonto, in an urgent tone."

👉 Step 3: confirm the imitated service. Riot infers from your description which brand the email should imitate; you confirm or correct it.

👉 Step 4: confirm the sign-in page. Riot identifies the service's official sign-in page and rebuilds it as the landing page.

👉 Step 5: Riot writes the email. Sender, subject, content and layout are generated, with the brand's real logo and colours. Allow up to a minute; you follow each step live.

👉 Step 6: review the result. You can edit the template and send yourself a preview to your own mailbox before accepting it.

👉 Step 7: click "Use template". The template is added to the current campaign and joins your catalogue.

3️⃣ Creating a template from a real email (.eml)

👉 Step 1: export the email in .eml format. From your mailbox, download the email you received.

👉 Step 2: open the relevant campaign, then click "Import EML". The button is in the Templates section, next to the description field.

👉 Step 3: select the .eml file. A guided window opens and takes you through to the finished template.

👉 Step 4: confirm the imitated service. Riot detects which service the email is trying to impersonate; you confirm or correct it.

👉 Step 5: confirm the sign-in page. Riot identifies the matching sign-in page; you confirm it.

​

👉 Step 6: Riot generates the template. The email is rebuilt with the sender style, subject, tone and layout of the original, along with its landing page.

👉 Step 7: click "Use template". The template is added to the current campaign and joins your catalogue.

👍 Good to know: if the imitated service is not yet in the Riot catalogue, it is generated on the fly along with its sign-in page. The resulting template integrates with your catalogue, your metrics and the remediation content (slides and courses).

4️⃣ When the sign-in page cannot be rebuilt

It is not always possible to recreate a sign-in page automatically, because some are protected by anti-bot measures. Others load normally but cannot be copied faithfully. You find out at the point where the attempt fails.

You are not stuck, though: enter the sign-in page URL and its HTML source yourself, and Riot builds the landing page from those elements.

👉 How to get a page's HTML source

  • Open the sign-in page in your browser.

  • Right-click the page, then choose "View page source" (shortcut: Ctrl + U on Windows, ⌥ + ⌘ + U on macOS).

  • Select everything shown (Ctrl + A or ⌘ + A), copy it, then paste it into the field provided in Riot.

You can also attach a screenshot of the page: it helps Riot reproduce its appearance.

👍 Good to know: this case remains rare. Most sign-in pages are rebuilt automatically, with nothing for you to do.

5️⃣ Editing and reusing the template

The generated template opens in the usual editor, the one you already use for catalogue templates. There you can adjust the subject, the email content, the sender, the links and the Smart Variables.

Personalisation is automatic: Riot spots the elements that need to change from one recipient to the next (first name, company name, manager, dates) and the template is translated into each employee's language.

Once used for the first time, the template lives in your catalogue: you can reuse it on any other campaign, exactly like a Riot template.

⚠️ Important: the template's raw HTML cannot be edited after generation. The subject, content, sender and links can.

6️⃣ Where the template lives: workspace or organisation

The template libraries of an organisation and of its workspaces remain completely separate. A template created at organisation level does not appear in the child workspaces; a template created in a workspace appears neither in neighbouring workspaces, nor at organisation level.

👉 An example

Acme Corp (organisation) has two workspaces, "Sales" and "Engineering".

  • A template created at organisation level can be used for campaigns targeting "Sales", "Engineering" or both, but it will not appear in the library belonging to "Sales" or "Engineering".

  • A template created from the "Sales" workspace stays local to "Sales": neither the organisation catalogue nor "Engineering" will have access to it.

👍 Good to know: the templates you create are not shared with other Riot customers.

7️⃣ What happens to the email you import

The generated template is not a copy of the original email: Riot analyses its content, neutralises it, then rebuilds the email and the landing page on its own fully monitored infrastructure.

👉 The imported file is cleaned before any storage

  • Any scripts in the email are stripped out.

  • All links are emptied: the attacker's URLs are never kept.

  • Images are re-hosted on your workspace storage, instead of being loaded from the original servers.

  • Attachments are never processed.

The original file is kept only for the duration of processing, for monitoring and diagnostic purposes. Only the cleaned template data is stored long term.

8️⃣ Limitations to be aware of

  • .eml format only. The Outlook desktop app exports to .msg by default, which is not accepted; Outlook on the web lets you save directly as .eml. From the desktop app, follow the Microsoft guide Save an Outlook message as an .eml file, then import the resulting file.

  • The description is limited to 512 characters. A precise sentence beats a long text.

  • Attachments are not reproduced in the generated template.

  • The raw HTML cannot be edited after generation.

  • The sender domain is not free-form. The part before the @ can be changed; the domain comes from the domains managed by Riot, the same rule as for catalogue templates.

  • The email date cannot be customised. Simulation emails are genuine sends: the date is that of the actual send.

  • The link type is not a choice. All links are neutralised and redirected to the landing page of the identified service. To simulate a different authentication page, start from an email or a description imitating that service.

Before launching the campaign, remember to check the difficulty rating of the generated template: a well-built real attack is often rated Difficult. See Template difficulty: Easy, Medium, Difficult.

Key takeaways

  • AI Templates create a complete template, email and landing page, from a simple description, a real email (.eml) or an Inbox report.

  • The path is the same in both cases: confirm the imitated service, then the sign-in page, then generation, then "Use template".

  • If the sign-in page cannot be rebuilt automatically, you supply its URL and HTML source, and Riot handles the rest.

  • The template is editable, personalised automatically for each recipient and reusable on your other campaigns; its raw HTML, however, is not editable.

  • Organisation and workspace libraries stay separate, and your templates are not shared with other customers.

  • The imported email is cleaned before storage: scripts stripped, links emptied, images re-hosted, attachments never processed.

Did this answer your question?