Dull Men's Club
An unofficial chapter of the popular Dull Men's Club.
1. Relevant commentary on your own dull life. Posts should be about your own dull, lived experience. This is our most important rule. Direct questions, random thoughts, comment baiting, advice seeking, many uses of "discuss" rarely comply with this rule.
2. Original, Fresh, Meaningful Content.
3. Avoid repetitive topics.
4. This is not a search engine
Use a search engine, a tradesperson, Reddit, friends, a specialist Facebook group, apps, Wikipedia, an AI chat, a reverse image search etc. to answer simple questions or identify objects. Also see rule 1, “comment baiting”.
There are a number of content specific communities with subject matter experts who can help you.
Some other communities to consider before posting:
5. Keep it dull. If it puts us to sleep, it’s on the right track. Examples of likely not dull: jokes, gross stuff (including toes), politics, religion, royalty, illness or injury, killing things for fun, or promotional content. Feel free to post these elsewhere.
6. No hate speech, sexism, or bullying No sexism, hate speech, degrading or excessively foul language, or other harmful language. No othering or dehumanizing of anyone or negativity towards any gender identity.
7. Proofread before posting. Use good grammar and punctuation. Avoid useless phrases. Some examples: - starting a post with "So" - starting a post with pointless phrases, like "I hope this is allowed" or “this is my first post” Only share good quality, cropped images. Do not share screenshots of images; share the original image.
.
view the rest of the comments
They're testing to see what happens when their filter fails to catch something.
They don't know how to simulate an email that would get through the filters. If they knew how to do that, they'd just update the filters.
Instead, they say "hypothetically, if something did make it through our filters, would people fall for the phishing attempt?"
Sure, there's some CYA behaviour here, and trying to look busy. But, just because they're using a trick to get past the spam filters doesn't mean the test is invalid. They're not testing the spam filters, they're testing the users.
So… not entirely accurate.
When setting up campaigns in software like KnowBe4, you must make sure the existing protections don’t flag emails you send in your campaigns. These are usually defined in something like defender for cloud as a policy, and so additional policies for knowB4 mail campaigns have to be set so you don’t prevent them from being caught.
However, this is mostly just to ensure you get targeted content for a campaign to end users, and most every email we send would pass through anyway. We set the defender for cloud exceptions because we do not want to falsely impact measures on targeted cohort performance with defender policies.
The above email for example would not be flagged as phishing by any current policies in place in our organization.
While it is easy to be cynical about the phishing email campaigns, they do exist to try and get to a more mindful state of your users. We have research that supports their efficacy, and while you won’t ever get end users to universally “good” levels of behaviors around phishing, we can’t make that perfection be the enemy of trying to be more mindful.
Still, it is humorous when you define a campaign and make it more specifically targeted for C suite cohorts only to get told to tone it down. They missed the point indeed.
As a moron, I wish companies would just fucking tell me about their scams. I never catch on until a few months after I leave the company.
inb4 this dude gets spearphished lol
My employer uses Google for email, etc. There are email headers in the tests we get like X-PHISHTEST and X-SECURITY-TEST. I wrote a Google script that analyzes incoming emails for these headers and adds a “Phishing” tag to anything with one of these headers. So they show up highlighted in my inbox. I doubt I’m the only person who has done something like this.
If the words "email headers" are anything more than gobblygook to you, then you're not the one the clicker trainings are intended for.
The phish test emails are however quite handy for staying vigilant. When good defenses make it take years for a real phishing email to sneak through, then being already primed by the quarterly phish tests to be suspicious helps ensure that as many people as possible don't get compromised
The people who know how to do that are probably not the people falling for the mails anyway.
You've not heard of ISO compliance. Time to delete your surly, ill-informed diatribe.