IP Library Granted Patent US 11,870,806
Granted Patent B1
US 11,870,806 · App. 16/669,817 · Granted Jan 9, 2024

Phishing attack training systems and methods

Inventors: Jin Qian (Austin, TX); Brent Cook (Pflugerville, TX)
Assignee: Rapid7, Inc.
H04L63/1483H04L63/1416H04L63/1425H04L63/1433H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,870,806
App. No.
16/669,817
Granted
Jan 9, 2024
Kind
B1
Abstract

Systems and methods for user training. The systems and methods involve deploying at least one static file on a computing resource controlled by an operator, transmitting a URL to a target user, receiving a request for the URL from the target user, transmitting the at least one static file to the target user for execution in a web browser of the user, and receiving data regarding the execution of the at least one static file.

Claims (44)

1. A method comprising:

deploying at least one static file on a computing resource of a company network, wherein the computing resource is controlled by an operator of the company, and the at least one static file comprises code executable by web browsers and being accessible by a URL;

transmitting the URL that provides access to the at least static file to a target user device of a target user;

receiving a request for the URL that provides the access to the at least one static file from the target user device;

transmitting the at least one static file from the computing resource of the company network to the target user device, wherein the transmission causes execution of the code in a web browser of the target user device, the execution including:

obtaining a phishing script for the target user based on an identifier of the target user;

tracking user interactions with the URL via the web browser and according to the phishing script; and

sending, to a training server controlled by a third party phishing application provider, the user interactions as individual events, wherein each event indicates an event identifier and the identifier of the target user.

2. The method of claim 1 wherein the phishing script is obtained from the third party phishing application provider.

3. The method of claim 1 wherein the user interactions include at least one of a click on a link associated with the URL and a transmission of a user credential of the target user.

4. The method of claim 1 wherein receiving the data regarding the user interactions includes at least one of receiving the data through a predetermined endpoint, receiving a transmitted resource, or receiving the data through a side-channel to another resource controlled by the operator.

5. The method of claim 1 wherein the received request includes an identifier that identifies the target user.

6. The method of claim 1 further comprising associating an identifier with the target user.

7. The method of claim 6 wherein associating the identifier with the target user includes embedding the identifier in the transmitted URL.

8. The method of claim 1 further comprising receiving the at least one static file from the third party phishing application provider.

9. The method of claim 8 , wherein the static file is a webpage template that mimics a webpage of the company and includes one or more of an image, a video, a document, a logo, a slogan, or a Cascading Style Sheet (CSS) file associated with the company.

10. A system, comprising:

one or more processors and memory storing instructions executable by the one or more processors to:

deploy at least one static file on a computing resource of a company network, wherein the computing resource is controlled by an operator of the company, and the at least one static file comprises code executable by web browsers and being accessible by a URL;

transmit the URL that provides the access to the at least one static file to a target user device of a target user;

receive a request for the URL from the target user device;

transmit the at least one static file from the computing resource of the company network to the target user device, wherein the transmission causes execution of the code in a web browser of the target user device, including to:

obtain a phishing script for the target user based on an identifier of the target user;

track user interactions with the URL via the web browser and according to the phishing script; and

send to a training server controlled by a third party phishing application provider, the user interactions as individual events, wherein each event indicates an event identifier and the identifier of the target user.

11. The system of claim 10 wherein the phishing script from the third party phishing application provider.

12. The system of claim 10 wherein the user interactions include at least one of a click on a link associated with the URL and a transmission of a user credential of the target user.

13. The system of claim 10 wherein the data regarding the user interactions is:

received through at least one of a predetermined endpoint,

received via a transmitted resource, or

received through a side-channel to another resource controlled by the operator.

14. The system of claim 10 wherein the received request includes the identifier that identifies the target user.

15. The system of claim 10 wherein the one or more processors is further configured to associate the identifier with the target user.

16. The system of claim 15 wherein the one or more processors associates the identifier with the target user by embedding the identifier in the transmitted URL.

17. The system of claim 10 wherein the one or more processors is further configured to receive the at least one static file from the third party phishing application provider.

18. The system of claim 17 wherein the static file is a webpage template that mimics a webpage of the company and includes one or more of an image, a video, a document, a logo, a slogan, or a Cascading Style Sheet (CSS) file associated with the company.

19. A non-transitory computer-readable medium storing program instructions that when executed by one or more processors cause the one or more processors to perform:

transmitting a URL to a target user device, wherein the URL accesses at least one static file comprising code executable by web browsers, and the static file is deployed on a computing resource of a company network and controlled by an operator of the company;

receiving a request for the URL that provides access to the at least one static file from the target user device;

transmitting the at least one static file from the computing resource of the company network to the target user device, wherein the transmission causes execution of the code in a web browser of the target user device, the execution including:

obtaining a phishing script for the target user based on an identifier of the target user;

tracking user interactions with the URL via the web browser and according to the phishing script; and

sending to a training server controlled by a third party phishing application provider, the user interactions as individual events, wherein each event indicates an event identifier and the identifier of the target user.

20. The non-transitory computer-readable medium of claim 19 , wherein the phishing script is obtained from the third party phishing application provider.

Assignments (4)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
RELEASE OF SECURITY INTEREST Recorded Dec 27, 2024
From: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: RAPID7, INC.
Reel/Frame 069785/0328 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2020
From: COOK, BRENT; QIAN, JIN
To: RAPID7, INC.
Reel/Frame 053774/0786 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 24, 2020
From: RAPID7, INC.
To: KEYBANK NATIONAL ASSOCIATION
Reel/Frame 052489/0939 →
Cited By (1)
US 12,423,421