IP Library Granted Patent US 11,641,375
Granted Patent B2
US 11,641,375 · App. 17/233,269 · Granted May 2, 2023

Systems and methods for reporting based simulated phishing campaign

Inventors: Greg Kras (Dunedin, FL); Alin Irimie (Palm Harbor, FL)
Assignee: KnowBe4, Inc.
H04L63/1491H04L51/046H04L51/212H04L51/42H04L63/1483G09B19/0053
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,641,375
App. No.
17/233,269
Granted
May 2, 2023
Kind
B2
Abstract

Systems and methods are described for leveraging the knowledge and security awareness of well-informed users in an organization to protect other users and train them to identify new phishing attacks. Initially, a report of a message being suspicious may be identified and it may be determined whether message is a malicious phishing message. In an example, a well-informed user of an organization may report the message as suspicious. Further, on determining the message to be a malicious phishing message, a simulated phishing message or a template may be created. The simulated phishing message may then be communicated to one or more devices of one or more users.

Claims (23)

1. A method for creating a simulated phishing message based on a phishing attack, the method comprising:

(a) identifying, by one or more processors, a report of a message, the message received by a user and reported as being suspicious during the phishing attack;

(b) determining, by the one or more processors, that the message is a malicious phishing message instead of a simulated phishing message communicated by the one or more processors;

(c) creating, by the one or more processors responsive to the determination that the message is a malicious phishing message and using the content of the malicious phishing message, a simulated phishing message or a template for the simulated phishing message by one of removing or modifying one or more malicious elements from the content of the malicious phishing message wherein the malicious elements in links of the message to include one or more links to training content when interacted with by a user;

(d) causing, by the one or more processors, the message in a messaging application of a user to be replaced with the simulated phishing message.

2. The method of claim 1 , wherein (a) further comprises receiving, by the one or more processors, a forward of the message, wherein the message is an email identified as potentially malicious by the report.

3. The method of claim 1 , wherein (a) further comprises identifying, by the one or more processors, the message being suspicious in a mailbox comprising one or more emails of the one or more users.

4. The method of claim 1 , wherein (b) further comprises determining, by the one or more processors, that the message is a malicious phishing email using a rule set of one or more characteristic detection rules.

5. The method of claim 1 , wherein (c) further comprising modifying, by the one or more processors, one or more malicious elements of the message to create the simulated phishing message or the template for the simulated phishing message.

6. The method of claim 1 , wherein (c) further comprising creating, by the one or more processors, the template to be customizable to include one of a specific user reference or content.

7. The method of claim 1 , further comprising causing, by the one or more processors, the simulated phishing message to be moved from one of a delete or trash folder of the messaging application of the user to an inbox of the messaging application.

8. A system for creating a simulated phishing message based on a phishing attack, the system comprising:

one or more processors, coupled to memory, and configured to:

identify a report of a message, the message received by a user and reported as being suspicious s during the phishing attack;

determine that the message is a malicious phishing message instead of a simulated phishing message communicated by the one or more processors

create, responsive to the determination that the message is a malicious phishing message and using the content of the malicious phishing message, a simulated phishing message or a template for the simulated phishing message by one of removing or modifying one or more malicious elements from the content of the malicious phishing message and modifying one or more links of the message to include one or more links to training content when interacted with by a user; and

cause, by the one or more processors, the message in a messaging application of a user to be replaced with the simulated phishing message.

9. The system of claim 8 , wherein the one or more processors are further configured to receive a forward of the message, wherein the message is an email identified as potentially malicious by the report.

10. The system of claim 8 , wherein the one or more processors are further configured to identify the message being suspicious in a mailbox comprising one or more emails of the one or more users.

11. The system of claim 8 , wherein the one or more processors are further configured to determine that the message is a malicious phishing email using a rule set of one or more characteristic detection rules.

12. The system of claim 8 , wherein the one or more processors are further configured to modify one or more malicious elements of the message to create the simulated phishing message or the template for the simulated phishing message.

13. The system of claim 8 , wherein the one or more processors are further configured to create the template to be customizable to include one of a specific user reference or content.

14. The system of claim 8 , wherein the one or more processors are further configured to cause the simulated phishing message to be moved from one of a delete or trash folder of the messaging application of the user to an inbox of the messaging application.

Assignments (4)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT REEL/FRAME: 062627/0001 Recorded Jul 28, 2025
From: BLUE OWL CREDIT INCOME CORP. (FORMERLY KNOWN AS OWL ROCK CORE INCOME CORP.)
To: KNOWBE4, INC.
Reel/Frame 072108/0205 →
PATENT SECURITY AGREEMENT Recorded Feb 2, 2023
From: KNOWBE4, INC.
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 062627/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 16, 2021
From: KRAS, GREG; IRIMIE, ALIN
To: KNOWBE4, INC.
Reel/Frame 055949/0035 →