IP Library Granted Patent US 11,601,470
Granted Patent B2
US 11,601,470 · App. 17/379,086 · Granted Mar 7, 2023

Systems and methods for performing simulated phishing attacks using social engineering indicators

Inventors: Alin Irimie (Clearwater, FL); Greg Kras (Dunedin, FL); David Austin (Dunedin, FL); Benjamin Dalton (St. Petersburg, FL)
Assignee: KnowBe4, Inc.
H04L63/1483G06F40/186H04L51/18H04L51/52H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,601,470
App. No.
17/379,086
Granted
Mar 7, 2023
Kind
B2
Abstract

Systems and methods are provided for performing simulated phishing attacks using social engineering indicators. One or more failure indicators can be configured in a phishing email template, and each failure indicator can be assigned a description about that failure indicator through use of a markup tag. The phishing email template containing the markup tags corresponding to the failure indicators can be stored and can be used to generate a simulated phishing email in which the one or more markup tags are removed.

Claims (34)

1. A method comprising:

receiving, by a server, a selection of a difficulty rating for a simulated phishing email, the difficulty rating identifying a level of sophistication for the simulated phishing email, wherein a higher level of sophistication is related to a larger percentage of users interacting with one or more failure indicators of the simulated phishing email;

communicating, by the server, the simulated phishing email to one or more email accounts, the simulated phishing email comprising a link to a page having a copy of the simulated phishing email using a phishing email template, the phishing email template comprising the one or more failure indicators based at least on the difficulty rating for the simulated phishing email, each of the one or more failure indicators assigned a flag; and

causing to display the page having the copy of the simulated phishing email responsive to an interaction with the link by a user of an email account of the one or more email accounts receiving the simulated phishing email, the copy of the simulated phishing email having one or more flags from the phishing email template corresponding to the one or more failure indicators.

2. The method of claim 1 , further comprising causing to display a flag of the one or more flags in the copy of the simulated phishing email.

3. The method of claim 2 , wherein the copy of the simulated phishing email is configured to provide a description on how to identify that type of failure indicator corresponding to the flag.

4. The method of claim 1 , wherein each of the one or more failure indicators is assigned a flag of the one or more flags and a description on identifying that type of failure indicator.

5. The method of claim 1 , wherein the copy of the simulated phishing email is embedded in the page.

6. A system comprising:

one or more processors, coupled to a hardware memory and configured to:

receive a selection of a difficulty rating for a simulated phishing email, the difficulty rating identifying a level of sophistication for the simulated phishing email, wherein a higher level of sophistication is related to a larger percentage of users interacting with one or more failure indicators of the simulated phishing email;

communicate the simulated phishing email to one or more email accounts, the simulated phishing email comprising a link to a page having a copy of the simulated phishing email using a phishing email template, the phishing email template comprising the one or more failure indicators based at least on the difficulty rating difficulty rating for the simulated phishing email, each of the one or more failure indicators assigned a flag; and

cause to display the page having the copy of the simulated phishing email responsive to an interaction with the link by a user of an email account of the one or more email accounts receiving the simulated phishing email, the copy of the simulated phishing email having one or more flags from the phishing email template corresponding to the one or more failure indicators.

7. The system of claim 6 , wherein the one or more processors are further configured to cause a flag of the one or more flags in the copy of the simulated phishing email to be displayed.

8. The system of claim 7 , wherein the copy of the simulated phishing email is configured to provide a description on how to identify that type of failure indicator corresponding to the flag.

9. The system of claim 6 , wherein each of the one or more failure indicators is assigned a flag of the one or more flags and a description on identifying that type of failure indicator.

10. The system of claim 6 , wherein the copy of the simulated phishing email is embedded in the page.

11. A method comprising:

receiving, by a server, a selection of a difficulty rating and a phishing link domain for a simulated phishing email, the phishing link domain to mimic a domain associated with a trusted entity, wherein the difficulty rating identifies a level of sophistication for the simulated phishing email and a higher level of sophistication is related to a larger percentage of users interacting with one or more failure indicators of the simulated phishing email;

communicating, by a server, the simulated phishing email to one or more email accounts, the simulated phishing email comprising a link to the phishing link domain that is redirected to a page having a copy of the simulated phishing email using a phishing email template, the phishing email template comprising the one or more failure indicators; and

causing to display the page having the copy of the simulated phishing email responsive to an interaction with the link to the phishing link domain by a user of an email account of the one or more email accounts receiving the simulated phishing email, the copy of the simulated phishing email having one or more flags from the phishing email template corresponding to the one or more failure indicators.

12. The method of claim 11 , further comprising causing to display a flag of the one or more flags in the copy of the simulated phishing email.

13. The method of claim 12 , wherein the copy of the simulated phishing email is configured to provide a description on how to identify that type of failure indicator corresponding to the flag.

14. The method of claim 11 , wherein each of the one or more failure indicators is assigned a flag of the one or more flags and a description on identifying that type of failure indicator.

15. The method of claim 11 , wherein the copy of the simulated phishing email is embedded in the page.

16. A system comprising:

one or more processors, coupled to a hardware memory and configured to:

receive a selection of a difficulty rating and a phishing link domain for a simulated phishing email, the phishing link domain to mimic a domain associated with a trusted entity, wherein the difficulty rating identifies a level of sophistication for the simulated phishing email and a higher level of sophistication is related to a larger percentage of users interacting with one or more failure indicators of the simulated phishing email;

communicate the simulated phishing email to one or more email accounts, the simulated phishing email comprising a link to the phishing link domain that is redirected to a page having a copy of the simulated phishing email using a phishing email template, the phishing email template comprising the one or more failure indicators; and

cause to display the page having the copy of the simulated phishing email responsive to an interaction with the link to the phishing link domain by a user of an email account of the one or more email accounts receiving the simulated phishing email, the copy of the simulated phishing email having one or more flags from the phishing email template corresponding to the one or more failure indicators.

17. The system of claim 16 , wherein the one or more processors are further configured to cause a flag of the one or more flags in the copy of the simulated phishing email to be displayed.

18. The system of claim 17 , wherein the copy of the simulated phishing email is configured to provide a description on how to identify that type of failure indicator corresponding to the flag.

19. The system of claim 16 , wherein each of the one or more failure indicators is assigned a flag of the one or more flags and a description on identifying that type of failure indicator.

20. The system of claim 16 , wherein the copy of the simulated phishing email is embedded in the page.

Assignments (4)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT REEL/FRAME: 062627/0001 Recorded Jul 28, 2025
From: BLUE OWL CREDIT INCOME CORP. (FORMERLY KNOWN AS OWL ROCK CORE INCOME CORP.)
To: KNOWBE4, INC.
Reel/Frame 072108/0205 →
PATENT SECURITY AGREEMENT Recorded Feb 2, 2023
From: KNOWBE4, INC.
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 062627/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 19, 2021
From: IRIMIE, ALIN; KRAS, GREG; AUSTIN, DAVID; DALTON, BENJAMIN
To: KNOWBE4, INC.
Reel/Frame 056901/0563 →
Continuity (6)
Continuation 16750640 · Jan 23, 2020
Continuation 16229905 · Dec 21, 2018
Continuation 15662083 · Jul 27, 2017
Continuation 15455448 · Mar 10, 2017
Provisional Application 62442800 · Jan 5, 2017
Related Publication 20210352102A1 · Nov 11, 2021