IP Library Granted Patent US 11,038,914
Granted Patent B1
US 11,038,914 · App. 17/175,892 · Granted Jun 15, 2021

Systems and methods for effective delivery of simulated phishing campaigns

Inventors: Mark William Patton (Clearwater, FL); Daniel Cormier (Clearwater, FL); Greg Kras (Dunedin, FL)
Assignee: KnowBe4, Inc.
H04L63/1433H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,038,914
App. No.
17/175,892
Granted
Jun 15, 2021
Kind
B1
Abstract

Systems and methods are described for verifying whether simulated phishing communications are allowed to pass by a security system of an email system to email account of users. The delivery verification campaign may be configured to include the selection of the one or more types of simulated phishing communications from the plurality of types of simulated phishing communications. The selected one or more types of simulated phishing communications of the delivery verification campaign may be communicated to one or more email accounts. It is determined whether or not each of the one or more types of simulated phishing communications was allowed by the security system to be received unchanged at the one or more email accounts.

Claims (44)

1. A method comprising:

identifying, by one or more processors, a mailbox of an email system with a security system;

identifying, by the one or more processors, a type of simulated phishing communication;

communicating, by the one or more processors, a simulated phishing communication of the type of simulated phishing communication to the mailbox;

determining, by the one or more processors, that the simulated phishing communication was received, unchanged by the security system, at the mailbox;

determining, by the one or more processors, that a second simulated phishing communication of a second type of simulated phishing communication was not received at the mailbox; and

identifying, by the one or more processors, the second type of simulated phishing communication to exclude for a subsequent simulated phishing communication communicated to one or more users of the email system.

2. The method of claim 1 , further comprising identifying, by the one or more processors, the type of simulated phishing communication from a plurality of types of simulated phishing communications.

3. The method of claim 2 , wherein the plurality of types of simulated phishing communications comprises at least one of the following: a simulated phishing communication with an attachment, a simulated phishing communication with one or more links and a simulated phishing communication with a macro.

4. The method of claim 1 , further comprising creating, by the one or more processors, the simulated phishing communication based at least on the type of simulated phishing communication.

5. The method of claim 1 , further comprising identifying, by the one or more processors, that the security system allows the type of simulated phishing communication to be communicated to one or more mailboxes of the email system.

6. The method of claim 1 , further comprising selecting, by the one or more processors responsive to the determination, the type of simulated phishing communication to use for a subsequent simulated phishing communication communicated to one or more users of the email system.

7. The method of claim 1 , further comprising determining, by the one or more processors, that a third simulated phishing communication of a third type of simulated phishing communication was received changed at the mailbox.

8. The method of claim 7 , further comprising identifying, by the one or more processors responsive to the determination that the third simulated phishing communication of the third type of simulated phishing communication was received changed at the mailbox, the third type of simulated phishing communication to exclude for a subsequent simulated phishing communication communicated to one or more users of the email system.

9. A system comprising:

one or more processors, coupled to memory and configured to:

identify a mailbox of an email system with a security system;

identify a type of simulated phishing communication;

communicate a simulated phishing communication of the type of simulated phishing communication to the mailbox;

determine that the simulated phishing communication was received, unchanged by the security system, at the mailbox;

determine that a second simulated phishing communication of a second type of simulated phishing communication was not received at the mailbox; and

identify the second type of simulated phishing communication to exclude for a subsequent simulated phishing communication communicated to one or more users of the email system.

10. A system comprising:

one or more processors, coupled to memory and configured to:

identify a mailbox of an email system with a security system;

identify a type of simulated phishing communication;

communicate a simulated phishing communication of the type of simulated phishing communication to the mailbox;

determine that the simulated phishing communication was received, unchanged by the security system, at the mailbox;

determine that a second simulated phishing communication of a second type of simulated phishing communication was received changed at the mailbox; and

identify the second type of simulated phishing communication to exclude for a subsequent simulated phishing communication communicated to one or more users of the email system.

11. The system of claim 10 , wherein the one or more processors are further configured to identify the type of simulated phishing communication from a plurality of types of simulated phishing communications.

12. The system of claim 11 , wherein the plurality of types of simulated phishing communications comprises at least one of the following: a simulated phishing communication with an attachment, a simulated phishing communication with one or more links and a simulated phishing communication with a macro.

13. The system of claim 10 , wherein the one or more processors are further configured to create the simulated phishing communication based at least on the type of simulated phishing communication.

14. The system of claim 10 , wherein the one or more processors are further configured to identify that the security system allows the type of simulated phishing communication to be communicated to one or more mailboxes of the email system.

15. The system of claim 10 , wherein the one or more processors are further configured to select, responsive to the determination, the type of simulated phishing communication to use for a subsequent simulated phishing communication communicated to one or more users of the email system.

16. The system of claim 10 , wherein the one or more processors are further configured to determine that a third simulated phishing communication of a third type of simulated phishing communication was not received at the mailbox.

17. The system of claim 16 , wherein the one or more processors are further configured to identify responsive to the determination that the third simulated phishing communication of the third type of simulated phishing communication was not received at the mailbox, the third type of simulated phishing communication to exclude for a subsequent simulated phishing communication communicated to one or more users of the email system.

18. A method comprising:

identifying, by one or more processors, a mailbox of an email system with a security system;

identifying, by the one or more processors, a type of simulated phishing communication;

communicating, by the one or more processors, a simulated phishing communication of the type of simulated phishing communication to the mailbox;

determining, by the one or more processors, that the simulated phishing communication was received, unchanged by the security system, at the mailbox;

determining, by the one or more processors, that a second simulated phishing communication of a second type of simulated phishing communication was received changed at the mailbox; and

identifying, by the one or more processors, the second type of simulated phishing communication to exclude for a subsequent simulated phishing communication communicated to one or more users of the email system.

Assignments (4)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT REEL/FRAME: 062627/0001 Recorded Jul 28, 2025
From: BLUE OWL CREDIT INCOME CORP. (FORMERLY KNOWN AS OWL ROCK CORE INCOME CORP.)
To: KNOWBE4, INC.
Reel/Frame 072108/0205 →
PATENT SECURITY AGREEMENT Recorded Feb 2, 2023
From: KNOWBE4, INC.
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 062627/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 15, 2021
From: PATTON, MARK WILLIAM; CORMIER, DANIEL; KRAS, GREG
To: KNOWBE4, INC.
Reel/Frame 055260/0046 →
Continuity (1)
Continuation 17001070 · Aug 24, 2020