IP Library Granted Patent US 11,936,687
Granted Patent B2
US 11,936,687 · App. 17/745,744 · Granted Mar 19, 2024

Systems and methods for end-user security awareness training for calendar-based threats

Inventors: Perry Carpenter (Austin, AR); Kathy Wattman (Dunedin, FL); Morgan Flake (Clearwater, FL); Detlev Weise (Berlin, DE); John Just (Palm Harbor, FL); Kevin Mitnick (Clearwater, FL)
Assignee: KnowBe4, Inc.
H04L63/1483G06F9/453G06Q10/1093H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,936,687
App. No.
17/745,744
Granted
Mar 19, 2024
Kind
B2
Abstract

Systems and methods are described for providing calendar-based simulated phishing attacks to users of an organization. Initially, a context is identified for a calendar-based simulated phishing attack directed towards a user. An electronic calendar invitation for the calendar-based simulated phishing attack is then generated using the context. Thereafter, the electronic calendar invitation may be communicated to an electronic calendar of the user.

Claims (28)

1. A method comprising:

identifying, by one or more servers, a user for which to communicate a simulated phishing attack that uses an electronic calendar invitation;

generating, by the one or more servers, the electronic calendar invitation of the simulated phishing attack with one or more meeting invitees appearing to have accepted the electronic calendar invitation;

communicating, by the one or more servers, the electronic calendar invitation to an electronic calendar of the user; and

identifying, by the one or more servers, an interaction with the electronic calendar invitation by the user.

2. The method of claim 1 , further comprising identifying, by one or more servers, a context of the user for the simulated phishing attack.

3. The method of claim 2 , further comprising generating, by the one or more servers, the electronic calendar invitation using the context.

4. The method of claim 2 , further comprising identifying, by one or more servers, the context for the user based at least on other electronic calendar invitations of the user.

5. The method of claim 2 , further comprising identifying, by one or more servers, the context from information from one or more emails associated with the user or from one or more mailboxes of the user.

6. The method of claim 1 , further comprising causing, by the one or more servers, a schedule-tracking information panel of a calendar application to display one or more of the meeting invitees as having accepted the electronic calendar invitation.

7. The method of claim 1 , further comprising inserting, by the one or more servers, benign content into the electronic calendar invitation.

8. The method of claim 7 , wherein the content facilitates delivery of security awareness training to the user responsive to the user's interaction with the electronic calendar invitation.

9. The method of claim 1 , further comprising generating, by the one or more servers, the electronic calendar invitation with a link or an attachment to training materials.

10. The method of claim 1 , wherein the interaction comprises one of: accepting the electronic calendar invitation, tentatively accepting the electronic calendar invitation, declining the electronic calendar invitation, proposing a new meeting time for the electronic calendar invitation, clicking on a link in the electronic calendar invitation, opening or downloading an attachment in the electronic calendar invitation, forwarding the electronic calendar invitation, or deleting the electronic calendar invitation.

11. A system comprising:

one or more servers, comprising one or more processors, coupled to memory, the one or more servers configured to:

identify a user for which to communicate a simulated phishing attack that use an electronic calendar invitation;

generate the electronic calendar invitation of the simulated phishing attack with one or more meeting invitees appearing to have accepted the electronic calendar invitation;

communicate the electronic calendar invitation to an electronic calendar of the user; and identify an interaction with the electronic calendar invitation by the user.

12. The system of claim 11 , wherein the one or more servers are further configured to identify a context of the user for the simulated phishing attack.

13. The system of claim 12 , wherein the one or more servers are further configured to generate the electronic calendar invitation using the context.

14. The system of claim 12 , wherein the one or more servers are further configured to identify the context for the user based at least on other electronic calendar invitations of the user.

15. The system of claim 12 , wherein the one or more servers are further configured to identify the context from information from one or more emails associated with the user or from one or more mailboxes of the user.

16. The system of claim 11 , wherein the one or more servers are further configured to cause a schedule-tracking information panel of a calendar application to display one or more of the meeting invitees as having accepted the electronic calendar invitation.

17. The system of claim 11 , wherein the one or more servers are further configured to insert benign content into the electronic calendar invitation.

18. The system of claim 17 , wherein the content facilitates delivery of security awareness training to the user responsive to the user's interaction with the electronic calendar invitation.

19. The system of claim 11 , wherein the one or more servers are further configured to generate the electronic calendar invitation with a link or an attachment to training materials.

20. The system of claim 11 , wherein the interaction comprises one of: accepting the electronic calendar invitation, tentatively accepting the electronic calendar invitation, declining the electronic calendar invitation, proposing a new meeting time for the electronic calendar invitation, clicking on a link in the electronic calendar invitation, opening or downloading an attachment in the electronic calendar invitation, forwarding the electronic calendar invitation, or deleting the electronic calendar invitation.

Assignments (4)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT REEL/FRAME: 062627/0001 Recorded Jul 28, 2025
From: BLUE OWL CREDIT INCOME CORP. (FORMERLY KNOWN AS OWL ROCK CORE INCOME CORP.)
To: KNOWBE4, INC.
Reel/Frame 072108/0205 →
PATENT SECURITY AGREEMENT Recorded Feb 2, 2023
From: KNOWBE4, INC.
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 062627/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 21, 2022
From: CARPENTER, PERRY; WATTMAN, KATHY; FLAKE, MORGAN; WEISE, DETLEV; JUST, JOHN; MITNICK, KEVIN
To: KNOWBE4, INC.
Reel/Frame 062170/0692 →
Continuity (3)
Continuation 17324723 · May 19, 2021
Provisional Application 63028890 · May 22, 2020
Related Publication 20220279017A1 · Sep 1, 2022