IP Library Granted Patent US 10,855,716
Granted Patent B2
US 10,855,716 · App. 16/672,715 · Granted Dec 1, 2020

Systems and methods for performing or creating simulated phishing attacks and phishing attack campaigns

Inventors: Alin Irimie (Clearwater, FL); Wendy Bartlett (Clearwater, FL); David Austin (Dunedin, FL)
Assignee: KnowBe4, Inc.
H04L63/1433H04L63/1483H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,855,716
App. No.
16/672,715
Granted
Dec 1, 2020
Kind
B2
Abstract

A method for establishing a campaign for a simulated phishing attack includes receiving, via a campaign manager, specification of a plurality of parameters for a campaign including at least an identifier of a campaign and identification of users to which to send the campaign, establishing, via the campaign manager, a type of exploit for the campaign and one or more types of data to collect via the type of exploit, storing, by the campaign manager, the campaign comprising the plurality of parameters, and identifying, by a simulation server, the campaign stored in the database to create a simulated phishing email, to be sent to email accounts of the users, using the plurality of parameters of the campaign, wherein the simulated phishing email is to be created to have a link to a landing page comprising the type of exploit and configured to collect the one or more types of data.

Claims (26)

1. A system comprising:

one or more processors, coupled to memory, and configured to receive identification of a type of exploit to use for a simulated phishing communication and one or more types of data to collect for the type of exploit;

wherein the one or more processors are configured to create the simulated phishing communication with a link that is configured to cause execution of an application configured to simulate the type of exploit and collect the one or more types of data;

wherein the one or more processors are configured to communicate the simulated communication email to email accounts of one or more users; and

wherein responsive to interaction with the link, the application is executed and the one or more types of data collected by the application for the type of exploit are communicated to a server to identify a result of the type of exploit caused by the simulated phishing communication.

2. The system of claim 1 , wherein the application comprises a downloader to obtain one or more files to be executed to simulate the type of exploit.

3. The system of claim 1 , wherein the application comprises one of a Java application or a Flash Script.

4. The system of claim 2 , wherein the downloader is configured to obtain the one or more files over a network from a server.

5. The system of claim 2 , wherein the downloader is configured to receive a uniform resource location (URL) from which to download the one or more files.

6. The system of claim 2 , wherein the one or more files provides for one of installation or execution of the type of exploit.

7. The system of claim 1 , wherein the link is configured to traverse to a web page configured to cause execution of the application.

8. The system of claim 1 , wherein the application is configured to one of collect the one or more types of data or communicate the collected one or more types of data according to a timeframe corresponding to the type of exploit.

9. The system of claim 1 , wherein the one or more processors are configured to receive the identification of the type of exploit via a selection from a plurality of types of exploits provided by an interface.

10. The system of claim 1 , wherein the one or more processors are configured to receive the identification of one or more types of data via a selection from a plurality of types of data provided by an interface.

11. A system comprising:

a database configured to store a plurality of campaigns configured for one or more simulated phishing attacks, wherein each of the plurality of campaigns identifies a type of exploit and a selection of one or more types of data to collect via configuration of the type of exploit; and

a simulation server executable on one or more processors and configured to identify from the database a first campaign from the plurality of campaigns and create a first simulated phishing email with a first link to a first landing page comprising a first type of exploit and the first type of exploit configured to collect the selection of a first one or more types of data.

12. The system of claim 11 , wherein the simulation server is further configured to communicate the first simulated phishing email to one or more email accounts of one or more users.

13. The system of claim 11 , wherein the simulation server is further configured to identify from the database a second campaign from the plurality of campaigns.

14. The system of claim 13 , wherein the simulation server is further configured to create a second simulated phishing email with a second link to a second landing page comprising a second type of exploit and the second type of exploit configured to collect a selection of a second one or more types of data.

15. The system of claim 14 , wherein the simulation server is further configured to communicate the second simulated phishing email to one or more email accounts of one or more users.

16. The system of claim 12 , wherein the selection of the type of exploit from a plurality of types of exploits is received via an interface.

17. The system of claim 12 , wherein the selection of one or more types of data from a plurality of types of data for the type of exploit is received via an interface.

18. The system of claim 12 , wherein the one or more the types of data comprises one or more of the following types of data: user information, network information, system information and Light Directory Access Protocol (LDAP) information.

19. The system of claim 12 , wherein the simulation server is further configured to receive, responsive to traversal via the first link to the first landing page, data corresponding to the one or more types of data.

20. The system of claim 12 , wherein one of the landing page or the type of exploit is configured to collect the one or more types of data.

Assignments (6)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT REEL/FRAME: 062627/0001 Recorded Jul 28, 2025
From: BLUE OWL CREDIT INCOME CORP. (FORMERLY KNOWN AS OWL ROCK CORE INCOME CORP.)
To: KNOWBE4, INC.
Reel/Frame 072108/0205 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL/FRAME NO.: 056885/0889 Recorded Feb 2, 2023
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: KNOWBE4, INC.
Reel/Frame 062625/0841 →
PATENT SECURITY AGREEMENT Recorded Feb 2, 2023
From: KNOWBE4, INC.
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 062627/0001 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Mar 12, 2021
From: KNOWBE4, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 056885/0889 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 4, 2019
From: IRIMIE, ALIN; BARTLETT, WENDY; AUSTIN, DAVID
To: KNOWBE4, INC.
Reel/Frame 050902/0953 →
Continuity (4)
Continuation 15891158 · Feb 7, 2018
Continuation 15442215 · Feb 24, 2017
Provisional Application 62300399 · Feb 26, 2016
Related Publication 20200067966A1 · Feb 27, 2020
Cited By (2)
US 12,210,733 US 12,341,813