Lucy Awareness
Visit our WebsiteContact Support
  • Wiki Overview
  • Guides
    • Quick Guides
      • Create Your First Campaign
        • Adding a New Client
        • Register an Attack Domain
        • Campaign Setup
          • Selecting an Attack
          • Attack Settings
          • Awareness Settings
          • Recipients
          • Review
        • Whitelisting
    • Installing Lucy
      • On-Premise vs Cloud Installation
      • Architecture
      • Hardware Requirements
      • Network Communication
      • Installing Lucy
      • Post Installation
    • Manage Blacklisted Domains
      • Managing Google SafeBrowsing Alerts
    • Whitelisting a Lucy Server
      • Google Workspace Whitelisting
      • Microsoft O365 Whitelisting
      • File Attack Whitelisting
    • Attack Simulations
      • Attack Types
        • Data Entry Attack
        • Hyperlink Attack
        • File Attack
        • Portable Media
        • Smishing
        • Lures
        • QR Codes
        • Ransomware Emulation
        • Technical Malware Test
          • Malware Toolkit Test Suite
        • Mail & Web Filter Test
        • Email Spoofing Test
      • Attack Template Customization
      • Firewall Protection Interval
      • Email Tracking Technologies
      • Advanced Information Gathering
      • Regular Expressions in Login Fields
      • Copy a Website
      • Redirecting Users
    • Awareness Training
      • Awareness Template Customization
      • Awareness Only Campaigns
        • Using Multiple Awareness Trainings
      • Use extended method of tracking the end of the quiz
    • Reporting Plugin
      • Deploying Office 365
      • Deploying Outlook Native
      • Deploying Gmail
  • Application Screens Reference
    • Statistics Dashboard
    • Campaigns Dashboards
    • Campaigns
      • New Campaign
        • Wizard Mode
          • Selecting an Attack
          • Attack Settings
          • Awareness Settings
          • Recipients
          • Review
        • Expert Mode
      • Campaign Settings
        • Configuration
          • Base Settings
          • Awareness Settings
          • Attack Settings
          • Schedule
            • Schedule Plan
          • Recipients
        • Advanced Settings
          • User Settings
          • Filters
          • Custom Fields
          • Reminders
        • Campaign Checks
        • Logs
        • Results
          • Summary
          • Statistics
          • Reports
          • Exports
    • Templates
      • Attack Templates
      • Awareness Templates
      • File Templates
      • Report Templates
      • Campaign Templates
      • Training Diploma
      • Download templates
      • Variables in Lucy
    • Users
      • Recipient Groups
      • End Users
      • End User Portal Settings
      • Administrative Users
      • Reputation Levels
    • Settings
      • Common System Settings
        • Domains
          • Supported TLDs
        • Firewall
        • Web Proxy
        • Mail Settings
        • SMTP Servers
        • SSL Settings
          • SSL for Campaigns
        • SMS Settings
        • Filter Settings
        • API Whitelist
          • API Routes
        • LDAP Servers
          • LDAP Sync Tool
        • LDAP Settings
        • Azure Applications
        • Azure AD Settings
        • SSO Configuration
      • Advanced System Settings
        • Advanced Settings
        • SSH Password
      • Submitted Email Settings
        • Custom Rules & Score Factors
        • Abuse Reports
        • Incident Autoresponder
        • Plugin Settings
      • Clients
        • Client Invoices
        • Client Invoice Settings
      • Backup and Restore
        • Backup Settings
      • Benchmark Sectors
      • Whitelabeling
      • File Browser
    • Incidents
    • Support
      • Status
        • Status
        • System Monitoring
        • System Health Check
        • Notifications
      • System Tests
        • Test Email
        • Performance Test
        • Spam Test
        • Mail Spoofing Test
        • Mail and Web Filter Test
      • System Logs
      • Manual
      • Update
      • Reboot
      • Mail Manager
      • Terms & Conditions
    • Account Settings
      • Two Factor Authentication
      • License
      • Invoices
    • Notifications
  • Release Notes
    • 5.4
    • 5.3.5
    • 5.3.4
    • 5.3.3
    • 5.3.2
    • 5.3.1
    • 5.3
    • 5.2.1
    • 5.2
    • 5.1
    • 5.0
    • Version 4
      • 4.14
      • 4.13
      • 4.12.1
      • 4.11
      • 4.10.1
      • 4.9.5
      • 4.9.2
      • 4.9.1
  • Legal
    • EULA
    • Privacy Policy
    • DPA, Customer and Partner Info
    • Service Level Agreement
    • Confidentiality of Campaign Data
  • When to Contact Us
    • Contact Technical Support
Powered by GitBook
On this page
  • Introduction
  • Date/Time Settings:
  • Automatically adjust DST:
  • Time Zone:
  • Date Format:
  • Use Proxy:
  • Smart Storage:
  • Default Editor Type:
  • Template Rating:
  • Auto Updates:
  • Password Settings:
  • Brute Force Protection:
  • 2FA Key:
  • Password History:
  • Account Lockout:
  • Enable Ajax Updating:
  • Export Data Separator:
  • Campaign Approval Period (days):
  • Use Full Blacklist:
  • Generate Short Recipient Links:
  • Disable Campaign Checks:
  • Benchmark Sharing:
  • Anonymous settings:
  • Anonymize Recipient Attributes:
  • Use DLP Activation String:
  • System Notification Email:

Was this helpful?

  1. Application Screens Reference
  2. Settings
  3. Advanced System Settings

Advanced Settings

PreviousAdvanced System SettingsNextSSH Password

Last updated 10 months ago

Was this helpful?

Introduction

The Advanced settings in Lucy offer administrators detailed control over security, storage management, server time settings, global anonymization, and system notifications.

Navigate to Settings -> Advanced System Settings -> Advanced Settings


Date/Time Settings:

Current System Time: Displays the current date and time according to the Lucy application server's clock.

Automatically adjust DST:

Daylight Saving Time: Lucy can automatically adjust for Daylight Saving Time changes if this option is enabled, ensuring scheduled tasks and time stamps reflect the correct time.

Time Zone:

Server Time Zone Setting: This dropdown allows you to set the time zone that the Lucy server should operate in, aligning tasks and operations with local time.

If you have active campaigns with running , you will not be able to change the Time Zone until these campaigns have been stopped.

Date Format:

Preferred Date Display: Customize how dates are displayed throughout the Lucy application, allowing consistency with regional format preferences.


Use Proxy:

When checked, this enables the use of a proxy server for network communications. It is useful if Lucy operates within a network that restricts direct internet access.

This field should be filled with the hostname or IP address of the proxy server that Lucy should use to route traffic.

Enter the port number on which the proxy server listens. Common proxy ports include 8080, 80, or 3128, but this can vary depending on the proxy service configuration.

If the proxy server requires authentication, input the username or login ID here.

Corresponding to the Proxy Login, this is where you would input the password associated with the proxy user account.

This checkbox, when selected, configures Lucy to bypass the proxy server for internal communications between Master and Slave servers. It’s a useful option when these servers are on the same local network and don't require the extra step of proxy communication, which can simplify networking and potentially improve performance.


Smart Storage:

Data Archiving Options: Manage how Lucy archives or deletes stopped campaign scenarios and Incidents to optimize storage usage.

Incident Management:

Deletes Incident Reports Automatically:

  • Daily Deletion: Incident reports are deleted every day at 02:00.

  • Weekly Deletion: Incident reports are deleted every Sunday at 02:00.

  • Monthly Deletion: Incident reports are deleted on the first day of each month at 02:00.

Scenario Management:

  • Automatically Archive: Choose to automatically move stopped campaigns to an archive after a specified number of months.

  • Automatically Delete: Set Lucy to automatically delete stopped campaigns after a certain period, maintaining storage efficiency.


Default Editor Type:

Editing Environment Preference: Select the default editor interface for crafting campaigns and templates in Lucy, such as a visual editor for a more intuitive, design-focused experience.

Template Rating:

Optionally disable the prompt asking users to rate templates on a five-star scale.


Auto Updates:

In version numbering, the patch version is indicated by the last integer. For instance, in version 4.14.1, the ".1" signifies the patch version.

Lucy's system can deploy essential updates automatically, addressing critical issues prevalent across various environments that require immediate action. While it's advised to keep this feature active for security reasons, administrators have the option to disable it if they choose to apply updates manually.

Turning off this setting will exclude your server from receiving automatic patch updates, which cover essential bug fixes and security enhancements.


Password Settings:

Enables the enforcement of specified password requirements for users.

Specifies the minimum number of characters required for user passwords.

Determines the minimum number of numerical characters that must be included in a password.

Sets the minimum number of special characters (like !, @, #, etc.) that passwords must contain.

Lists characters that are not allowed to be used in passwords.

Mandates that passwords must contain a mix of uppercase and lowercase letters to increase complexity.

Allows the setting of a time period after which users will be required to change their password. The 'Off' setting indicates no mandatory password changes are currently enforced.

Brute Force Protection:

Enable Security Image: When this setting is enabled, it integrates a CAPTCHA challenge on the login page. This serves as a defense mechanism against automated brute force attacks by requiring users to identify and input a set of characters displayed in an image, thereby confirming they are not bots.

2FA Key:

Password History:

Enable Password History: This setting, when checked, activates the tracking of users' password history. It prevents users from reusing their recent passwords when they are required to create a new one.

In this field, you would specify the number of unique new passwords a user must create before an old password can be reused, enhancing security by reducing the risk of password reuse over short periods.

This checkbox, when selected, will block the use of common passwords that are deemed too weak or too frequently used, thereby increasing the security of user accounts against common password threats.

Account Lockout:

Enable Account Lockout On Failed Login Attempt: This option, when enabled, activates the account lockout feature which secures user accounts by locking them after a specified number of unsuccessful login attempts.

Here you would specify the threshold of failed login attempts that triggers the account lockout. This is a security measure to prevent brute force attacks by limiting the number of guesses an unauthorized user can make.

This field indicates the duration of the lockout period in minutes. If an account is locked due to too many failed login attempts, it will remain inaccessible for the time specified here before the user can attempt to log in again.


Enable Ajax Updating:

Enable Ajax Updating: When this is checked, it turns on the Ajax (Asynchronous JavaScript and XML) updating feature, allowing the page to refresh or update content dynamically without the need to reload the entire page. Ajax Update Period (seconds): This field allows you to set the frequency, in seconds, at which the Ajax calls will occur to update or refresh content. In the example given, with it set to '5', Ajax will make a call to the server every five seconds to check for and retrieve any new data. This keeps the displayed content up to date in near real-time, improving user experience by providing the latest information without manual page refreshes.


Export Data Separator:

This option allows you to select the character that will be used to separate fields in exported data files. The options provided are comma, tab, colon, and semicolon. For example, choosing 'Tab', as highlighted, means that each field in the exported data will be separated by a tab space, typically used in TSV (Tab-Separated Values) files.

Export Double Quotes: An additional setting related to enclosing all fields in double quotes during data export. This is commonly used to ensure that field data that might contain commas or other separators are treated as single fields in the exported data.


Campaign Approval Period (days):

This setting specifies the timeframe in which a supervisor must approve a campaign. The number '5' entered indicates that the supervisor has a 5-day window to review and approve a campaign. If the campaign is not approved within this period, the system is configured to automatically reject the launch of the campaign. This setting helps in maintaining a controlled workflow and ensures timely action on campaign deployment.

Use Full Blacklist:

This setting, when enabled, allows for the campaign content to be checked against the complete spam blacklist database. Utilizing the full list for spam checking could significantly slow down the process due to the extensive nature of the blacklist. This option would enhance the thoroughness of the spam filtering but at the cost of performance speed.

Generate Short Recipient Links:

By enabling this option, the system will create concise links for recipients, limited to a maximum of five alphanumeric characters. This feature is designed to make links more manageable and user-friendly, potentially increasing the likelihood that recipients will engage with them. Selecting this option can be particularly useful in simplifying the appearance of URLs and making communications look cleaner.

Disable Campaign Checks:

If checked, this option would deactivate certain automated checks that are typically run on campaigns before they are launched. This includes validation of links, checking for spam triggers, etc.


Benchmark Sharing:

  • Send Anonymous Benchmark Data: By selecting this option, the system would anonymously send data regarding campaign performance to a central benchmarking service, helping to compare the effectiveness of campaigns against a broader dataset.

  • Don't ask to send Anonymous Benchmark Data: This option, when checked, will not ask to send data for benchmarking purposes.


Anonymous settings:

Global Anonymous Setting: Activating this setting will apply anonymity by default to all campaigns, ensuring that all collected data lacks personally identifiable information, in compliance with various privacy laws.

Anonymize Recipient Attributes:

  • Hide Country Attribute: Masks the country information of the recipients in reports.

  • Hide OS Attribute: Conceals the operating system details of the recipients' devices.

  • Hide Browser Attribute: Omits the browser type used by the recipients.

  • Hide Location Attribute: Removes the location data of the recipients from visibility.

  • Hide Division Attribute: Hides the division or departmental information of the recipients.

  • Hide Comment Attribute: Ensures that any comments or notes related to recipients are not shown.

  • Hide Staff Type Attribute: Obscures the designation or staff type of the recipients.


Use DLP Activation String:

The DLP String functionality is designed to enhance email security by embedding specific identifying data within the body of emails:

  • DLP String Activation: When enabled, this feature allows for the inclusion of specific data points in the email body to help classify emails and manage responses effectively.

  • Data Included in DLP String:

    • Recipient's Email

    • Email's SHA256 hash

    • Victim ID, a unique identifier within the system

    • Campaign ID, which identifies the specific email campaign

  • Invisibility of DLP String: If discretion is required, the visibility of the DLP string can be concealed by setting the DLP String Font Size to 0px. This ensures that the string does not disrupt the recipient's reading experience while still maintaining the functionality for administrative purposes.


System Notification Email:

This setting is used to specify the email address from which system-generated notifications, such as alerts, password reset notifications, updates, or automated responses, are sent to users.


This input field is where you should enter your Authy 2FA API key. To obtain this key, you must create an account at , a two-factor authentication (2FA) service provider. Once you have an account, Authy will provide an API key which you can input here to enable 2FA for added security in your Lucy application.

By enabling the DLP String, users can organize and sort victims' replies in the with greater ease, allowing for more efficient email management and review processes.

Lucy will send system notification emails from the defined mail server (internal postfix/external SMTP) as defined in

Schedulers
Authy.com
Mail Manager
Mail Settings