# Wiki Overview

{% hint style="info" %}
This wiki is for Lucy version 5.2 and higher.
{% endhint %}

This wiki assists users in navigating and utilizing Lucy's platform. Whether you're looking for in-depth technical details about Lucy's platform specifications and features, or need step-by-step guidance for developing comprehensive security awareness strategies, this wiki is designed to be your go-to resource.

***

**This wiki is organized into two primary sections:**

<table data-card-size="large" data-view="cards" data-full-width="false"><thead><tr><th align="center"></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td align="center"><p><strong>Application Reference</strong></p><p></p><p>Provides detailed information on Lucy's platform specifications and features.</p></td><td><a href="/pages/fUGZPZ3UpDokqEBY6fiR">/pages/fUGZPZ3UpDokqEBY6fiR</a></td><td></td></tr><tr><td align="center"><p><strong>Guides</strong></p><p></p><p>Provides step-by-step instructions for administrators to create, configure, and troubleshoot platform-related topics.</p></td><td><a href="/pages/c3F6Y3dAyqwCuLYOMmPi">/pages/c3F6Y3dAyqwCuLYOMmPi</a></td><td></td></tr></tbody></table>

***

## Quick Links

<table data-view="cards" data-full-width="false"><thead><tr><th align="center"></th><th data-hidden></th><th data-hidden></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td align="center">Quick Start</td><td></td><td></td><td><a href="/pages/BsKbMJMBFO3QGCYXLPy6">/pages/BsKbMJMBFO3QGCYXLPy6</a></td></tr><tr><td align="center">Installing Lucy</td><td></td><td></td><td><a href="/pages/dgZPyndqvJkHhKewbUln">/pages/dgZPyndqvJkHhKewbUln</a></td></tr><tr><td align="center">Release Notes</td><td></td><td></td><td><a href="/pages/JiUYS3KvFrrGZg8pCWpi">/pages/JiUYS3KvFrrGZg8pCWpi</a></td></tr></tbody></table>

***


# Guides

Guides provide step-by-step instructions for administrators to create, configure, and troubleshoot platform-related topics.


# Quick Guides


# Create Your First Campaign

Before launching your first campaign, configure the key settings outlined in this guide to streamline the setup process and minimize delays. Lucy is designed for all experience levels, offering a versatile and intuitive interface.


# Adding a New Client

<details>

<summary>What is a Client?</summary>

Lucy’s architecture utilizes a client framework to organize information, where each client acts as a container for elements such as campaigns, templates, and user access. This structure promotes data segregation and improved security, ensuring data integrity and confidentiality. Clients can be customized to suit various needs: a single client is appropriate for one organization, while managing multiple organizations requires distinct clients for each, allowing tailored control and security for every organization.

</details>

***

### Create a Client

{% hint style="info" %}
Navigate to **Settings -> Clients -> Clients**
{% endhint %}

<div align="center" data-full-width="false"><figure><img src="/files/VRle5vc4Nsm03Q9Y8eag" alt="" width="563"><figcaption></figcaption></figure></div>

***

Select "New Client"<br>

<figure><img src="/files/FGDo5x0aCIdRV6y0YWxu" alt=""><figcaption></figcaption></figure>

***

To set up a client in Lucy, you only need to enter the client's name. Additional fields can be filled in for record-keeping and statistical analysis.

<figure><img src="/files/7x8f3XuNeoPbWxwFBGt9" alt=""><figcaption></figcaption></figure>

***


# Register an Attack Domain

<details>

<summary>Why do you need to register an Attack Domain?</summary>

Registering an attack domain serves two key purposes:

1. Enables creating domains resembling the targeted organization, enhancing realism (e.g., "mirconsoft.com" instead of "microsoft.com").
2. Prevents blacklisting of the Lucy system domain, safeguarding your server and ensuring effective future campaigns.

</details>

Configuring an attack domain in Lucy is simplified with our GoDaddy API integration, which automatically sets up DNS records for email sending and landing page hosting.

{% hint style="info" %}
Navigate to **Settings -> Common System Settings -> Domains**
{% endhint %}

<figure><img src="/files/HFD0vhPmh1ioRQZvoDfk" alt=""><figcaption></figcaption></figure>

Select "Register"\
\
Enter the modified "spoofed" domain you would like to use and check whether it is available for registration. When the check is complete you will be taken to the registration page.

<figure><img src="/files/ukOD1q8ruhQ7p3HEHY7g" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
Provide a valid email address for WHOIS validation, domain expiration alerts, and DNS management access. Ensure accurate details when registering your domain as it is linked to your organization.
{% endhint %}

<figure><img src="/files/WLr38IDWBs9KvqVZgE3V" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
After registering your domain, the automatic DNS configuration typically completes within minutes. However, in very rare cases, it may take 4 to 8 hours for all DNS servers to fully propagate.
{% endhint %}


# Campaign Setup

**1.1** On the Lucy dashboard, select "New Campaign"

<figure><img src="/files/LQoQyqmGVhfWvDhk97q5" alt=""><figcaption></figcaption></figure>

**1.2** Choose the Campaign Type:\
\
Lucy's campaign creation strategy includes three key elements: Attack Simulations, Employee Education (Awareness), and Infrastructure Tests. These components can operate individually or together.

<figure><img src="/files/6B2Ij9QhOjLwXXcTKqqR" alt=""><figcaption></figcaption></figure>

{% tabs %}
{% tab title="Attack Simulation" %}
To begin creating a campaign with an Attack, first select the Attack type. You can also link an Awareness training template in subsequent steps if desired.

[**Data Entry Attack:**](/guides/attack-simulations/attack-types/data-entry-attack)\
\
The recipient will receive an email with a link that leads to a fake webpage designed to harvest credentials. A successful attack occurs when the recipient enters their data on this page.

[**Hyperlink Attack:**](/guides/attack-simulations/attack-types/hyperlink-attack)

The recipient will receive an email with a link, and the attack is deemed successful as soon as they click on this link. There is no associated landing page in this scenario.

[**File Attack:**](/guides/attack-simulations/attack-types/file-attack)

Like Data Entry Attacks, the user receives an email with two potential actions: they can click a link to visit a landing page where they download an executable file, or the executable file can be directly attached to the email itself.

[**Portable Media Attack:**](/guides/attack-simulations/attack-types/portable-media)

LUCY provides the capability to create files for use on various removable media devices, including CDs, USBs, DVDs, SD Cards, and others. The most common approach involves attacks via USB sticks.

[**Smishing:**](/guides/attack-simulations/attack-types/smishing)

Smishing, also known as SMS Phishing, is a deceptive tactic where fraudulent text messages are sent to trick recipients into revealing sensitive information such as credit card details or passwords. It's important to note that this type of attack can only be configured in [**Expert Mode**](/application-reference/campaigns/expert-mode).
{% endtab %}

{% tab title="Educate Employees" %}
This selection is reserved for Awareness-only campaigns, where an administrator aims to focus solely on training their users.
{% endtab %}

{% tab title="Infrastructure Tests" %}
Infrastructure tests are designed to assess your organization's defenses against common attack vectors.

**Technical Malware Test**: Evaluate your technical defenses against malware by simulating a malware attack and observing whether the current security setup can detect and neutralize the threat.

**Mail & Web Filter Test**: Assesses the effectiveness of your email and web filtering systems. This test sends non-malicious simulated spam and phishing emails to see if the filters can successfully block these potential threats.

**Spoofing Test**: Checks the robustness of the system against email spoofing. It tests whether someone can mimic or 'spoof' an email address from your domain, which is a common tactic used in phishing and social engineering attacks.
{% endtab %}
{% endtabs %}


# Selecting an Attack

Select one of our multiple Attack templates that closely resembles your simulation goal.

<details>

<summary>Search Hints</summary>

To ensure clear communication, always send templates in the recipient's native language. Our language filter showcases templates already translated into your target languages.\
\ <img src="/files/iKhx0eITXgqlTjj9LreU" alt="" data-size="original">\
\
Similarly, you can also search for the **Target Audience**, **Category,** and **Difficulty Level**\
\
![](/files/z1WsUb1G4WzcEZGT6fW5)

</details>

Let's focus on the **ChatGPT Scenario**:\
\
Lucy's wizard is designed for efficient previewing of the Message Template and Landing page. It provides real-time dynamic access to test the template before committing it to your campaign.<br>

<figure><img src="/files/ICjgWf8fY6z1SpB3P1E9" alt="" width="204"><figcaption></figcaption></figure>

**2.1** Previewing the Landing Page:\
\
Select -> Preview -> Landing -> the Language you would like to view.

<figure><img src="/files/cUXZu2VrQmAi2I78RMTK" alt="" width="208"><figcaption></figcaption></figure>

This action will open a new tab in your browser, enabling you to dynamically test the template's functionality.

<figure><img src="/files/1QWIspSfauQe21xv7SIb" alt="" width="334"><figcaption></figcaption></figure>

**2.2** Previewing the Email Message:

Similarly, you can also preview the email message

<figure><img src="/files/WM0Lgz3ao0xCCPZfxAcn" alt="" width="208"><figcaption></figcaption></figure>

After selecting the Attack template you want to use, click on 'Next'


# Attack Settings

Next, define the Campaign and Attack settings, then link the relevant Awareness Training.\
\
**3.1** Campaign settings:\
\
Specify the campaign name, associated client, and additional options in this section.

<figure><img src="/files/boxWO8PPQdUnpikxMidF" alt="" width="375"><figcaption></figcaption></figure>

**3.2** Attack Settings:

Next, we will specify the parameters for the Attack.\
\
**Domain** -> Select the attack domain registered in [step 2](/guides/quick-guides/create-your-first-campaign/register-an-attack-domain) of the Quick Guides. This will be the primary domain for the email address and the associated landing page.

<figure><img src="/files/eWLZ8Nrft0nxITMY5gK2" alt="" width="281"><figcaption></figcaption></figure>

**SSL** -> Lucy seamlessly integrates with Let's Encrypt to automatically create, validate, and bind SSL certificates to your domain.

<details>

<summary>What is SSL?</summary>

SSL (Secure Sockets Layer) acts as a protective shield. It ensures that data exchanged with the phishing page remains secure and protected from eavesdropping. This safeguard helps maintain the realism and safety of your simulation.

Without an SSL certificate, recipients will see a red warning page, indicating an insecure site. This can undermine the authenticity of your simulation.

</details>

<figure><img src="/files/ohYfemvpBg3HLlURJwsr" alt="" width="269"><figcaption></figcaption></figure>

**Sender Name**, **Email**, and **Subject** -> Define the sender of the attack, their email address, and the subject.

{% hint style="warning" %}
Using a sender email that matches your registered domain is recommended. This improves email deliverability by leveraging existing DNS records and reduces the risk of emails being flagged as spam.
{% endhint %}

<figure><img src="/files/szUmc1J2kQbaONczXNCJ" alt="" width="282"><figcaption></figcaption></figure>

**3.3** Editing the Email Content:\
\
The Lucy email editor is a versatile tool that lets you tailor email content to your preferred language and structure. Most templates include variable placeholders like **%name%**, which auto-insert each recipient's name for a personalized touch, making spear-phishing attacks more effective.

<figure><img src="/files/WqtsFdoV5JF4Xvhv2c1V" alt="" width="563"><figcaption></figcaption></figure>

{% hint style="warning" %}
The objective of simulated attacks is to persuade users to click on an email link, enabling the collection of click-through statistics.
{% endhint %}

To add a **new** link in your email, highlight the desired word or phrase, click the link icon, and enter **%link%** in the URL field.

<figure><img src="/files/r5GsyV6ZKuXghjELxBnW" alt="" width="563"><figcaption></figcaption></figure>

{% hint style="info" %}
The `%link%` placeholder automatically generates a URL combining your registered attack domain with a unique tracking hash for each recipient, allowing for detailed tracking.

For example, with "open-ai.net" as the domain, the recipient sees a link like "[https://open-ai.net/<mark style="background-color:red;">xvcskahjry</mark>](https://open-ai.net/xvcskahjry)", enabling precise monitoring of individual interactions.
{% endhint %}


# Awareness Settings

**3.4** **Adding an Awareness Template to Your Campaign**

Select **Add Awareness Training** located beneath the attack email editor.

<figure><img src="/files/B1YtZRVDx1JHB5OFkdON" alt=""><figcaption></figcaption></figure>

You will be redirected to the Awareness Template Gallery, where you can search for, preview, and select templates that detail the awareness training.

To complement the AI-simulated attack, find a template that focuses on the specific attack vector used.

<figure><img src="/files/bJGJmMKtT7fhQ8Nbi18Y" alt=""><figcaption></figcaption></figure>

<details>

<summary>Preview the Awareness Template</summary>

Similar to the Attack template gallery, you can dynamically preview both the email and landing page templates for your Awareness training.\
\ <img src="/files/81NayOMAQmymm6vXGKQC" alt="" data-size="original">

</details>

**4.1** Awareness Settings:\
\
Next, define the Awareness domain and email settings. This section is found below the Attack email template editor.

<figure><img src="/files/D3XrXKI0IJ3vDHhlyQfS" alt=""><figcaption></figcaption></figure>

**Domain ->** You can either use the default system domain or send the awareness from a trusted domain.

<details>

<summary>Awareness Domain Hints</summary>

When directing recipients to Awareness content, it's important to associate a familiar and trusted domain.&#x20;

Recipients, having just completed a successful phishing simulation, may be wary of clicking unfamiliar links. Using a known domain can reduce this hesitation and increase engagement with the training material.\
\
There are two methods to accomplish this:\
\
1\. You can send emails from a domain associated with your company using the internal Lucy mail server. Please make sure that all necessary DNS records are correctly configured and pointing to your Lucy server before initiating the campaign. For more details, refer to our [domain section](/application-reference/settings/common-system-settings/domains).\
\
2\. You can directly authenticate to your company SMTP server to send the training directly from your internal mail server, refer to our [SMTP section](/application-reference/settings/common-system-settings/smtp-servers).

</details>

**4.2** Adjust the Awareness email body:\
\
Lucy comes with generic email responses. It is highly encouraged to personalize these Awareness Training emails according to your company's branding and ethos. <br>

<figure><img src="/files/9gxdc0iGCrUZYBdYp3ZD" alt=""><figcaption></figcaption></figure>

**4.3** Click 'Next'


# Recipients

**Adding your recipients**\
\
Lucy offers several ways to add recipients within the platform. Using the wizard, you can either choose an existing group or create a new one.

{% hint style="info" %}
For additional details on how to create existing recipient groups with import capabilities, including automatic[ LDAP](/application-reference/settings/common-system-settings/ldap-settings) or [Azure Entra ID](/application-reference/settings/common-system-settings/azure-applications) integration, please refer to our section on [recipients](/application-reference/users/recipient-groups).
{% endhint %}

In this scenario, we will choose the "New Group" option and input the recipient's name and email address. This process can be repeated to add more recipients.

<figure><img src="/files/ifEUaThk2bP4evCSlNM0" alt=""><figcaption></figcaption></figure>

Click "Next" once all recipients have been added.


# Review

**Review your campaign**\
\
Your campaign is now configured. This page provides a detailed summary of all applied settings, letting you review and modify as needed.

<figure><img src="/files/oT3z1yt93jMy4iBcXo1P" alt=""><figcaption></figcaption></figure>

If everything looks correct, click "Finish." A pop-up will appear with three selectable options:<br>

<figure><img src="/files/sDX1rTq7qTx5xDdq7Oq6" alt=""><figcaption></figcaption></figure>

**Start Campaign** -> Begin the campaign immediately.

\
**Initiate Test Run** -> This is a great way to test the campaign by first sending it to a specified email address, ensuring functionality and data collection are working correctly.

\
**Go to Campaign** -> Choosing this option will take you to the campaign dashboard, where you can set advanced parameters like scheduling and IP filtering.<br>

{% hint style="danger" %}
**Important:** Before launching your campaign, ensure your Lucy server is whitelisted to prevent non-deliveries. See the next section on **Whitelisting**.
{% endhint %}


# Whitelisting

<details>

<summary>What is Whitelisting?</summary>

Whitelisting involves allowing certain IP addresses to bypass an organization's defense systems, ensuring successful phishing simulations and awareness training. This requires adding the Lucy server IP and sender domain(s) to trusted sources in email gateways, anti-virus software, and web proxies, preventing simulated phishing emails from being blocked or marked as spam.

</details>

> The main objective of a Security Awareness program is to evaluate the recipients' awareness, not the strength of your network defenses. Ensure your defensive systems allow traffic from your Lucy server so it isn't blocked.

{% hint style="info" %}
Below are quick guides for **Microsoft 365 (O365)** and **Google Workspace**. For more detailed information, refer to our[ advanced whitelisting guides.](/guides/whitelisting-a-lucy-server)
{% endhint %}

**Google Workspace:**

1. Log in to `admin.google.com` and navigate to "Apps" -> "Google Workspace" -> "Gmail".
2. Under "Spam, phishing, and malware", add the Lucy IPv4 to "Email Allowlist" and save.
3. In the same menu, go to "Inbound Gateway". Add Lucy IPv4, activate Message Tagging, add a symbol set to the Regular Expression field, select "Disable Gmail spam evaluation on mail from this gateway", and save.

   <figure><img src="/files/J5TEtohzaKtGAUKeBcHj" alt="" width="360"><figcaption></figcaption></figure>

**Microsoft 365 (O365):**

1. Open the Microsoft 365 Defender portal -> `security.microsoft.com`
2. Go to Email & Collaboration > Policies & Rules > Threat Policies.
3. In Advanced Delivery, under Phishing Simulation, click "Edit" to add the sending domain, the IP of Lucy, and the simulation URL.<br>

<figure><img src="/files/HsZyHozugVLEwtqKLxAR" alt="" width="375"><figcaption></figcaption></figure>

<br>


# Installing Lucy


# On-Premise vs Cloud Installation

### Introduction

This article explores Lucy's adaptable architecture for on-premise and cloud-hosted setups.

### **Cloud Installation Advantages:**

<details>

<summary>VPS and Dedicated Root Server Hosting with LUCY Security AG</summary>

LUCY provides clients with the option to rent Virtual Private Servers (VPS) or dedicated physical servers, mainly located in Europe. There is also the flexibility to establish servers in other countries upon request. For services in Switzerland, LUCY partners with Hosttech.

**EU Data Centers**

LUCY Security uses Hetzner Online's data centers, a trusted provider since 1997. With data centers in Germany and Finland, Hetzner boasts DIN ISO/IEC 27001 certification for its ISMS. Their cloud servers feature AMD EPYC 2nd Gen and Intel® Xeon® Gold processors with fast NVMe SSDs.

Standard Virtualized Private Server configurations include 8 vCPUs, 16 GB RAM, 240 GB SSD, and 20 TB Traffic.

**US Data Center**

Through Hetzner Online, LUCY Security extends its hosting services to the US, specifically to Ashburn, Virginia, within the Data Center Alley. Clients can request a VPS in this region by specifying a preference for the US zone.

**High Availability**

Despite efforts to maintain uninterrupted service, potential downtime risks include DDoS attacks, power failures, and compromised client servers. LUCY's infrastructure is monitored 24/7 from multiple global locations, ensuring rapid response to issues. The VPS services have a 99.9% annual availability guarantee, allowing for up to 9 hours of potential downtime per year.

**Advantages of LUCY's VPS/Dedicated Servers**

Opting for LUCY's VPS or dedicated server hosting provides several benefits:

* **Bandwidth**: A guaranteed bandwidth of 1 Gbyte.
* **Public IP Address**: Reduces the risk of your infrastructure being blacklisted.
* **Dedicated Full Root Access**: With an optimized operating system for peak performance.
* **DNS Management**: Creation of necessary DNS entries to mitigate SPAM issues.
* **Direct Access**: Ensures servers are not blocked by pre-existing security solutions.
* **Application Checks**: Comprehensive testing to ensure seamless LUCY operation.

</details>

* **Reduced Attack Surface**: Placing LUCY on the internet eliminates the need to modify internal firewall settings, aligning with secure zone principles and minimizing attack vectors.
* **Simplified Integration**: Cloud-based LUCY servers are quicker to set up, facing fewer integration challenges with existing email, DNS, and firewall configurations.
* **Direct Access**: Hosting servers in the cloud bypasses internal security obstacles, ensuring uninterrupted access.
* **Public IP Address**: A cloud server provides a public IP address outside your network range, reducing the risk of having your infrastructure blacklisted.

### **On-Premise Installation Advantages:**

* **Enhanced Security**: Hosting LUCY internally utilizes the existing security infrastructure (IDS, firewalls, etc.) to protect sensitive data (login credentials, usernames, emails) from unauthorized access.
* **Integration with Backend Systems**: LUCY seamlessly integrates with various APIs (LDAP, REST, etc.) that are secured within the internal network and not exposed to the internet.
* **Compliance with Legal Requirements**: Regulations like GDPR in Europe may restrict storing sensitive data on external servers, making on-premise installations necessary.

### **Placement in an On-Premise Installation:**

For on-premise setups, LUCY can be deployed within the intranet or a secured zone (DMZ). However, granting secure access for external users (e.g., mobile devices accessing phishing simulations or e-learning modules) directly from the intranet poses security risks. A web server exposed to the internet could serve as an entry point for attackers if vulnerabilities are exploited.

### **Recommended Configuration for On-Premise Deployment**:

* **Reverse Proxy Setup**: Use a LUCY instance as a reverse proxy in the DMZ, with the main application hosted securely within the intranet as the "master instance". This setup provides an extra layer of security by managing external access while keeping the core application protected inside the internal network.
* **DMZ Installation**: For better security, install LUCY in a separate, secure zone within the DMZ. This configuration reduces direct exposure to the intranet.

{% hint style="info" %}
See our platform reference article on [Master/Slave deployment](/application-reference/settings/common-system-settings/web-proxy)
{% endhint %}


# Architecture

### Overview

This document outlines the key structural elements and settings of Lucy.

<figure><img src="/files/Vlyayk7G6FUlmxzHxh77" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
"LUST" is the central licensing and content server managed by Lucy Security.
{% endhint %}

### Operating System

* **Ubuntu 20.04.4 LTS**: Lucy operates on a 64-bit Ubuntu 20.04.4 LTS system, without any additional patches or hardening. Updates are managed through a self-hosted repository mirror.

### Web Server

* **Apache 2.4.41**: Utilizes "mod-security" and "mod-headers" for enhanced security.

### Database

* **PostgreSQL 14.8**: Stores all related data with AES-256-CBC encryption at the column level.

### Intermediary Storage

* **Redis 5.0.7**: Used as a task queue for passing data between users and system workers.

### Application

* **PHP v8.2.6 and Python 3.8.10**: Lucy is primarily a PHP application using the Yii Framework, with some background scripts in Python.

### Security

* **OWASP Top 10 / 2017**: Adheres to OWASP security standards.
* **Firewall and SSL**: Custom [firewall rules](/application-reference/settings/common-system-settings/firewall) and [SSL configurations](/application-reference/settings/common-system-settings/ssl-settings).
* **User Accounts**: "phishing" and "support" accounts for specific functions and support purposes.

### Folders

* **/opt/phishing**: Main directory containing system code, user files, and settings.

### Logs

* **Apache Logs**: Located in `/var/logs/apache2`.
* **Application Logs**: Located in `/opt/phishing/runtime`.

### Critical Services

* **Services**: Apache2, PostgreSQL, Redis-server, and Supervisor are critical services.

### Installation and Updates

Docker-based installation with seamless updates via APT within the container.

* Containers share the host OS kernel, enabling rapid startup and efficient RAM usage.
* Uses layered filesystems for efficient disk usage and image downloads.
* Ensures application isolation, running as a separate process in userspace.
* Not bound to specific infrastructure, allowing operation on any computer, infrastructure, or cloud.

### Network Communication

* **Outbound Communication**: Required by LUCY for license server updates, vulnerability checks, and various optional services.
  * **License Server (LUST)**: Updates and templates over HTTPS.
  * **Vulnerability Checks**: Port 80 connection to static.nvd.nist.gov for NIST CVE database.
  * **Update Servers**: Access to update.phishing-server.com and update1.phishing-server.com on ports 80 and 443.
  * **Optional Services**: DNS, URL shortening
* **Inbound Communication**: Requires ports 80 and 443 for web access and port 25 for email replies.
* **Malware Simulation Communication**: Uses HTTP/HTTPS for data collection during simulations.


# Hardware Requirements

### Supported Operating System for Docker Installation

LUCY runs on Docker. Docker Engine is supported on Linux, Cloud, Windows, and OS X.

<details>

<summary>What is Docker?</summary>

[**Docker**](https://docs.docker.com/get-started/overview/) is a platform that allows developers to automate the deployment of applications inside lightweight, portable, self-sufficient containers. These containers can run on any system that has Docker installed, ensuring that the software works consistently across different environments.

**Key Features of Docker:**

* **Portability:** Docker containers can be run on any machine with Docker installed, making it easy to move Lucy between environments.
* **Isolation:** Each Docker container runs in isolation, which means it doesn't interfere with other containers or the host system.
* **Efficiency:** Containers share the host system's kernel, making them more lightweight and faster to start compared to traditional virtual machines.

#### How Lucy Uses Docker

Using Docker, Lucy can be deployed consistently and efficiently across different systems. Here's how Docker is used in the context of Lucy:

1. **Containerization:** Lucy is packaged as a Docker container, which includes all the necessary software and dependencies. This ensures that Lucy runs the same way on any system with Docker installed.
2. **Port Management:** The installer script ensures that the necessary network ports (25, 80, and 443) are available and not used by other services. These ports, such as handling web traffic and email communications, are essential for Lucy's operations.
3. **Automated Installation:** The installer script automates setting up Docker (if it's not already installed) and configuring it to run Lucy. This reduces the complexity of installation and ensures that all necessary steps are followed correctly.
4. **Isolation and Security:** Running Lucy in a Docker container isolates it from other applications on the host system. This improves security and reduces the risk of conflicts with other software.

</details>

### Supported Linux Distributions

* **Ubuntu**: 20.04 LTS,  22.04 LTS
* **Debian**: 9.x, 10.x (Legacy)
* **Red Hat/CentOS**: 9.x

<details>

<summary>Other Operating Systems</summary>

Virtualization platforms such as VMware or VirtualBox are compatible with most common operating systems. Users are encouraged to refer to their specific vendor's documentation for detailed compatibility information.

**Compatibility with Operating Systems and Platforms:**

Docker containers support a wide range of environments, including but not limited to:

* Amazon EC2
* Arch Linux
* CentOS
* CRUX Linux
* Fedora
* FrugalWare
* Gentoo
* IBM SoftLayer
* Install on Joyent Public Cloud
* Mac OS X
* Microsoft Azure platform
* Oracle Linux
* Rackspace Cloud
* Red Hat Enterprise Linux
* openSUSE and SUSE Linux Enterprise
* Ubuntu
* Windows

### Supported Browsers:

LUCY's phishing and awareness templates are designed to function seamlessly across a wide range of browsers to ensure broad accessibility for users. Here’s a list of supported browsers:

* **Browsers:**
  * Chrome (desktop and mobile)
  * Firefox (desktop and mobile)
  * Microsoft Edge (desktop and mobile)
  * Opera (desktop and mobile)
  * Safari (desktop and mobile)

</details>

***

### Hardware Requirements

#### Small Campaigns (up to 2000 recipients)

* **RAM**: 8 GB
* **CPU**: 4 Core
* **Hard Disk**: 100 GB

#### Medium Campaigns (up to 50,000 recipients)

* **RAM**: 16 GB
* **CPU**: 8 Core
* **Hard Disk**: 300 GB

#### Large Campaigns (up to 100,000 recipients)

* **RAM**: 32 GB
* **CPU**: 16 Core
* **Hard Disk**: 500 GB

<details>

<summary>Hardware <strong>Recommendations</strong></summary>

* **Initial Setup:** Ensure that your initial hardware setup meets the minimum requirements for your expected campaign size. It's better to allocate more resources upfront to avoid performance bottlenecks.
* **Storage Planning:** Given the potential need for additional templates and the data generated by campaigns, planning for ample storage from the beginning is wise. Consider future expansion when selecting your hard disk size.
* **Use Built-in Tools:** Regularly utilize LUCY's [performance testing ](/application-reference/support/system-tests/performance-test)and [monitoring tools](/application-reference/support/status/system-monitoring) to keep your system running efficiently. These tools can provide valuable insights into how well your hardware is coping with the demands of your campaigns.
* **Flexible Scaling:** If you are hosting your LUCY instance on a VPS, take advantage of the ability to scale your resources as needed. This can be particularly useful for handling peak loads during large campaigns.

**VPS Hosting**

For users opting for a Virtual Private Server (VPS) hosted by LUCY:

* **Dynamic Resource Scaling.** LUCY provides the capability to automatically scale computing resources, including CPU and RAM, to meet the demands of your campaign. This feature ensures optimal performance of campaigns by adjusting resources in real time, eliminating the need for manual adjustments. In case of hardware limitations, users are encouraged to contact the[ support department](/contact-us) for assistance in scaling their Virtual Private Server (VPS).

</details>


# Network Communication

LUCY may initiate or require certain communication channels to servers on the internet.\
Below is an overview of these requirements.

***

## Workstation IP Address

Your workstation must use a **static IP address**. If the IP address changes, the workstation may lose its license.

If this occurs, [contact Support](/contact-us) for assistance reconnecting the license.

If you cannot use a static IP address, notify your account manager or contact Support for guidance.

***

## Outbound Communication

#### General Communication Types

1. **First-Time Use**: During the first installation, LUCY connects via HTTP to obtain the workstation key and ID. No data beyond the current build version is transmitted.
2. **Updates**: LUCY connects to our update server and Ubuntu repository mirror.
3. **SSH**: When SSH is enabled via the Help menu, LUCY initiates an outbound SSH connection to our SSH Jump Host. This feature is disabled by default.
4. **Campaign Checks**: LUCY connects to fixed servers to test campaign settings and internet reachability via HTTP/HTTPS. No data is transmitted during these tests.
5. **Campaign Execution**: LUCY may communicate via SMTP (Port 25 or 465) when sending emails over the internet.
6. **Vulnerability Detection**: To enable this feature, allow Port 80 access to `static.nvd.nist.gov` (129.6.13.177) for downloading the NIST CVE database.

#### Outbound Ports & IPs

| IP Address/Domain                           | Function                             | Port   | Protocol |
| ------------------------------------------- | ------------------------------------ | ------ | -------- |
| 162.55.130.83 (update.phishing-server.com)  | Update/License Server, HTTP Proxy    | 80/443 | TCP      |
| 162.55.130.83 (update.phishing-server.com)  | Linux Repository                     | 80     | TCP      |
| 8.8.8.8 (or any DNS server)                 | DNS Server                           | 53     | UDP      |
| nvd.nist.gov                                | NIST CVE Database (Optional)         | 443    | TCP      |
| 0.0.0.0 (Any)                               | Mail Communication (Optional)        | 25     | TCP      |
| 116.203.185.12 (changelog.lucysecurity.com) | Fetch Update News (Optional)         | 80     | TCP      |
| is.gd                                       | URL Shortening Service (Optional)    | 443    | TCP      |
| api-ssl.bitly.com                           | URL Shortening Service (Optional)    | 443    | TCP      |
| api.authy.com                               | Two-Factor Authentication (Optional) | 443    | TCP      |

{% hint style="warning" %}
LUCY version ≥ 5.0 requires dynamic IP access to `update1.phishing-server.com`.\
Create an allow rule for the domain name.
{% endhint %}

***

## Inbound Communication

To access LUCY from the internet, specific ports must be open:

| Source IP | Destination         | Port                | Protocol | Comment                                                            |
| --------- | ------------------- | ------------------- | -------- | ------------------------------------------------------------------ |
| ANY       | Your LUCY Server IP | 80/443 (HTTP/HTTPS) | TCP      | Required for accessing landing pages and certificate verification. |
| ANY       | Your LUCY Server IP | 25 (SMTP)           | TCP      | Only needed for catching email replies.                            |

***

## Malware Simulation Communication

The malware simulation tool uses the recipient's default browser (in hidden mode) to send collected data to LUCY via HTTP or HTTPS. For SSL-enabled campaigns, HTTPS is used automatically. The tool is compatible with environments requiring proxy authentication for internet access.


# Installing Lucy

Lucy can be deployed using one of the following methods:

* **Docker installation on a supported OS**
* **Prebuilt virtual machines (VMware / VirtualBox)**

For a full list of supported operating systems, see the [**Supported Operating Systems**](/guides/installing-lucy/hardware-requirements).

## Lucy 6

### Docker Installation (Recommended)

{% hint style="info" %}
Supported Systems: Ubuntu 22.04 or higher
{% endhint %}

#### Bash Installer

```
wget https://download.phishing-server.com/dl/lucy-latest/Install_lucy_6.0.sh
sudo bash Install_lucy_6.0.sh
```

## Lucy 5

### Docker Installation (Recommended)

{% hint style="info" %}
Supported Systems: Ubuntu 22.04 or higher
{% endhint %}

#### **C++ Installer**

```
wget https://download.phishing-server.com/dl/lucy-latest/Install_lucy_5.7.2
sudo ./Install_lucy_5.7.2
```

#### **Bash Installer**

```
wget https://download.phishing-server.com/dl/lucy-latest/Install_lucy_5.7.2.sh
sudo bash Install_lucy_5.7.2
```

#### Verify the Installation

Once installation is complete, confirm the Lucy container is running:

```
docker ps
```

You should see the **Lucy container** listed in the output.

***

#### Legacy Docker Installers

{% hint style="info" %}
⚠ **Warning**

The legacy installation scripts deploy a **Docker container running Ubuntu 20.04**, which is **no longer supported**.

Use these installers **only if you have a specific compatibility requirement**.
{% endhint %}

**Ubuntu 20.04 Host**

```
wget https://download.phishing-server.com/dl/lucy-latest/install-20.04.sh
```

**Ubuntu 22.04 Host**

```
wget https://download.phishing-server.com/dl/lucy-latest/install-22.04.sh
```

***

### Virtual Machine Installations

Lucy is also available as a **preconfigured virtual machine**.

{% hint style="info" %}
For all VM deployments, configure the network adapter as:

Network Mode: `Bridged`
{% endhint %}

#### VMware

**ESXi**

```
https://download.phishing-server.com/dl/phishing-5.7/esxi.ova
```

**OVF**

```
https://download.phishing-server.com/dl/phishing-5.7/esxi_ovf.zip
```

#### Legacy VMware Images

**ESXi**

```
https://download.phishing-server.com/dl/phishing-5.6/esxi.ova
```

**OVF**

```
https://download.phishing-server.com/dl/phishing-5.6/esxi_ovf.zip
```

***

#### VirtualBox

```
https://download.phishing-server.com/dl/lucy-latest/virtualbox.zip
```


# Upgrading to Lucy 6.0

## VPS Customers

If we are hosting your Lucy server for you, please [contact support](/contact-us) to request an upgrade to 6.0.

Upgrades are on a first-come, first-served basis and need to be scheduled in advance.

***

## On-Premise Customers

This guide walks you through the migration from **Lucy 5.7.6 to Lucy 6.0**.

The migration is performed using an upgrade script. Follow the steps below **in order** and do not remove the old Lucy container until you have verified that the migration was successful.

{% hint style="success" %}
Lucy 6.0 uses Ubuntu 24.04 inside the Docker container.\
The host machine itself can run any operating system supported by Docker.
{% endhint %}

#### Before you start

Make sure you have:

* A Docker-based deployment
* Lucy version 5.7.6
* At least 60% free storage space on the host
* A recent **snapshot or backup of the host machine**

{% hint style="danger" %}
If Lucy was deployed using a virtual machine image, this migration script cannot be used.\
[Contact Support](/contact-us) for assistance with the upgrade.
{% endhint %}

#### 1. Stop all campaigns

Stop all active and scheduled campaigns before starting the migration.

{% hint style="warning" %}
The Lucy dashboard will be unavailable for the entire migration process. We recommend performing the upgrade during a maintenance window or during off-peak hours.
{% endhint %}

#### 2. Free up storage space

The migration requires at least **60% free storage space on the host** to allow the existing Lucy container to be backed up and migrated.

Before starting, consider removing:

* Unedited templates that are no longer needed
* Unneeded campaigns
* Old exports
* Cached data

#### 3. Create a host snapshot

The migration script creates a backup of the existing Lucy container. As an additional safety measure, we strongly recommend creating a snapshot of the **entire host machine** before starting the migration.

{% hint style="info" %}
If the host is running on a virtualization platform, create the snapshot using the platform's normal snapshot functionality.
{% endhint %}

#### 4. Download the migration script

Run the following command **on the host machine, not inside the Lucy container**:

```bash
wget https://download.phishing-server.com/dl/upgrade_container6.sh
```

#### 5. Run the migration script

Run the following command **on the host machine, not inside the Lucy container**:

```bash
sudo bash upgrade_container6.sh
```

{% hint style="info" %}
The migration can take several hours depending on the amount of data stored in Lucy.
{% endhint %}

When prompted, select:

* **Autodetect Lucy container** → `YES`
* **System snapshot** → `YES`

Allow the script to complete before proceeding.

#### 6. Update Lucy in the UI

Once the migration script has finished, access the Lucy UI and complete the [update to Lucy 6.0](/application-reference/support/update).

#### 7. Verify the Migration

After upgrading to Lucy 6.0, review the workstation and verify that your data has been migrated successfully.

Check that the expected campaigns, templates, users, settings, and other required data are available and functioning correctly.

#### 8. Remove the old container

Once you have confirmed that the migration was successful and everything is working correctly, remove the old container:

```
sudo docker rm lucy_old_backup
```

{% hint style="danger" %}
**Important:** Only remove `lucy_old_backup` after verifying the migration. Once the old container has been removed, it can no longer be used as a fallback.
{% endhint %}


# Post Installation Setup

## Using the setup script

Access your Lucy container and execute the setup script:

**Lucy version 5.2.1 and below**

```
docker exec -it lucy python /opt/phishing/current/tools/setup/setup.py
```

**Lucy version 5.3 and above**

```
docker exec -it lucy python3 /opt/phishing/current/tools/setup/setup.py
```

{% hint style="success" %}
The default name for the container is `lucy`.\
If you named it something else, use that name in the command above.
{% endhint %}

You can also run the setup script at any time from within the container using:

```
sudo python /opt/phishing/current/tools/setup/setup.py
OR
sudo python3 /opt/phishing/current/tools/setup/setup.py
```

The script starts with this menu:

<figure><img src="/files/LFqoCwbbco8u3b2oyTVN" alt=""><figcaption></figcaption></figure>

## Create an administrative user

Select **Users** (6), then select **Add User** (2).

<figure><img src="/files/wKlk3y3dPrweGXSq7cX0" alt=""><figcaption></figcaption></figure>

## Configure the administrative domain

Select **Base Task** (5) and enter a domain you own.

<figure><img src="/files/idSH8ieZRpZxdBV7lCSw" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Ensure all relevant [DNS records](/application-reference/settings/common-system-settings/domains#dns-records-explained) are pointing to your Lucy server.
{% endhint %}

<figure><img src="/files/AoNQVVAEGrMhc6b3xJrx" alt=""><figcaption></figcaption></figure>

***

## Get a license

Licensing restrictions currently limit some configuration options on your Lucy server. To start the licensing process, please contact your Account Manager and provide your Lucy [workstation ID](/application-reference/account-settings/license#workstation-id).

Once a license has been assigned to your workstation, you can sync the details by going to **Support > Update** and clicking **Check Update**.

***

## Initial Lucy Configuration

* [x] [Configure mail delivery.](/application-reference/settings/common-system-settings/mail-settings)
* [x] [Set up a domain for phishing simulations or the e-learning portal.](/application-reference/settings/common-system-settings/domains)
* [x] [Create a trusted SSL certificate.](/application-reference/settings/common-system-settings/ssl-settings)
* [x] [Create administrator users.](/application-reference/users/administrative-users)
* [x] [Download the latest templates.](/application-reference/templates/download-templates)
* [x] [Implement additional security layers.](/application-reference/settings/common-system-settings/firewall)
* [x] [Customize portal branding and 404 pages.](/application-reference/settings/whitelabeling)
* [x] [Set up your first campaign.](/guides/quick-guides/create-your-first-campaign)


# Manage Blacklisted Domains

Domains used in phishing simulations are evaluated using the same security mechanisms and algorithms as any other domain to determine their legitimacy. Consequently, there isn't a singular reason a domain might be blacklisted. However, adhering to best practices can significantly reduce the risk of a domain being blacklisted.

<details>

<summary>Why was my domain blacklisted?</summary>

In the context of phishing simulations using Lucy, domains can be blacklisted based on several factors. Each security vendor uses different detection mechanisms to identify malicious domains. Here are some key factors:

1. **Spoofed Brands:**
   * Domains mimicking well-known brands (e.g., Google, Facebook, Microsoft) can be flagged. For example, Google’s algorithms detect visual and structural similarities to known brands to prevent phishing.
2. **Phishing Indicators:**
   * If the domain hosts landing pages that solicit login credentials, personal information, or payment details, it can be flagged as a phishing site.
3. **New or Untrusted Domains:**
   * Newly registered domains often lack a reputation. If these domains are used for phishing simulations, they are more likely to be blacklisted.
4. **Domain Configuration:**
   * The setup of SPF, MX, and A records pointing to the Lucy server is scrutinized. Misconfigurations or anomalies in these records can trigger blacklisting. Checks are done for alignment with typical usage patterns and legitimate email configurations.
5. **SSL Certificates:**
   * Even with valid SSL certificates, if the domain shows signs of misuse or if the certificates are not from well-known Certificate Authorities, the domain can be flagged.
6. **Malware Distribution:**
   * If the domain inadvertently hosts or distributes malware (e.g., through attachments or linked downloads), it will be blacklisted. Landing pages can be scanned for malicious software and scripts.
7. **Deceptive Content:**
   * Inspecting content that is intentionally deceptive or misleading, designed to trick users into performing unsafe actions. This includes fake warnings, alerts, and instructions.
8. **Suspicious Behavior Patterns:**
   * High volumes of emails sent from the domain, especially those resembling phishing emails, can raise red flags. Monitoring is done for sending patterns and email content for suspicious activities.
9. **User Reports:**
   * If users report the domain as suspicious or harmful, Google/Microsoft will take these reports into consideration. High numbers of user complaints can lead to a domain being blacklisted.
10. **Embedded Links and Redirects:**
    * Checks are implemented for suspicious links and redirects within the domain. If the site redirects to known malicious or phishing sites, it can be flagged.

</details>

<details>

<summary>What can I do to prevent Blacklisting?</summary>

To minimize the risk of your newly spoofed domains being blacklisted when conducting phishing simulations with content related to known brands like Google, Facebook, and Microsoft, follow these best practices:

### **Choose Reputable Domain Providers:**

* Register your domains with well-known and reputable domain providers. This helps establish initial trust. You can use the built-in [Domain wizard](/application-reference/settings/common-system-settings/domains#register) for registration with GoDaddy.

### **Set Up Proper DNS Records:**

* Ensure your SPF, DKIM, and DMARC records are correctly configured to authenticate your emails.
* [Example SPF record:](/application-reference/settings/common-system-settings/domains#dns-records-explained)

  ```plaintext
  v=spf1 ip4:{your_lucy_ip_address} ~all
  ```
* [Example DKIM record:](/application-reference/campaigns/campaign-settings/main-settings/attack-simulation#dkim-support)

  ```plaintext
  default._domainkey IN TXT "v=DKIM1; k=rsa; p=<public_key>"
  ```
* Example DMARC record:

  ```plaintext
  _dmarc IN TXT "v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com"
  ```

See our platform reference article on [DNS records](/application-reference/settings/common-system-settings/domains#add-a-domain)

### **Implement HTTPS:**

* Use SSL/TLS certificates from reputable Certificate Authorities (CAs) to secure your domains. Use the built-in [Let's Encrypt certificate generator](/application-reference/settings/common-system-settings/ssl-settings) for your domains.

### **Regularly Update Your DNS Records:**

* Keep your DNS records up-to-date and ensure there are no misconfigurations.

### **Content and Email Practices:**

**Avoid Exact Brand Imitation:**

* Avoid replicating the exact appearance of well-known brands like Google, Facebook, or Microsoft. Introduce subtle changes to the email and landing pages to prevent detection by algorithms.

**Use Clear Disclaimers:**

* Include disclaimers in your emails and landing pages stating that they are part of a security awareness program.

**Limit Email Volume:**

* Send your phishing simulation emails in small batches to avoid triggering spam filters. Use the built-in [Scheduler](/application-reference/campaigns/campaign-settings/optional-settings/schedule) to achieve this.

**Monitor Email Content:**

* Ensure your emails do not contain elements commonly associated with spam or phishing, such as excessive links or suspicious attachments.

**Test Content with Spam Checkers:**

* Use tools like Mail-Tester or Litmus to test your emails for spammy elements before sending them out.

### **Domain Management and Monitoring:**

**Warm-Up Your Domain:**

* Gradually increase your email sending volume to establish a good sending reputation. Use the built-in [Scheduler](/application-reference/campaigns/campaign-settings/optional-settings/schedule) to achieve this.

**Monitor Domain Health:**

* Use tools like [Google Search Console ](https://search.google.com/search-console/about)to monitor your domain’s health and address any issues promptly.

**Engage in Regular Clean-Up:**

* Periodically review and clean your email lists to ensure you are sending to valid addresses. Use [Lucy's built-in automation](/application-reference/settings/common-system-settings/ldap-settings#action-for-new-users) to automatically keep your users up to date with your organization's directory.&#x20;

### **Google Safe Browsing and User Reports:**

**Regularly Check for Blacklisting:**

* Periodically check your domains using tools like Google Safe Browsing to ensure they are not blacklisted.

**Promptly Address User Reports:**

* Respond quickly to any user reports of suspicious activity related to your domains.

**Verify and Whitelist Your Domain:**

* Verify your domain ownership with Google Search Console and request reviews if blacklisting occurs.

### **Legal and Ethical Considerations:**

**Stay Within Legal Boundaries:**

* Ensure your simulations comply with local laws and regulations regarding email communications and data privacy.

**Communicate with Stakeholders:**

* Inform relevant stakeholders within your organization about the phishing simulations to avoid misunderstandings and false reports to Google.

</details>

***

### Identify Vendors That Have Blacklisted Your Domain

You can use common tools like:

**MXToolbox** -> <https://mxtoolbox.com/blacklists.aspx>

**Google SafeBrowsing** -> <https://www.google.com/webmasters/tools/security-issues>

**Virus Total** -> <https://www.virustotal.com/gui/home/url>

* Enter your blacklisted domain
* Make a note of all blacklisted vendors

{% hint style="info" %}
If your domain is displaying "Deceptive Site Ahead" in Chrome, see our guide on [Google SafeBrowsing](/guides/manage-blacklisted-domains/managing-google-safebrowsing-alerts)
{% endhint %}

***

### Delisting a Blacklisted Domain

Most vendors allow you to submit a false positive claim to remove a blacklisted domain. Each vendor has specific procedures for this. Below is a list of vendors and their respective whitelisting processes:

{% hint style="success" %}
Our [Technical Support](/contact-us) team is available to assist you with de-listing your domain.
{% endhint %}

| Vendor                                    | Contact Email                                                                    | False Positive Reporting                                                                                                                                                                                        |
| ----------------------------------------- | -------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| 360                                       | <kefu@360.cn>                                                                    | N/A                                                                                                                                                                                                             |
| Abusix                                    | <support@abusix.com>                                                             | [Abusix Lookup](https://lookup.abusix.com/)                                                                                                                                                                     |
| Acronis                                   | <virustotal-falsepositive@acronis.com>                                           | N/A                                                                                                                                                                                                             |
| ADMINUSLabs                               | <info@adminuslabs.net>, <samples@adminus.net>, <falsepositive@adminuslabs.net>   | N/A                                                                                                                                                                                                             |
| AegisLab                                  | <support@aegislab.com>                                                           | N/A                                                                                                                                                                                                             |
| Ahnlab                                    | <e-support@ahnlab.com>, <samples@ahnlab.com>                                     | N/A                                                                                                                                                                                                             |
| AILabs (Monitorapp)                       | <aicc@monitorapp.com>                                                            | N/A                                                                                                                                                                                                             |
| Alibaba                                   | <virustotal@list.alibaba-inc.com>                                                | N/A                                                                                                                                                                                                             |
| AliCloud                                  | <antivirus@alibabacloud.comm>                                                    | N/A                                                                                                                                                                                                             |
| AlienVault                                | <otx-support@alienvault.com>                                                     | N/A                                                                                                                                                                                                             |
| AlphaMountain                             | <support@alphamountain.freshdesk.com>                                            | N/A                                                                                                                                                                                                             |
| AlphaSOC                                  | <virustotal@alphasoc.com>                                                        | N/A                                                                                                                                                                                                             |
| Alyac (Estsoft)                           | <esrc@estsecurity.com>                                                           | N/A                                                                                                                                                                                                             |
| Antivir (Avira)                           | N/A                                                                              | [Avira Submit URL](https://www.avira.com/en/analysis/submit-url)                                                                                                                                                |
| Antiy                                     | <avlsdk_support@antiy.cn>                                                        | N/A                                                                                                                                                                                                             |
| Arcabit                                   | <vt.fp@arcabit.pl>                                                               | N/A                                                                                                                                                                                                             |
| ArcSight Threat Intelligence              | <arcsight-virustotal@microfocus.com>                                             | N/A                                                                                                                                                                                                             |
| AutoShun                                  | <info@autoshun.org>                                                              | N/A                                                                                                                                                                                                             |
| Avast                                     | <DL-Virus@gendigital.com>                                                        | N/A                                                                                                                                                                                                             |
| AVG                                       | N/A                                                                              | [AVG Submit Sample](http://www.avg.com/submit-sample), [AVG Whitelist](http://www.avg.com/us-en/whitelist)                                                                                                      |
| Baidu                                     | <bav@baidu.com>, <gaoyingchun@baidu.com>                                         | N/A                                                                                                                                                                                                             |
| BitDefender                               | <virus_submission@bitdefender.com>                                               | N/A                                                                                                                                                                                                             |
| BforeAi                                   | N/A                                                                              | [BforeAi Support](https://bfore.ai/support)                                                                                                                                                                     |
| Bkav                                      | <fpreport@bkav.com>, <bkav@bkav.com>                                             | N/A                                                                                                                                                                                                             |
| Certego                                   | N/A                                                                              | [Certego Contact](https://www.certego.net/company/contact-us/)                                                                                                                                                  |
| Chong Lua Dao                             | <info@chongluadao.vn>                                                            | N/A                                                                                                                                                                                                             |
| CINS Army (Sentinel IPS)                  | <cins@sentinelips.com>                                                           | [CINS Army Contact](http://cinsscore.com/#contact)                                                                                                                                                              |
| ClamAV                                    | N/A                                                                              | [ClamAV Reports](http://www.clamav.net/reports/fp)                                                                                                                                                              |
| Clean-MX                                  | <abuse@clean-mx.de>                                                              | N/A                                                                                                                                                                                                             |
| Cluster25                                 | <threatintel@cluster25.io>                                                       | N/A                                                                                                                                                                                                             |
| CMC                                       | <PSIRT@cmccybersecurity.com>                                                     | N/A                                                                                                                                                                                                             |
| CRDF                                      | N/A                                                                              | [CRDF False Positive](https://threatcenter.crdf.fr/false_positive.html)                                                                                                                                         |
| Criminal IP (AI Spera)                    | <support@aispera.com>                                                            | N/A                                                                                                                                                                                                             |
| CrowdStrike                               | <VTscanner@crowdstrike.com>                                                      | N/A                                                                                                                                                                                                             |
| CSIS Security Group                       | <abuse-reporting@csis.com>                                                       | N/A                                                                                                                                                                                                             |
| CyanSecurity                              | <virustotal@cyansecurity.com>                                                    | N/A                                                                                                                                                                                                             |
| Cybereason                                | <vt-feedback@cybereason.com>                                                     | N/A                                                                                                                                                                                                             |
| Cyble                                     | <cyblevt_patnership@cyble.com>                                                   | N/A                                                                                                                                                                                                             |
| Cylance                                   | <cylancefilesubmit@cylance.com>                                                  | N/A                                                                                                                                                                                                             |
| Cynet                                     | <soc@cynet.com>                                                                  | N/A                                                                                                                                                                                                             |
| CyRadar                                   | <virustotal@cyradar.com>                                                         | N/A                                                                                                                                                                                                             |
| Deep Instinct                             | <vt-fps-requests@deepinstinct.com>                                               | N/A                                                                                                                                                                                                             |
| DNS8                                      | <dns8@layer8.pt>                                                                 | N/A                                                                                                                                                                                                             |
| DrWeb                                     | <vms@drweb.com>                                                                  | N/A                                                                                                                                                                                                             |
| eGambit (Tehtris)                         | <virus@tehtris.com>                                                              | [Tehtris eGambit FP](https://tehtris.com/en/forms/false-positives-false-negatives/)                                                                                                                             |
| Elastic                                   | <fp_reports@elastic.co>                                                          | [Elastic Discuss](https://discuss.elastic.co/t/submitting-false-positives/232322)                                                                                                                               |
| Emsisoft                                  | <submit@emsisoft.com>, <fp@emsisoft.com>                                         | [Emsisoft Contact](https://www.emsisoft.com/en/help/1720/why-did-an-emsisoft-product-detect-an-innocent-file-as-malware-2/)                                                                                     |
| ESET                                      | N/A                                                                              | [ESET Support](https://support.eset.com/kb141/?page=content\&id=SOLN141)                                                                                                                                        |
| FireEye                                   | <virustotal@fireeye.com>                                                         | N/A                                                                                                                                                                                                             |
| F-Prot                                    | <viruslab@f-prot.com>                                                            | N/A                                                                                                                                                                                                             |
| F-Secure/WithSecure                       | <spyware-samples@f-secure.com>, <vsamples@f-secure.com>                          | N/A                                                                                                                                                                                                             |
| Forcepoint ThreatSeeker                   | <reviewmysite@forcepoint.com>                                                    | N/A                                                                                                                                                                                                             |
| Fortinet                                  | [Fortinet Contact Support](http://www.fortinet.com/support/contact_support.html) | [Fortinet Classification Dispute](https://www.fortiguard.com/faq/classificationdispute)                                                                                                                         |
| GData                                     | N/A                                                                              | [GData Submit Suspicious File](https://www.gdatasoftware.com/faq/consumer/submit-a-suspicious-file-app-or-url)                                                                                                  |
| Google (File Scanner)                     | <google-at-virustotal@google.com>                                                | N/A                                                                                                                                                                                                             |
| Google Safe Browsing (URL/Netloc Scanner) | N/A                                                                              | [Google Safe Browsing Report](https://safebrowsing.google.com/safebrowsing/report_error/?hl=en)                                                                                                                 |
| GreenSnow                                 | N/A                                                                              | [GreenSnow Contact](https://greensnow.co/contact)                                                                                                                                                               |
| Gridinsoft                                | <virus@gridinsoft.com>                                                           | N/A                                                                                                                                                                                                             |
| Hacksoft                                  | <virus@hacksoft.com.pe>                                                          | N/A                                                                                                                                                                                                             |
| Hauri                                     | <viruslab@hauri.co.kr>                                                           | N/A                                                                                                                                                                                                             |
| Heimdal                                   | <report-vt@heimdalsecurity.com>                                                  | N/A                                                                                                                                                                                                             |
| Hunt.io Intelligence                      | <k.lo@hunt.io>                                                                   | N/A                                                                                                                                                                                                             |
| Hoplite Industries                        | <vt-info@hopliteindustries.com>                                                  | N/A                                                                                                                                                                                                             |
| Ikarus                                    | <fp@ikarus.at>                                                                   | N/A                                                                                                                                                                                                             |
| IPsum                                     | N/A                                                                              | [IPsum GitHub](https://github.com/stamparm/ipsum)                                                                                                                                                               |
| Jiangmin                                  | <support@jiangmin.com>, <shaojia@jiangmin.com>                                   | N/A                                                                                                                                                                                                             |
| K7                                        | <reportfp@labs.k7computing.com>, <k7viruslab@labs.k7computing.com>               | N/A                                                                                                                                                                                                             |
| Kaspersky                                 | <newvirus@kaspersky.com>                                                         | N/A                                                                                                                                                                                                             |
| Kingsoft                                  | <ti@mingting.cn>                                                                 | N/A                                                                                                                                                                                                             |
| Lionic                                    | <support@lionic.com>                                                             | [Lionic Report FP](https://www.lionic.com/reportfp/)                                                                                                                                                            |
| Lumu                                      | <vt@lumu.io>                                                                     | N/A                                                                                                                                                                                                             |
| Malbeacon                                 | <vtreport@malbeacon.com>                                                         | N/A                                                                                                                                                                                                             |
| Malwarebytes                              | N/A                                                                              | [Malwarebytes False Positives](https://forums.malwarebytes.com/forum/122-false-positives/)                                                                                                                      |
| Malwares.com (Saint Security)             | <kog@stsc.com>                                                                   | N/A                                                                                                                                                                                                             |
| MalwareURL                                | <team@malwareurl.com>                                                            | N/A                                                                                                                                                                                                             |
| MAX (SaintSecurity)                       | <root@malwares.com>                                                              | N/A                                                                                                                                                                                                             |
| MaxSecure                                 | <tech@maxpcsecure.com>                                                           | N/A                                                                                                                                                                                                             |
| McAfee                                    | <virus_research@mcafee.com>                                                      | N/A                                                                                                                                                                                                             |
| Skyhigh                                   | <virus_research_gateway@avertlabs.com>                                           | N/A                                                                                                                                                                                                             |
| Microsoft                                 | N/A                                                                              | [sender.office.com](https://sender.office.com/)                                                                                                                                                                 |
| Microworld                                | <samples@escanav.com>                                                            | N/A                                                                                                                                                                                                             |
| NANO                                      | <false@nanoav.ru>                                                                | N/A                                                                                                                                                                                                             |
| Netcraft                                  | N/A                                                                              | [Netcraft Report Mistake](https://report.netcraft.com/report/mistake)                                                                                                                                           |
| Inca (previous nProtect)                  | <virus_info@inca.co.kr>                                                          | N/A                                                                                                                                                                                                             |
| Palo Alto                                 | <vt-pan-false-positive@paloaltonetworks.com>                                     | N/A                                                                                                                                                                                                             |
| Panda                                     | <falsepositives@pandasecurity.com>, <virussamples@pandasecurity.com>             | N/A                                                                                                                                                                                                             |
| Phishing Database                         | N/A                                                                              | [Phishing Database GitHub](https://github.com/mitchellkrogza/Phishing.Database#please-remove-my-domain-from-this-list-)                                                                                         |
| PhishLabs                                 | <info@phishlabs.com>                                                             | N/A                                                                                                                                                                                                             |
| Qihoo360                                  | <support@360safe.com>                                                            | N/A                                                                                                                                                                                                             |
| QuickHeal                                 | <viruslab@quickheal.com>                                                         | N/A                                                                                                                                                                                                             |
| Quttera                                   | <support@quttera.com>                                                            | N/A                                                                                                                                                                                                             |
| Rising                                    | N/A                                                                              | [Rising File Check](http://mailcenter.rising.com.cn/filecheck_en/)                                                                                                                                              |
| Sansec eComscan                           | <support@sansec.io>                                                              | N/A                                                                                                                                                                                                             |
| Sangfor                                   | <virustotal@sangfor.com.cn>                                                      | N/A                                                                                                                                                                                                             |
| Scumware.org                              | N/A                                                                              | [Scumware Removals](https://www.scumware.org/removals.php)                                                                                                                                                      |
| SecureAge                                 | N/A                                                                              | [SecureAge Report FP](https://www.secureaplus.com/features/antivirus/report-false-positive/)                                                                                                                    |
| Seclookup                                 | <info@seclookup.com>                                                             | N/A                                                                                                                                                                                                             |
| Segasec                                   | <support@segasec.com>                                                            | N/A                                                                                                                                                                                                             |
| Sentinel One                              | <report@sentinelone.com>                                                         | N/A                                                                                                                                                                                                             |
| SOCRadar                                  | <vt@socradar.io>                                                                 | N/A                                                                                                                                                                                                             |
| Sophos                                    | <samples@sophos.com>                                                             | [Sophos Support](https://support.sophos.com/support/s/article/KB-000033301?language=en_US)                                                                                                                      |
| Spamhaus                                  | N/A                                                                              | [Spamhaus DBL Removal](https://check.spamhaus.org/)                                                                                                                                                             |
| Sucuri                                    | <soc@sucuri.net>                                                                 | N/A                                                                                                                                                                                                             |
| Symantec                                  | N/A                                                                              | [Symantec Submit FP](https://symsubmit.symantec.com/submit/false_positive), [Symantec Content Submission](https://knowledge.broadcom.com/external/article/173729/how-to-submit-false-positives-on-content.html) |
| Tencent                                   | <TAVfp@tencent.com>                                                              | N/A                                                                                                                                                                                                             |
| TheHacker                                 | <virus@hacksoft.com.pe>, <falsopositivo@hacksoft.com.pe>                         | N/A                                                                                                                                                                                                             |
| Trapmine                                  | <fp@trapmine.com>                                                                | N/A                                                                                                                                                                                                             |
| TrendMicro                                | <virus@trendmicro.com>, <virus_doctor@trendmicro.com>                            | [TrendMicro Detection Re-evaluation](https://www.trendmicro.com/en_us/about/legal/detection-reevaluation.html)                                                                                                  |
| Trustwave                                 | N/A                                                                              | [Trustwave Detection Review](https://support.trustwave.com/virustotal-detection-review/)                                                                                                                        |
| Trustlook                                 | <bd@trustlook.com>                                                               | N/A                                                                                                                                                                                                             |
| Underworld                                | <post@helsecert.no>                                                              | N/A                                                                                                                                                                                                             |
| URLQuery                                  | <contact@urlquery.net>                                                           | N/A                                                                                                                                                                                                             |
| Varist                                    | <support@varist.com>, <virus@avsubmit.com>                                       | N/A                                                                                                                                                                                                             |
| VBA32                                     | <feedback@anti-virus.by>                                                         | N/A                                                                                                                                                                                                             |
| Viettel Threat Intelligence               | <cyberthreat@viettel.com.vn>                                                     | N/A                                                                                                                                                                                                             |
| Vipre                                     | <productsupport@vipre.com>                                                       | N/A                                                                                                                                                                                                             |
| VirIT                                     | <virustotal@viritpro.com>                                                        | N/A                                                                                                                                                                                                             |
| VirusDie                                  | <partners@virusdie.com>                                                          | N/A                                                                                                                                                                                                             |
| Webroot                                   | N/A                                                                              | [Webroot Vendor Dispute](https://www.webroot.com/us/en/business/support/vendor-dispute-contact-us)                                                                                                              |
| WithSecure/F-Secure                       | <spyware-samples@f-secure.com>, <vsamples@f-secure.com>                          | N/A                                                                                                                                                                                                             |
| Xcitium Verdict Cloud (Comodo)            | <support@xcitium.com>                                                            | N/A                                                                                                                                                                                                             |
| Yomi                                      | <yomi-false-positives@yoroi.company>                                             | N/A                                                                                                                                                                                                             |
| Yandex                                    | <yandex-antivir@support.yandex.ru>                                               | N/A                                                                                                                                                                                                             |
| Yandex Safebrowsing                       | <sbapi@support.yandex.ru>                                                        | N/A                                                                                                                                                                                                             |
| Zillya                                    | <virus@zillya.com>                                                               | N/A                                                                                                                                                                                                             |
| ZoneAlarm                                 | <zonealarm_VT_reports@checkpoint.com>                                            | N/A                                                                                                                                                                                                             |
| Zoner                                     | <false@zonerantivirus.com>                                                       | N/A                                                                                                                                                                                                             |


# Managing Google SafeBrowsing Alerts

If your domain is blacklisted by Google, it will display a "Deceptive site ahead" warning, adversely affecting your phishing simulation campaigns.

<figure><img src="/files/oAENNRFsv9EuyeLzkXvz" alt="" width="563"><figcaption></figcaption></figure>

<details>

<summary>Why did Google SafeBrowsing blacklist my domain?</summary>

1. **Spoofed Brands:**
   * Domains mimicking well-known brands (e.g., Google, Facebook, Microsoft) can be flagged. Google’s algorithms detect visual and structural similarities to known brands to prevent phishing.
2. **Phishing Indicators:**
   * If the domain hosts landing pages that solicit login credentials, personal information, or payment details, it can be flagged as a phishing site. Google analyzes the content for common phishing tactics and deceptive practices.
3. **New or Untrusted Domains:**
   * Newly registered domains often lack a reputation. If these domains are used for phishing simulations, they are more likely to be blacklisted. Google evaluates the age and trustworthiness of a domain.
4. **Domain Configuration:**
   * The setup of SPF, MX, and A records pointing to the Lucy server is scrutinized. Misconfigurations or anomalies in these records can trigger blacklisting. Google checks for alignment with typical usage patterns and legitimate email configurations.
5. **SSL Certificates:**
   * Even with valid SSL certificates, if the domain shows signs of misuse or if the certificates are not from well-known Certificate Authorities, the domain can be flagged. Google inspects the validity and trustworthiness of the SSL certificates.
6. **Malware Distribution:**
   * If the domain inadvertently hosts or distributes malware (e.g., through attachments or linked downloads), it will be blacklisted. Google scans for malicious software and scripts.
7. **Deceptive Content:**
   * Google looks for content that is intentionally deceptive or misleading, designed to trick users into performing unsafe actions. This includes fake warnings, alerts, and instructions.
8. **Suspicious Behavior Patterns:**
   * High volumes of emails sent from the domain, especially those resembling phishing emails, can raise red flags. Google monitors sending patterns and email content for suspicious activities.
9. **User Reports:**
   * If users report the domain as suspicious or harmful, Google will take these reports into consideration. High numbers of user complaints can lead to a domain being blacklisted.
10. **Embedded Links and Redirects:**
    * Google checks for suspicious links and redirects within the domain. If the site redirects to known malicious or phishing sites, it can be flagged.

</details>

<details>

<summary>What can I do to prevent Blacklisting?</summary>

### **Choose Reputable Domain Providers:**

* Register your domains with well-known and reputable domain providers. This helps establish initial trust. You can use the built-in [Domain wizard](/application-reference/settings/common-system-settings/domains#register) for registration with GoDaddy.

### **Set Up Proper DNS Records:**

* Ensure your SPF, DKIM, and DMARC records are correctly configured to authenticate your emails.
* [Example SPF record:](/application-reference/settings/common-system-settings/domains#dns-records-explained)

  ```plaintext
  v=spf1 ip4:{your_lucy_ip_address} ~all
  ```
* [Example DKIM record:](/application-reference/campaigns/campaign-settings/main-settings/attack-simulation#dkim-support)

  ```plaintext
  default._domainkey IN TXT "v=DKIM1; k=rsa; p=<public_key>"
  ```
* Example DMARC record:

  ```plaintext
  _dmarc IN TXT "v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com"
  ```

See our platform reference article on [DNS records](/application-reference/settings/common-system-settings/domains#add-a-domain)

### **Implement HTTPS:**

* Use SSL/TLS certificates from reputable Certificate Authorities (CAs) to secure your domains. Use the built-in [Let's Encrypt certificate generator](/application-reference/settings/common-system-settings/ssl-settings) for your domains.

### **Regularly Update Your DNS Records:**

* Keep your DNS records up-to-date and ensure there are no misconfigurations.

### **Content and Email Practices:**

**Avoid Exact Brand Imitation:**

* Do not exactly replicate the appearance of Google, Facebook, or Microsoft emails and pages. Add slight variations to avoid detection by algorithms.

**Use Clear Disclaimers:**

* Include disclaimers in your emails and landing pages stating that they are part of a security awareness program.

**Limit Email Volume:**

* Send your phishing simulation emails in small batches to avoid triggering spam filters. Use the built-in [Scheduler](/application-reference/campaigns/campaign-settings/optional-settings/schedule) to achieve this.

**Monitor Email Content:**

* Ensure your emails do not contain elements commonly associated with spam or phishing, such as excessive links or suspicious attachments.

**Test Content with Spam Checkers:**

* Use tools like Mail-Tester or Litmus to test your emails for spammy elements before sending them out.

### **Domain Management and Monitoring:**

**Warm-Up Your Domain:**

* Gradually increase your email sending volume to establish a good sending reputation. Use the built-in [Scheduler](/application-reference/campaigns/campaign-settings/optional-settings/schedule) to achieve this.

**Monitor Domain Health:**

* Use tools like [Google Search Console ](https://search.google.com/search-console/about)to monitor your domain’s health and address any issues promptly.

**Engage in Regular Clean-Up:**

* Periodically review and clean your email lists to ensure you are sending to valid addresses. Use [Lucy's built-in automation](/application-reference/settings/common-system-settings/ldap-settings#action-for-new-users) to automatically keep your users up to date with your organization's directory.&#x20;

**Utilize Subdomains:**

* Consider using subdomains specifically for simulations to isolate potential issues from your main domain.

### **Google Safe Browsing and User Reports:**

**Regularly Check for Blacklisting:**

* Periodically check your domains using tools like Google Safe Browsing to ensure they are not blacklisted.

**Promptly Address User Reports:**

* Respond quickly to any user reports of suspicious activity related to your domains.

**Verify and Whitelist Your Domain:**

* Verify your domain ownership with Google Search Console and request reviews if blacklisting occurs.

### **Legal and Ethical Considerations:**

**Stay Within Legal Boundaries:**

* Ensure your simulations comply with local laws and regulations regarding email communications and data privacy.

**Communicate with Stakeholders:**

* Inform relevant stakeholders within your organization about the phishing simulations to avoid misunderstandings and false reports to Google.

</details>

***

### **Domain Verification and Ownership Proof**

**Verify Domain Ownership:**

* Go to [Google Search Console Security Issues](https://www.google.com/webmasters/tools/security-issues) and click "Add property now".

<figure><img src="/files/xb8O5Mt1bF5VTyHmD2sZ" alt="" width="361"><figcaption></figcaption></figure>

* Enter the URL of the property you want to verify and click "Continue".

<figure><img src="/files/QBuayKUJcw3TQeKlm5nL" alt="" width="563"><figcaption></figcaption></figure>

**Domain Name Provider Verification:**

* Choose your domain provider from the dropdown menu or select "Any DNS provider" for the TXT record method.

<figure><img src="/files/kkSqdOmSFsH9KnAZc9yj" alt="" width="563"><figcaption></figcaption></figure>

* Sign in to your domain name provider and add a TXT record as instructed.

> In this example, we will add the Google provided TXT record to my domains DNS panel in GoDaddy. This procedure should be similar for all Domain registration panels.

<figure><img src="/files/m9DsATJtvBdV6dFRq20q" alt=""><figcaption></figcaption></figure>

* Go back to Google Search Console and click Verify

<figure><img src="/files/KUQYBHV843yZi0kH5s4j" alt="" width="563"><figcaption></figcaption></figure>

{% hint style="info" %}
Sometimes DNS changes can take a while to appear. Please wait a few hours, then reopen your property in Search Console. If verification fails again, try adding a different DNS TXT record.
{% endhint %}

<figure><img src="/files/DwA1THKTjUudk9xbAtty" alt="" width="563"><figcaption></figcaption></figure>

***

### What is next?

After verifying domain ownership, Google may take 48 to 72 hours to whitelist it. Updates and notifications will be sent to the registered email in Google Search Console.


# Whitelisting a Lucy Server

### Introduction

Whitelisting is vital for effective phishing simulations. By whitelisting your Lucy server in email clients, simulation emails bypass scanning or quarantine, ensuring they reach users' inboxes. This helps focus on employees' ability to recognize phishing attempts instead of testing email defenses.

***

### Whitelisting Guides

Below are some articles to help you implement whitelisting for your mail client:

<table data-view="cards"><thead><tr><th></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Google Workspace</strong></td><td><a href="/files/u5LAFmj5hrZHXlJrpnTE">/files/u5LAFmj5hrZHXlJrpnTE</a></td><td><a href="/pages/r3ikxVJzk0CdsWAPRj3i">/pages/r3ikxVJzk0CdsWAPRj3i</a></td></tr><tr><td><strong>Microsoft O365</strong></td><td><a href="/files/sAmJCEZu43dWPy9ozdc0">/files/sAmJCEZu43dWPy9ozdc0</a></td><td><a href="/pages/xJax58DwBOCc9BVnAiGq">/pages/xJax58DwBOCc9BVnAiGq</a></td></tr><tr><td><strong>File Attack Whitelisting</strong></td><td><a href="/files/xD04V4IQ4V36Y8vtYkg5">/files/xD04V4IQ4V36Y8vtYkg5</a></td><td><a href="/pages/dB7XqKAOr0n3TpTxkji3">/pages/dB7XqKAOr0n3TpTxkji3</a></td></tr></tbody></table>

***


# Google Workspace Whitelisting

Several options in Google Workspace can be adjusted to improve the phishing simulation experience with Lucy. Follow the steps below to whitelist emails and ensure they are not flagged as spam.

***

### **Whitelisting Emails from Lucy**

**Log into Google Admin Console:**

* Go to [admin.google.com](https://admin.google.com).
* Navigate to "Apps".
* Navigate to Google Workspace
* Click on "Gmail".

<figure><img src="/files/Gzp6BOITTeAvahv8RbLW" alt=""><figcaption></figcaption></figure>

* Scroll to the bottom and select "Spam, phishing, and malware".

<figure><img src="/files/MckLnivDk5ZfDRxbSaPm" alt=""><figcaption></figcaption></figure>

* Add Lucy's IPv4 address to the "Email Allowlist".
* Click "Save".

<figure><img src="/files/FRu2SKZLwyw13aYMPoWv" alt=""><figcaption></figcaption></figure>

***

### **Bypassing Spam by Email Header**

To ensure emails from Lucy are not flagged as spam, configure Google Workspace to bypass spam detection based on specific email headers.

{% hint style="warning" %}
If you whitelist using this method, [test emails](/application-reference/support/system-tests/test-email) will still not arrive because it will not contain these campaign headers.
{% endhint %}

**Compliance Settings:**

* Go back to -> Google Workspace -> Gmail - Scroll to the bottom and select "Compliance".

<figure><img src="/files/PYKMhbpS88PRLWRRQJqw" alt=""><figcaption></figcaption></figure>

Scroll down to "Content Compliance"

* Click "Configure".

<figure><img src="/files/lv4kgH0GsibD9pHNB4Jp" alt=""><figcaption></figcaption></figure>

**Add Compliance Rule:**

* Add a description (e.g., "Lucy Email Phishing").
* Check "Inbound" and "Internal - receiving".
* Select "If ANY of the following match the message".

<figure><img src="/files/2LtP8gHj2dsceMHzxUyh" alt="" width="563"><figcaption></figcaption></figure>

* Click "Add" → Advanced content match → Headers + Body → Contains text.
* In "Content", input your Lucy X-Mailer Header (default is "X-Lucy-VictimUrl") and click "Save".

<figure><img src="/files/JoDtaQpTgak1aGVm9ONq" alt="" width="563"><figcaption></figcaption></figure>

* Scroll down to the "Spam" section and activate "Bypass spam filter for this message".
* Click "Save".

<figure><img src="/files/GWqYECPA4YBIEBzSN5n5" alt="" width="563"><figcaption></figcaption></figure>

***

### **Addressing Suspicious Link Issues**

Sometimes, a warning pop-up window appears when trying to open a link from a Lucy email. To mitigate this:

**Enable SSL in Lucy Campaign:**

* Ensure SSL is enabled in your Lucy campaign.

{% hint style="info" %}
Refer to our platform reference article on [campaign SSL settings.](/application-reference/campaigns/campaign-settings/main-settings/attack-simulation#ssl-settings)
{% endhint %}

**Consider a Paid Certificate:**

* If the Let's Encrypt certificate is not sufficient, consider obtaining a paid certificate. Contact any SSL vendor you prefer and [upload your SSL certificate](/application-reference/campaigns/campaign-settings/main-settings/attack-simulation#generate-or-upload) to the campaign.

***

### **Disable Warning Prompts:**

If issues persist, you can disable the warning prompt for links to untrusted domains in Google Workspace. Follow these steps:

* Log into [admin.google.com](https://admin.google.com).
* Navigate to "Apps".
* Select "Google Workspace".
* Go to "Gmail".
* Select "Safety".
* Go to "Links and external images".
* Deactivate "Show warning prompt for any click on links to untrusted domains".
* Click "Save".


# Microsoft O365 Whitelisting

To create, modify, or remove settings in an advanced delivery policy, you need to be a member of the specific role groups. Microsoft's new "secure by default" feature may affect your current whitelisting rules. Use Advanced Delivery Policies to whitelist emails for phishing simulations.

***

### **Avoid Spam Issues Related to Office 365**

**How are Phishing Simulation Emails Whitelisted in O365?**

Microsoft has a centralized configuration for phishing campaigns in Exchange Online Protection Policies. The Advanced Delivery section allows configuring Phishing Simulations with specific domain names and senders. Since mid-2021, changes to mail flow and filtering mean exceptions in mail flow rules are optional, and security defaults are enforced, blocking 'High Confidence Phish' emails from passing through Exchange Online Rules.

For more details, refer to the following resources:

* [Mastering Configuration in Defender for Office 365](https://techcommunity.microsoft.com/t5/microsoft-defender-for-office/mastering-configuration-in-defender-for-office-365-part-two/ba-p/2307134)
* [Configure Advanced Delivery](https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/configure-advanced-delivery?view=o365-worldwide)

***

Navigate to the configuration via the [Microsoft 365 Defender portal](https://security.microsoft.com) ->[ security.microsoft.com](https://security.microsoft.com)

**Adding Sending Domain and Sending IP to Whitelist**

* Open the Microsoft 365 Defender Portal
* Navigate to "Email & Collaboration":
* Go to Policies & Rules -> Threat policies.

<figure><img src="/files/H21NQvfnBRHPf2OwG5b2" alt=""><figcaption></figcaption></figure>

* Select Advanced Delivery.

<figure><img src="/files/epcMoZp72vhTJ8n2iXvb" alt=""><figcaption></figcaption></figure>

***

**Configure Phishing Simulation:**

* On the Advanced delivery page, go to the Phishing Simulation tab. Click the Edit icon or, if no phishing simulations are configured, click Add.

<figure><img src="/files/mfPA8Ig8Zjc5yQyA0lHR" alt=""><figcaption></figcaption></figure>

**Edit Phishing Simulation Settings:**

In the Edit third-party phishing simulation modal, adjust the following settings:

* **Sending Domain:** Enter at least one sending domain used as the sender email in Lucy.

<figure><img src="/files/QdqNjF7YFLj9CTt5L1aE" alt="" width="563"><figcaption></figcaption></figure>

* **Sending IP:** Enter the sending IP address of your Lucy instance.

<figure><img src="/files/Im6V1nfQgnzvimGAr7n2" alt="" width="563"><figcaption></figcaption></figure>

* **Specific URLs (optional):** Enter specific URLs that are part of your phishing simulation campaign using the recommended URL syntax format: `example.com/*`

<figure><img src="/files/07qfD4oGWv47FZONAP9I" alt="" width="560"><figcaption></figcaption></figure>

**Save Changes:**

* Click Add for all options and Save

**Propagation Time:**

* Wait at least 30 minutes for changes to propagate before starting any phishing campaigns.


# File Attack Whitelisting

### **Introduction**

To simulate file-based malware attacks with Microsoft Defender, you need to configure Active Directory (AD) Group Policy Object (GPO) settings to exclude specific files from being scanned. This guide provides step-by-step instructions for whitelisting files by path using GPOs.

***

### **Important Considerations**

**Whitelisting Lucy IP:**

* Ensure that Lucy's IP is whitelisted at the mail gateway level to guarantee email delivery.
* Refer to the following links for detailed instructions:
  * [O365 Whitelisting](/guides/whitelisting-a-lucy-server/microsoft-o365-whitelisting)
  * [Google Workspace Whitelisting](/guides/whitelisting-a-lucy-server/google-workspace-whitelisting)

***

**Additional Security Measures:**

* This guide covers GPO settings for AD. If your organization uses additional antivirus software or firewall protection, equivalent whitelisting must be configured accordingly.

**Macro-Related Attacks:**

* For macro-related attacks, users will still need to enable editing and macros in Office documents. Design the attack scenario to prompt users to perform these actions.

***

### **Scenario Example**

**Scenario:**

* Successful Attack = Data Submit / File Data Received
* Attack Vector: Mixed Attack (Harvest credentials via user login on a web-hosted page + download and execute payload).

**Idea:**

* The user receives an email from the CEO with a link to a list of top clients.
* The user logs in to a landing page, completing phase 1 (credential harvesting).
* The user downloads an Excel file, which is excluded from virus scanning.
* Upon opening the file and enabling editing and macros, the script runs, completing phase 2 (data submission).

***

Below is the process for adding a file to the exclusion list at the machine level:

1. **Open Windows Security:**
   * Go to Start -> Settings -> Update & Security -> Windows Security -> Virus & Threat Protection.

<figure><img src="/files/3SOHBfQzzBksk4BcgQ6A" alt="" width="547"><figcaption></figcaption></figure>

**Add Exclusion:**

* Under Virus & Threat Protection settings, select Manage Settings.
* Scroll down to Exclusions and select Add or Remove Exclusions.
* Click Add an Exclusion and choose File.
* Select the file to be excluded.

<figure><img src="/files/SeqEUmdKWWhTDL0e2hvA" alt="" width="563"><figcaption></figcaption></figure>

<figure><img src="/files/h8O9MnfY7Bzfk2RYva05" alt="" width="563"><figcaption></figcaption></figure>

This workflow demonstrates the process at an individual level, but for organizational-scale implementation, the Network Administrator will perform these steps via AD GPO.

***

### **Excluding a File Path in Active Directory via GPO:**

**Open Group Policy Management:**

* Navigate to Tools -> Group Policy Management.

<figure><img src="/files/NSnsFuOSS5ABzBF9btsN" alt=""><figcaption></figcaption></figure>

**Create or Edit a GPO:**

* Select the domain associated with the end users.
* Right-click on the policy and select Edit.

<figure><img src="/files/ACIwU5fueQOBZhCQm6d5" alt=""><figcaption></figcaption></figure>

**Navigate to Windows Defender Settings:**

* Go to Policies > Administrative Templates.

<figure><img src="/files/amDea9oAGpn9HYlwCwEg" alt=""><figcaption></figcaption></figure>

* Click on Windows Components.

<figure><img src="/files/FnLQaxx4zlWpuDrpzT2e" alt=""><figcaption></figcaption></figure>

* Scroll down to Microsoft Defender Antivirus.

<figure><img src="/files/0ZiYkykf5lOM8BCixr9V" alt=""><figcaption></figcaption></figure>

* Click on Exclusions.

<figure><img src="/files/0N02pUuydBhY7yMGzLIZ" alt=""><figcaption></figcaption></figure>

**Define Path Exclusion:**

* Select Path Exclusions.

<figure><img src="/files/SJWQOWhUfxOA0eLVRzlC" alt=""><figcaption></figcaption></figure>

* Click Enable and then Show.

<figure><img src="/files/vV03PyosLKl3rKp2MbBv" alt="" width="497"><figcaption></figcaption></figure>

* Enter the file path, e.g., `C:\Users\local.user\Downloads\List of Top clients V2.xls`.
* Set the value to 0.
* Click OK and Apply.

<figure><img src="/files/MRFQA0yx5UywCfObeMwS" alt="" width="563"><figcaption></figcaption></figure>

**Enforce the Policy:**

* Right-click on the policy in Group Policy Management and select Enforce.

<figure><img src="/files/XgFQejnCvX6yommEet7l" alt=""><figcaption></figcaption></figure>

* Run `gpupdate /force` to update the policy for all users.

<figure><img src="/files/vivWPKrZAOpafLvbSGOW" alt=""><figcaption></figcaption></figure>

***

### **Enabling Editing and Content in Excel:**

**Enable Editing:**

* When the file is opened, click Enable Editing.

<figure><img src="/files/u51zqyuVKaCg0SoljHeJ" alt=""><figcaption></figcaption></figure>

**Enable Content:**

* Click Enable Content to allow macros to run.

<figure><img src="/files/20vuCfZihifIn4915zvg" alt=""><figcaption></figcaption></figure>

By following these steps, you can ensure that Defender does not block the file download and execution, allowing the simulation to proceed as intended.

**References**

* [Configure Extension File Exclusions in Microsoft Defender Antivirus](https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-extension-file-exclusions-microsoft-defender-antivirus?view=o365-worldwide)


# Attack Simulations


# Attack Types


# Data Entry Attack

## Understanding the Attack

A data entry attack is a targeted effort where attackers deceive victims into entering their login credentials on a fake website. These attacks often leverage email spoofing, creating a sense of urgency or trust to compel the victim to act quickly.

<figure><img src="/files/HmaKJ3T1CrMT0LMQMe0H" alt=""><figcaption><p>This is an example of a Data Entry Attack, once clicked the user is directed to a fake landing page</p></figcaption></figure>

***

## Checklist

* [x] [Register an Attack Domain](/application-reference/settings/common-system-settings/domains#register-a-domain-via-the-domain-registration-wizard)
* [x] [Add a Data Entry Attack to your Campaign](/application-reference/campaigns/campaign-settings/main-settings/attack-simulation#add-an-attack-template-to-your-campaign)
* [x] [Ensure "Data Submit" is set as your Success Action](/application-reference/campaigns/campaign-settings/main-settings/attack-simulation#success-action)
* [x] [Ensure the sending Domain is whitelisted](/guides/whitelisting-a-lucy-server)

***

## Real-world Examples

* A corporate employee receives an email that appears to be from the IT department, instructing them to update their password on a fake company portal.
* A user gets a notification from a popular social media platform about unusual activity and is redirected to a fake social media site to log in.
* A recipient is notified that they are running late for a Teams or Zoom meeting and receives an email with a link to join the meeting. In their haste, they click the link and are prompted to log in on a fake Teams or Zoom login page, unknowingly entering their credentials.

{% hint style="success" %}
Ready to set up your Data Entry Attack? See our platform reference article on [Adding an Attack to your campaign.](/application-reference/campaigns/campaign-settings/main-settings/attack-simulation)
{% endhint %}

***

## User Detection Methods

To help employees recognize and respond to Data Entry phishing attempts effectively, the following user detection methods can be incorporated into training programs:

**Email Analysis**

* **Check Sender Details:** Verify the sender's email address and domain to ensure they match the legitimate source.
* **Look for Red Flags:** Be wary of emails with poor grammar, spelling errors, or unusual formatting.

**URL Inspection**

* **Hover Over Links:** Before clicking, hover over links to view the actual URL and ensure it points to a legitimate site.
* **Check for HTTPS:** Ensure the website URL starts with "https\://" and look for a padlock symbol, indicating a secure connection.

**Content Verification**

* **Suspicious Attachments:** Avoid opening unexpected attachments or downloading files from unknown sources.
* **Urgency and Threats:** Be cautious of emails that create a sense of urgency, pressure to act quickly, or threaten negative consequences.

**Login Page Checks**

* **Website Appearance:** Verify that the login page looks exactly as expected. Fake sites often have slight visual discrepancies.
* **Double-Check URLs:** Manually type the known URL of the website into your browser instead of clicking on links in emails.

**Communication Verification**

* **Cross-Check Requests:** If an email asks for sensitive information, verify the request through a separate communication channel, such as a phone call to the supposed sender.

**Incident Reporting**

* **Report Suspicious Emails:** Immediately report any suspicious emails to the IT or security department for further analysis.
* **Use Reporting Tools:** Deploy the [Lucy Phish Button](/application-reference/settings/submitted-email-settings) for all users to use as a reporting tool.

***


# Hyperlink Attack

### **Understanding the Attack**

**Definition**&#x20;

A hyperlink attack involves embedding malicious URLs in emails. When users click these links, they may be redirected to phishing sites, download malware, or unintentionally disclose personal information. For Lucy, success is measured by whether the user clicks the link.

<figure><img src="/files/YIetrivt8ss0C0db4K8x" alt=""><figcaption><p>This is an example of a Hyperlink Attack, once clicked redirecting to awareness training</p></figcaption></figure>

***

### **Checklist**

* [x] [Register an Attack Domain](/application-reference/settings/common-system-settings/domains#register-a-domain-via-the-domain-registration-wizard)
* [x] [Add a Hyperlink Attack to your Campaign](/application-reference/campaigns/campaign-settings/main-settings/attack-simulation#add-an-attack-template-to-your-campaign)
* [x] [Ensure "Click" is set as your Success Action](/application-reference/campaigns/campaign-settings/main-settings/attack-simulation#success-action)
* [x] [Ensure the sending Domain is whitelisted](/guides/whitelisting-a-lucy-server)

***

### **Real-world Examples**

* An employee in the finance department receives an email that appears to be from their HR department, prompting them to complete a timesheet.
* An employee receives an email purportedly from the HR department, containing a link to view their colleagues' performance metrics compared to their own.
* A finance executive receives an urgent email that seems to be from the CEO, containing a payment link for an emergency account transfer.

{% hint style="success" %}
Ready to set up your Hyperlink Attack? See our platform reference article on [Adding an Attack to your campaign.](/application-reference/campaigns/campaign-settings/main-settings/attack-simulation#add-an-attack-template-to-your-campaign)
{% endhint %}

***

### **User Detection Methods**

To help employees recognize and respond to hyperlink phishing attempts effectively, the following user detection methods can be incorporated into training programs:

#### Email Analysis

**Check Sender Details:** Verify the sender's email address and domain to ensure they match the legitimate source.

**Look for Red Flags:** Be wary of emails with poor grammar, spelling errors, or unusual formatting.

#### URL Inspection

**Hover Over Links:** Before clicking, hover over links to view the actual URL and ensure it points to a legitimate site.

**Check for HTTPS:** Ensure the website URL starts with "https\://" and look for a padlock symbol, indicating a secure connection.

#### Content Verification

**Suspicious Attachments:** Avoid opening unexpected attachments or downloading files from unknown sources.

**Urgency and Threats:** Be cautious of emails that create a sense of urgency, pressure to act quickly, or threaten negative consequences.

#### Link Appearance Checks

**Verify Link Text:** Ensure the visible text of the hyperlink matches the actual URL. For example, a link labeled as “[www.lucysecurity.com”](http://www.lucysecurity.com”) should not redirect to “[www.lucysecurtiy.com.”](http://www.lucysecurtiy.com.”)

**Type Known URLs Manually:** Instead of clicking on a link, manually type the known and trusted URL into your browser to ensure you are visiting the correct site.

#### Communication Verification

**Cross-Check Requests:** If an email or message asks for sensitive information, verify the request through a separate communication channel, such as a phone call to the supposed sender.

#### Incident Reporting

**Report Suspicious Links:** Immediately report any suspicious links to the IT or security department for further analysis.

**Use Reporting Tools:** Deploy the [Lucy Phish Button](/application-reference/settings/submitted-email-settings) for all users to use as a reporting tool.

***


# File Attack

### **Understanding the Attack**

**Definition**

A file attack is a type of cyber attack where malicious files are sent via email as attachments or links to web pages hosting the files. These files come in various formats, such as .exe, .SVG, Word macros, and Excel macros. The attack is successful if the user downloads, opens, and executes the file, with the executed data sent to Lucy.

<figure><img src="/files/r8ODPZLen8kpA5df3Q0U" alt=""><figcaption><p>This is an example of a File Attack, using a downloaded SVG to redirect to a malicious site</p></figcaption></figure>

***

### **Checklist**

* [x] [Register an Attack Domain](/application-reference/settings/common-system-settings/domains#register-a-domain-via-the-domain-registration-wizard)
* [x] [Add a File Attack to your Campaign](/application-reference/campaigns/campaign-settings/main-settings/attack-simulation)
* [x] [Choose a success action: File Download; File Data Received or File Opened](/application-reference/campaigns/campaign-settings/main-settings/attack-simulation#success-action)
* [x] [Ensure the File is excluded from Anti-Virus scanning in your infrastructure](/guides/whitelisting-a-lucy-server/file-attack-whitelisting)
* [x] [Ensure the sending Domain is whitelisted](/guides/whitelisting-a-lucy-server)

***

### **Real-world Examples**

* An employee in the finance department receives an email appearing to be from HR, prompting them to download and fill out a timesheet attached as a Word document with a macro. Upon enabling and executing the macro, the malicious payload is delivered.
* An employee receives an email with a link to an .SVG file purportedly containing new branding materials. When the file is downloaded and opened, it executes a script that compromises the user's system.
* A finance executive receives an urgent email seemingly from the CEO, with an attached .exe file labeled as critical software for an emergency task. When the file is downloaded and executed, it installs malware, and the executed data is sent to the attacker.

{% hint style="success" %}
Ready to set up your File Attack? See our platform reference article on [Adding an Attack to your campaign](/application-reference/templates/attack-templates).
{% endhint %}

***

### **File Attack Simulation Templates**

#### Lucy can compile different custom Malware Simulations:

Each file type can be modified (layout, filetype, name) before using it in a campaign. Currently, Lucy comes with the following file types:

{% hint style="success" %}
Want to start adapting your File Attack template? Navigate to **Templates -> File Templates**
{% endhint %}

| **Setting Name**           | **Description**                                                                                                                                                  | **Success Action**         | **Preferable Delivery Method** |
| -------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------- | ------------------------------ |
| Console Interactive        | Establishes a reverse HTTP/HTTPS channel to Lucy. Runs in memory and allows command execution in Windows shell. Only works with Windows 7/8 with IE and Firefox. | File download              | Landing page                   |
| Console Outlook            | Executes commands and sends the output back via Outlook to a predefined email address.                                                                           | File download              | Landing page                   |
| Console post               | Executes commands within Windows shell and sends output to Lucy. Allows a limited set of commands.                                                               | File download              | Landing page                   |
| Console (POST-only)        | Pings back to Lucy when the user opens the executable file, without collecting any data.                                                                         | File download/open         | Landing page                   |
| Excel Macros (GET-only)    | Pings back to Lucy when the document is opened, without sending any data.                                                                                        | Click/download/open        | Email/Landing page             |
| GoggleDocs                 | Pings back to Lucy when the document is opened, without collecting any data.                                                                                     | File download              | Email/Portable device (USB)    |
| HTML (Redirect)            | Redirects to the phishing website when opened, without transferring any data.                                                                                    | File download              | Landing page                   |
| Keylogger                  | Records keys pressed on the keyboard.                                                                                                                            | File download/submit       | Email/Landing page             |
| Macros                     | Runs console commands through an Office file that contains a Macro.                                                                                              | File download/open         | Email/Landing page             |
| Malware Testing Toolkit    | Tests if the target system is vulnerable to miscellaneous malware technologies.                                                                                  | File download/open         | Email/Portable device (USB)    |
| Microphone                 | Gets audio recordings from the microphone.                                                                                                                       | File download/submit       | Portable device (USB)          |
| Ransomware (Screen Locker) | Locks the PC screen and asks the user to enter a password. Intended to prompt user to call helpdesk for password, enhancing learning effect.                     | File download/submit       | Email/Portable device (USB)    |
| Recent Documents           | Sends back a predefined number of documents listed in the recent doc cache to Lucy.                                                                              | File download/submit       | Email/Portable device (USB)    |
| Screen Recorder            | Records screenshots and attempts to access the webcam to record a few seconds.                                                                                   | File download/submit       | Email/Portable device (USB)    |
| SVG (Redirect)             | Redirects to the phishing website when opened, without transferring any data.                                                                                    | File download/click/submit | Email/Portable device (USB)    |

{% hint style="danger" %}
Email file attacks might be blocked by server security policies. Admins should ensure that such emails aren't filtered out before running the campaign. This can involve excluding the file by path using[ GPO or whitelisting the file name](/guides/whitelisting-a-lucy-server/file-attack-whitelisting).
{% endhint %}

***

### **User Detection Methods**

To help employees recognize and respond to file-based phishing attempts effectively, the following user detection methods can be incorporated into training programs:

#### Email Analysis

**Check Sender Details:** Verify the sender's email address and domain to ensure they match the legitimate source.

**Look for Red Flags:** Be wary of emails with poor grammar, spelling errors, or unusual formatting.

#### File Inspection

**Verify Attachments:** Be cautious of unsolicited attachments, especially those with executable or macro-enabled formats.

#### Content Verification

**Suspicious Attachments:** Avoid opening unexpected attachments or downloading files from unknown sources.

**Urgency and Threats:** Be cautious of emails that create a sense of urgency, pressure to act quickly, or threaten negative consequences.

#### Execution Verification

**Disable Macros:** By default, keep macros disabled in Office documents and only enable them if absolutely necessary and from a trusted source.

**Manual File Type Checks:** Instead of clicking on attachments, manually verify the file type and source before opening.

#### Communication Verification

**Cross-Check Requests:** If an email or message asks to download or execute a file, verify the request through a separate communication channel, such as a phone call to the supposed sender.

#### Incident Reporting

**Report Suspicious Files:** Immediately report any suspicious files or download links to the IT or security department for further analysis.

**Use Reporting Tools:** Deploy the [Lucy Phish Button](/application-reference/settings/submitted-email-settings) for all users to use as a reporting tool.

***


# Portable Media

### **Understanding the Attack**

**Definition**&#x20;

A portable media attack involves distributing malicious files via removable media devices. The victim is deceived into executing the file, which then performs harmful actions on their system. In Lucy's context, success is measured by retrieving the executed data from the victim's computer.

***

### **Checklist**

* [x] [Register an Attack Domain](/application-reference/settings/common-system-settings/domains#register-a-domain-via-the-domain-registration-wizard)
* [x] [Add a Portable Media Attack to your Campaign](/application-reference/campaigns/campaign-settings/main-settings/attack-simulation)
* [x] [Ensure the success action is File Data Received](/application-reference/campaigns/campaign-settings/main-settings/attack-simulation#success-action)
* [x] [Ensure the File is excluded from Anti-Virus scanning in your infrastructure](/guides/whitelisting-a-lucy-server/file-attack-whitelisting)

***

### **Real-world Examples**

* **USB Stick in Public Places:** A USB stick labeled "Confidential - Company Financials" is left in a company parking lot. An employee finds it and inserts it into their computer out of curiosity, executing the malicious file.
* **CD with Company Branding:** A CD labeled "Employee Benefits Overview" is mailed to employees. When they insert the CD and open the file, it executes malicious code.
* **Infected SD Cards:** An SD card labeled "Project Files" is distributed at a conference. Attendees insert the card into their computers to access the files, unknowingly executing the malicious software.

***

### Configuration

**Create a New Campaign:**

* Navigate to the Campaigns Dashboard and select the "New Campaign" button. Choose the "Attack Simulation" campaign type.

<figure><img src="/files/ID0QXijcBmIXIgjRlksV" alt="" width="563"><figcaption></figcaption></figure>

#### **Choose Attack Type:**

* Select -> **Skip Wizard and enable expert setup**

<figure><img src="/files/RrDygFg6X3wWQBlFIhv8" alt="" width="563"><figcaption></figcaption></figure>

#### Give the scenario a name and client:

<figure><img src="/files/lYgO82GBaBiQUwIlvbC9" alt=""><figcaption></figcaption></figure>

#### Navigate to Attack Settings and select New Scenario:

<figure><img src="/files/iFaZFzYDVdgTKvxzweBm" alt="" width="563"><figcaption></figcaption></figure>

**Select the Portable Media Attack Template:**

* Select the "Portable Media Attack" scenario and click "Use template".&#x20;

{% hint style="info" %}
If it's not available, download it by first navigating to **Templates ->** [**Download Templates**](/application-reference/templates/download-templates) and searching for "**Portable Media Attack**".
{% endhint %}

<figure><img src="/files/tgkj2UDizBRLwcSMTa5W" alt="" width="563"><figcaption></figcaption></figure>

**Give the Scenario a Name and Pick a Domain:**

* Specify the domain or IP used upon execution. The malware simulation will send data back to this host.
* Specify what constitutes a successful attack, by default this will be set to "Data Submit" and click "Save"

<figure><img src="/files/DHX4ONXLdthXLCpvMAjg" alt=""><figcaption></figcaption></figure>

**Add your Portable Media recipient group:**

{% hint style="info" %}
Portable Media recipients are automatically generated by the system to track each file created for a portable media device and do not use company email addresses.
{% endhint %}

* Navigate to **Configuration -> Recipients -> "Add Group"**
* Add your Portable Media recipient group:

<figure><img src="/files/cRbqD8eLq7fgzxc8eb9D" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/a86EBv5xnUabydKy9S2U" alt=""><figcaption></figcaption></figure>

<details>

<summary>I received an error "Incompatible recipient group type"</summary>

This error occurs when you select a recipient group that is not optimized for a Portable Media Attack.

**Solution:**

Navigate to **Users -> Recipient Groups -> Select "New Group"**

Enter the group name, and associated client:

![](/files/yp4YLw2V2sW2N9JGiMLM)

Ensure to enable the check box for "**Portable Media Attack**" and specify the number of items you will be loading the files on.

</details>

**Download Files:**

* Navigate to **Results -> Summary -> Select "Download Files"**

<figure><img src="/files/Aev4jhGdjeQHChnMYzze" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
To address the dynamic nature of payload creation, note that these file-based attack files are not signed by code signing certificates and may trigger antivirus alerts. To mitigate this, ensure to whitelist these files by their path for testing purposes. Additionally, update the Group Policy Object to apply these changes for the company-wide simulation.

\
Please refer to our guide on [**File Attack Whitelisting**](/guides/whitelisting-a-lucy-server/file-attack-whitelisting)
{% endhint %}

#### Upload Files to Portable Media:

* Once these files are downloaded, they can be extracted from their zip file.
* Place each file on an individual Portable Media device.
* Distribute these Portable Media devices among your organization.

#### Start Campaign:

* Start the campaign and wait for the configuration checks to complete

<figure><img src="/files/tIDaPvHH0jCs8JVOgbhQ" alt=""><figcaption></figcaption></figure>

* When the campaign starts, LUCY will wait for incoming requests from the executed files.

***

### Payload Execution Process

The Portable Media attack uses a Console Post to run `ipconfig` and `whoami` commands. It aims to find users accessing unknown media and executing the payload, likely named "Yearly Bonus Report."

{% hint style="warning" %}
Portable Media Attacks are not classified as Keyloggers and will not run automatically.&#x20;
{% endhint %}

#### Payload Data Received

After a user has successfully executed the file, Lucy will capture the output data and display a success metric on the Summary Dashboard:

<figure><img src="/files/qa7kaJAraTk8CSnBwBq6" alt=""><figcaption></figcaption></figure>

* To observe the output from the file execution, navigate to **Results -> Statistics -> Collected Data**
* Click the **"command\_line\_output.txt"** to view the output data

<figure><img src="/files/Nws6k1qoliUjEn2vOSpD" alt=""><figcaption></figcaption></figure>

#### Example Output:

```bash
[ipconfig]

Windows IP Configuration


Ethernet adapter Ethernet0:

   Connection-specific DNS Suffix  . : localdomain
   IPv4 Address. . . . . . . . . . . : 10.0.0.25
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 10.0.0.2

Ethernet adapter Bluetooth Network Connection:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 

[whoami]
visvang\nick
```

***


# Smishing

## Understanding Smishing

**Smishing** is a form of phishing that uses SMS messages to direct recipients toward a malicious or simulated website or to request information.

In Lucy, a smishing scenario can use one of two primary attack types:

* **Hyperlink attack:** The recipient receives an SMS containing a link and is tracked when they click it.
* **Data-entry attack:** The recipient is directed to a landing page where they are asked to submit information.

Smishing campaigns require additional configuration because SMS delivery is subject to requirements imposed by SMS providers, mobile carriers, and the countries where recipients are located.

If you are setting up a smishing campaign for the first time, contact your **Customer Success Manager or Solution Engineer** before starting the campaign.

## Before You Begin

Complete the following steps before launching a smishing campaign:

* [ ] [Register an attack domain](/application-reference/settings/common-system-settings/domains).
* [ ] [Select an SMS provider](/application-reference/settings/common-system-settings/sms-settings).
* [ ] Create a campaign using [**Expert Mode**](/application-reference/campaigns/expert-mode).
* [ ] Add an attack scenario.
* [ ] Configure the scenario's success action:
  * **Click** for a hyperlink attack.
  * **Data Submit** for a data-entry attack.
* [ ] Enable the [**Bitly URL shortener**](/application-reference/settings/common-system-settings/url-shortener-settings) in the attack scenario settings.
* [ ] Submit the required information for SMS provider whitelisting.
* [ ] Register the SMS sender/originator.
* [ ] Confirm that provider whitelisting has been completed before launching the campaign.

{% hint style="danger" %}
SMS provider whitelisting can take several weeks. Allow a minimum of **4 weeks** for the process.
{% endhint %}

## Create the Campaign

#### 1. Register an Attack Domain

Register and configure the attack domain that will be used by the smishing scenario.

Ensure that the domain is correctly configured and accessible before creating the campaign.

#### 2. Select an SMS Provider

Select the SMS provider you intend to use for the campaign.

The available configuration depends on whether you are using Lucy's default SMS integration or a custom integration with your own provider account.

For more information, see [SMS Integration](https://chatgpt.com/sms-integration/README.md).

#### 3. Create the Campaign

Create a new campaign using **Expert Mode**.

Add the required attack scenario to the campaign.

#### 4. Configure the Attack Scenario

Configure the scenario according to the type of smishing attack you want to perform.

**Hyperlink Attack**

For a hyperlink scenario, set the **Success Action** to:

**Click**

This records the recipient's interaction with the link.

**Data-Entry Attack**

For a data-entry scenario, set the **Success Action** to:

**Data Submit**

This records when the recipient submits data through the landing page.

#### 5. Enable URL Shortening

Enable the **Bitly URL shortener** in the attack scenario settings.

URL shortening can help reduce the length of links included in SMS messages and help keep the overall message within applicable SMS character limits.

## SMS Provider Whitelisting

SMS traffic is subject to provider and carrier requirements. Before sending a campaign, you must provide the required campaign and sender information to the SMS provider.

The provider may require information about:

* The sender/originator.
* The legal entity sending the messages.
* The intended use case.
* The SMS content.
* Links included in the messages.
* The countries where recipients are located.
* The number of SMS messages to be sent.
* The campaign duration.
* Proof of authorization or consent from the organization conducting the simulation.

{% hint style="danger" %}
Do not schedule the campaign until the required provider registration and whitelisting processes have been completed.
{% endhint %}

## Register the SMS Sender

The SMS sender, also called the **originator**, identifies the sender displayed to the recipient.

The sender must be registered with the SMS provider when required by the destination country or carrier. An unregistered sender may result in messages being rejected or not delivered.

#### Originator Information

The following information may be required when registering an originator.

| Field                                | Description                                                                                                                                                               |
| ------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Originator**                       | The sender displayed to the recipient. Depending on the provider and country, this may be an alphanumeric sender ID, shortcode, or virtual/mobile number.                 |
| **Originator legal company country** | The country where the company owning the originator is legally registered.                                                                                                |
| **Originator legal company name**    | The legal name of the company that owns the originator.                                                                                                                   |
| **Originator corporate URL**         | The corporate website of the company that owns the originator.                                                                                                            |
| **Industry vertical**                | The organization's industry, such as Education, Technology, or Agriculture.                                                                                               |
| **Call to action (CTA) URL**         | A URL included in SMS messages sent using the registered originator. In Lucy, this is typically the value of the `%link%` variable.                                       |
| **Other CTA(s)**                     | Any additional URLs that may appear in the SMS message.                                                                                                                   |
| **Description of use case**          | A description of how the SMS service will be used. Explain any relationship between the registered originator and the legal company name or corporate URL if they differ. |
| **SMS template**                     | A copy of the SMS message that will be sent during the campaign.                                                                                                          |

## Additional Campaign Information

The SMS provider may also request the following information:

1. **Sender ID:** The name displayed as the sender of the SMS.
2. **Client consent:** Documentation from the organization authorizing the simulated smishing campaign and use of the specified Sender ID.
3. **Total SMS count:** The estimated number of SMS messages to be sent.
4. **SMS content:** The exact message that will be used in the campaign.
5. **Campaign duration:** The planned campaign duration, including any testing period.
6. **Locations:** The countries where campaign recipients are located.

Provider requirements can vary by country and may change over time. Always follow the requirements provided by the SMS provider for the countries targeted by the campaign.


# Lures

## Understanding the Attack

A lure is not an attack on its own, but most attack types can have a lure attached to them in the Attack Settings. Lures prepare the targets of a phishing campaign for the phishing email, lowering the user's guard and tricking them into believing that the email is real.

## Checklist

* [x] [Register an attack domain](/guides/quick-guides/create-your-first-campaign/register-an-attack-domain)
* [x] Enable **Double Barrel Attack** in the Attack Settings and set a delay
* [x] Design a Lure email (see below)

## Lure Emails

First enable the **Double Barrel Attack** setting, set a delay, and save:

<figure><img src="/files/jXo83waWCOgruWOXPZ93" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
The delay is in seconds, so 1800 seconds is 30 minutes between the lure and the attack.
{% endhint %}

Then go to the **Lure Template** tab and create a lure email:

<figure><img src="/files/EYXSO0DZAR8eTfCSLP2s" alt=""><figcaption></figcaption></figure>

{% hint style="success" %}
You are now ready to use lures in your campaign.
{% endhint %}


# QR Codes

## Understanding the Attack

A QR-code phishing attack involves embedding a malicious URL within a QR code. When victims scan the QR code, they are directed to a fake website designed to steal sensitive information, such as login credentials or personal data.

## Checklist

* [x] [Register an Attack Domain](/application-reference/settings/common-system-settings/domains#register-a-domain-via-the-domain-registration-wizard)
* [x] [Add a QR-code template to your campaign](/application-reference/campaigns/campaign-settings/main-settings/attack-simulation#add-an-attack-template-to-your-campaign)
* [x] [Set the success action](/guides/quick-guides/create-your-first-campaign/campaign-setup/attack-settings)
  * [x] If the QR code links to a data-entry page, select **Data Submit**.
  * [x] If the QR code redirects to an awareness training or other page, select **Click**.
* [x] [Ensure the sending Domain is whitelisted](/guides/whitelisting-a-lucy-server)

## Real-world Examples

* At a conference, attackers place fake QR codes near registration, leading attendees to a phishing site to steal login credentials. Victims think they're logging into the event portal.
* Attackers replace parking meter QR codes with fake ones, tricking users into entering credit card details on a fraudulent payment page. The stolen data is used for financial theft.
* Diners scan fake QR codes on restaurant tables, leading to phishing sites that steal personal information. They believe they’re accessing the digital menu.

## User Detection Methods

**Avoid Scanning from Unverified Sources**: Be cautious about scanning codes from posters, emails, social media, or ads that seem suspicious, especially in public places or unexpected messages.

**Look for Tampering**: Malicious actors sometimes overlay a fraudulent QR code on top of a legitimate one (on posters, signs, or printed materials). If a QR code looks like it’s been altered or pasted over something else, avoid scanning it.

**Check the Link Before Opening**: Many QR scanning apps and smartphones offer a feature that displays the URL before visiting the site. Review the link carefully for suspicious or misspelled URLs.

**Avoid Shortened URLs**: Phishers often use URL shorteners to disguise malicious links. If the previewed link is a shortened URL (e.g., bit.ly), proceed with caution, or use a service to expand the link and check where it leads.


# Ransomware Emulation

> ### Page Under Construction


# Technical Malware Test

## Overview

The Malware Simulation Toolkit is a powerful tool designed to mimic various types of malware behavior on your computer. However, using this tool without appropriate precautions can raise concerns within your organization's Information Security (InfoSec) team.

## Checklist

* [x] Set up a VM that replicates your real environment.

{% hint style="danger" %}
You should only use this tool inside of a VM - **never** in your real environment. While the files are ultimately harmless, they mimic the behavior of many types of malware and could raise false alarms for your security team(s).
{% endhint %}

* [x] [Download the LHFC email template](/application-reference/templates/download-templates)
* [x] [Download the Malware Testing Toolkit file template](/application-reference/templates/download-templates)
* [x] [Create a Malware Test campaign using the wizard](/application-reference/campaigns/wizard-mode)
* [x] Use the toolkit in the message template<br>

  <figure><img src="/files/8Ij9Kgy5ftedxbeLN0dR" alt=""><figcaption></figcaption></figure>
* [x] Whitelist the delivery method(s)
  * [x] Email attachment
  * [x] Download from your Lucy server
* [x] Alert your Security team before starting!

## Configure the Toolkit

The Malware Testing Toolkit comes with three different modes to choose from; Full, Advanced Dropper, and Ransomware. Each mode has its own set of configuration options:

{% tabs %}
{% tab title="Full" %}
The full toolkit performs an extensive test of the system using a large number of operations. By default the full suite of tests is active, and each test can be configured in the message template.

[Click here to view the full list of tests.](/guides/attack-simulations/attack-types/technical-malware-test/malware-toolkit-test-suite)
{% endtab %}

{% tab title="Dropper" %}
This template simulates certain aspects of malware behavior similar to [FinFisher](https://attack.mitre.org/software/S0182/), but without making any modifications to the system (e.g., no hooks, MBR changes, etc.). All activities will be executed with standard user rights.

### Setup

* The tool creates a subfolder in the TEMP directory, named something like `TMP6BCF227D` (details will be provided in the report).
* A file named `malware.jpeg` is placed in this subfolder.

### Execution

* The image is decrypted and launched from its current location.
* The contained file is a standard LUCY dropper that establishes a reverse HTTP/HTTPS connection using the browser to make base64 POST requests.
* The new process will be named `malware.jpeg`.

### Logging

* The dropper generates a log file named `log.txt`, which is stored in the `TMP*` folder.

### Information Harvesting

* A hidden folder is created in the TEMP directory, named something like `ADVDROP81227C11` (details will be recorded in `log.txt`).
* The dropper begins to gather information and, for each session, creates a subfolder within the hidden folder, named similarly to `82C89047`. The resulting structure will look like `ADVDROP81227C11\82C89047` in the TEMP directory.
* Harvested files are placed in this subfolder and are later encrypted.

### Data Transmission

* After encryption, the LUCY URL is called, and the dropper sends the files back to LUCY via POST (using HTTP or HTTPS, depending on your campaign settings).

{% hint style="success" %}
If you have SSL configured for the domain, Lucy uses HTTPs by default.
{% endhint %}

### Variables

Several LUCY variables can be defined for this template:

* **Working Hours**: Currently set from 10:00 to 00:00. If the template is launched at 9:00, the dropper will wait until 10:00 to begin execution.
* **Session Count**: Currently set to 3, meaning the dropper will create 3 subfolders within `ADVDROP81227C11`, each containing its dataset.
* **Session Intervals**: Currently set to 5 minutes, allowing the dropper to operate for approximately 15 minutes in total (`number of sessions X minutes per session`).
* **Maximum File Size**: This defines the maximum size of files the tool will send or encode within the POST requests (in kB).
  {% endtab %}

{% tab title="Ransomware" %}

### Overview

Ransomware is a type of malware that restricts users from accessing their systems or files. Victims are typically coerced into paying a ransom through various online payment methods to regain access to their systems or recover their data. Some ransomware, such as Cryptolocker, encrypts files, while others, like CTB Locker, utilize TOR to conceal command and control (C\&C) communications.

### Simulation Tool

Our template simulates a form of ransomware that locks files such as documents, spreadsheets, and other important data. It then creates an encrypted copy on either a shared drive with write access or locally. The primary goal of this template is to determine if the information-gathering activities or the significant number of read/write operations on a drive from a single PC trigger any alerts in your monitoring system.

### Settings

Within the tool, you can specify several settings:

* **File Location:** Where the tool will install itself.\
  0 = Current directory, 1 = Desktop, 2 = Temp folder, 3 = User folder
* **Start/Stop Hours:** When the tool will execute and when it will automatically unlock.
* **Operation Mode**: Choose whether to work with dummy data or real data discovered on the network. Mode 0 = Data Discovery, Mode 1 = Dummy Data.
* **File Extensions**: Specify which file types to search (default: doc, ppt, xls, pdf, txt).
* **Maximum File Size**: Set the maximum size of files to process (default: 512 KB).
* **Number of Files**: Specify the maximum number of files to copy (default: 100).
* **Crawl Time (minutes):** The maximum amount of time the tool will spend searching for files.
* **Data Retention**: Decide whether to leave a copy of the data on the PC/share or delete it after execution.
* **Number of fake file operations:** If using dummy data, this setting controls the maximum number of files the tool will create.
  {% endtab %}
  {% endtabs %}

## Running the test

Start your campaign, then either download the toolkit to your VM from your Lucy server or from the campaign email attachment.

{% hint style="warning" %}
A test like this is likely to raise a lot of red flags for your InfoSec team. While this is a good sign that your policies are working to protect you, it's best to give them a heads up before executing this test and setting off alarms.
{% endhint %}

## AV problems and security warnings <a href="#av_problems_security_warnings" id="av_problems_security_warnings"></a>

Some antivirus solutions may flag the tool as a virus or suspicious file, especially behavior-based antivirus programs. This indicates that your antivirus can detect certain methods used by the tool that are commonly associated with malware. It is a positive sign that your antivirus can identify malicious code without relying solely on signatures. Since the toolkit mimics malware activities, these alerts are not inherently incorrect. You can either ignore them or, if necessary, disable your antivirus if it prevents you from completing the malware assessment test.

You may encounter multiple security warnings when opening or executing the file. If you open the file as an email attachment or download it, a warning window will inform you that executables can be dangerous and may harm your computer. This warning occurs because the executable is not code-signed. We cannot code-sign the executable because parts of it are dynamically generated at runtime; however, it is safe to execute.


# Malware Toolkit Test Suite

The Toolkit tests if the target system is vulnerable to miscellaneous malware technologies.

## Command Line Access

All tools tested within the custom malware test are custom-made and utilize Windows functionalities (not exploits) to access data within the protected network, making them harder to detect. However, they are not designed to conceal their malicious functionality (e.g., they post data back to a server using long base64 strings in a fixed rhythm). This tool allows the execution of hardcoded commands. The toolkit will verify whether an external program can initiate the shell and execute commands.

## Recent Documents Access

If malware can access the recent document path, it can learn a lot about which files were recently used and where they are stored. The tool can use cached user credentials to access the last documents (either locally or on a shared drive). This tool will read the absolute paths from the recent documents directory and attempt to access them.

## Outlook Access

An external tool can overwrite the security warning in Outlook, gaining access to all emails or even sending emails via Exchange on behalf of the compromised user. This tool will use Outlook MAPI to overwrite the security message and attempt to access the last message in the inbox.

## Screenshots

Malware capable of taking screenshots may record on-screen activity, such as passwords entered using an on-screen keyboard. This tool will attempt to take screenshots of the current desktop.

## Webcam Access

Malware that can take pictures with the webcam may be used to spy on users or blackmail them. This tool will try to take a picture with the webcam.

## Microphone Access

Malware can embed itself into computer systems without detection by traditional antivirus applications and can execute total surveillance, including turning on the camera and microphone, copying data, and recording emails and chat conversations. The toolkit will test whether a third-party application can access and record from an attached or built-in microphone.

## Access to the Internet via HTTP

Malware could embed its own custom web browser. The toolkit will verify if malware can connect back to the Internet using its own HTTP class, simulating a portable tool with a built-in custom browser.

## Access to the Internet via Internet Explorer

Inside-out attacks attempt to initiate network connections from a trusted (corporate) network to an untrusted (Internet) network. The inside-out attack consists of three steps: delivery (getting the backdoor into the network), execution (executing the backdoor by the user), and output delivery (sending the data out). The toolkit will verify if malware can connect back to the Internet using Internet Explorer via HTTP.

## HTTP Access with IE Proxy

Malware could integrate a custom web browser and read proxy details from the registry. The toolkit will verify if malware can connect back to the Internet using its own HTTP class with the current proxy settings.

## HTTP Access with IE Proxy with Credentials

Malware could embed its own custom web browser, read proxy details from the registry, and access stored credentials. The toolkit will attempt to access the Internet using the default credentials stored on the system, simulating malware that can bypass security controls like integrated Windows authentication on a corporate proxy.

## HTTP Access with Proxy from Firefox Settings

If the company disables Internet Explorer, malware could attempt to access the Internet using Firefox. The toolkit will verify if malware can connect back to the Internet using its own HTTP class with the current proxy settings accessed through a different browser (Firefox).

## Access to the Internet via HTTPS

Malware might conceal its activity by using an encrypted connection. The toolkit will verify if malware can connect back to the Internet via HTTPS using its own HTTP class, simulating malware that has a built-in custom web browser.

## DNS Tunneling

Using DNS tunneling, malware can access a remote server via HTTP, even if the proxy blocks the website. In a DNS tunnel, data are encapsulated within DNS queries and replies, utilizing the DNS domain name lookup system for bi-directional data transfer. The toolkit will test if it can resolve an external third-party domain directly on the client.

## Protocol Tests

### ICMP

ICMP tunneling injects arbitrary data into an echo packet sent to a remote computer, which replies by injecting an answer into another ICMP packet and sending it back. The toolkit will send various ICMP packets with random data and sizes to an external host.

### SMTP

SMTP is a common protocol for malware distribution. The toolkit will verify if malware can connect to the Internet directly using a protocol like SMTP.

### FTP

FTP is a common protocol used by malware to export collected data. The toolkit will verify if malware can connect to the Internet directly using a protocol like FTP.

### SSH

Malware could establish an outbound connection that cannot be logged using SSH. The toolkit will verify if malware can connect to the Internet directly using a protocol like SSH.

### IRC

Internet Relay Chat (IRC) is an application layer protocol that facilitates communication through text. The toolkit will test the ability to connect to an external IRC server and channel, send a couple of messages, and then disconnect after a short wait.

## OS Version

This check is purely informational. In this step, the tool attempts to identify the host operating system.

## Local Administrators

If a user has local administrative rights, they can disable the security enhancements that protect them (e.g., Firewall, BitLocker, Antimalware). This check verifies if any users have local admin rights on the PC.

## Firewall

If an infected laptop is connected to the network, it may attempt to infect all other devices on the LAN, potentially bypassing the corporate firewall. Local firewalls can also prevent the successful transmission of the virus. The toolkit will verify if the firewall is running and then test whether it can be disabled.

## Antivirus

The toolkit will verify if an antivirus product is running and whether it can be disabled.

## Virus Download

[Simda](https://www.microsoft.com/en-us/wdsi/threats/threat-search?query=win32/simda) is a multi-component malware family that includes Trojan, backdoor, password-stealing, downloader, and file-infector variants.

**Backdoor:Win32/Simda.A**: This variant allows a remote user to connect to an infected machine and perform malicious actions, such as stealing user credentials and capturing screen images. The backdoor component drops a malicious DLL that is injected into Windows processes to gather user information, detected as **PWS/Simda.A**. The backdoor can exploit vulnerabilities to gain elevated privileges, allowing it to perform more restrictive actions, such as Windows process injection. It may also gain admin privileges by brute-forcing the administrator password using a dictionary attack. Once access is gained, it collects user information, logs keystrokes, and takes screenshots. The backdoor connects to its command and control server to report infection and download a configuration file.&#x20;

Once connected, a remote attacker can collect the stolen information and execute additional commands. In this check, the toolkit will test if a known dangerous virus called Simda can be downloaded. If the download is successful, the toolkit will check if the downloaded file can be placed in the "Documents" folder.

## Hosts File

The toolkit will verify if write access to the hosts file is granted.

## Add New User

A local account is specific to your computer and not integrated with any of Microsoft's online services, similar to accounts used in previous Windows versions. If malware can create users, it might "backdoor" the system and bypass other security mechanisms in place. The toolkit will attempt to add local users.

## Patch Level

If a patch is missing and an exploit exists, the system can be easily compromised. The toolkit will examine the patch level, comparing it with current exploits. The toolkit will specifically look for privilege escalation exploits and their respective KB patch numbers, such as `KiTrap0D (KB979682)`, `MS11-011 (KB2393802)`, `MS10-059 (KB982799)`, `MS10-021 (KB979683)`, and `MS11-080 (KB2592799)`.

## Passwords in Configuration Files

In environments requiring the installation of many machines, technicians typically do not visit each machine individually. Various solutions enable automatic installations, and these methods often leave behind configuration files used in the installation process. These files can contain sensitive information, such as the operating system product key and administrator password.

## Passwords in Policies

GPO preference files can create local users on domain machines. When a compromised box is connected to a domain, it’s worthwhile to search for the `Groups.xml` file stored in `SYSVOL`, which any authenticated user can read. The password in this XML file is "obscured" from casual users by encryption with AES. However, it is only obscured because the static key is published on the MSDN website, allowing for easy decryption.

## AlwaysInstallElevated

The toolkit will check for the registry setting `AlwaysInstallElevated`. If enabled, this setting allows users of any privilege level to install `.msi` files as `NT AUTHORITY\SYSTEM`. It is a Group Policy setting for Windows Installer that runs any Windows Installer Package (.msi file) launched by a user under the Local System account. This allows users to install applications they need without granting them administrative rights.

## Write Access

The toolkit will verify if malware has write access to important system files.

## Autostart

The toolkit will verify our ability to place an executable in the autostart folder.

## Autorun

AutoRun is a Windows feature that automatically executes files when a USB drive is plugged into a Windows machine. AutoRun is often used by malware to enable its own execution as soon as a USB drive is inserted. Microsoft has significantly disabled AutoRun for many file types, yet some applications (like a disk image mounted in Windows Explorer) may still execute AutoRun files. The toolkit will verify if autorun can execute files from a USB stick.

## Mounted Shares

When computers connect via a network, malware writers gain a transport mechanism that can surpass the capabilities of removable media to spread malicious code. The toolkit will attempt to access known shares to test their access security and, in a second step, scan the same network range as the host to check for anonymous user access to shares.

## Domain Shares

Similar to mounted shares, attacks can replicate across computer systems using various methods. The toolkit will attempt to access known shares to test their access security and then scan the same network range as the host to check for anonymous user access to shares.

## Port Scan

After infecting a host, malware will scan neighboring IP addresses to find new targets. Malware writers do not rely on standard commands, as monitoring and restricting these might lead to containment. Instead, they evaluate the next host by scanning all IP addresses in the host's address space. The toolkit will scan a small selection of hosts in the same network for common ports.

## Firewall Block

Malware may try to connect on random unknown ports back to the attacker. The tookit will test if an outbound TCP connection on a very high port is possible. Such connections are usually suspicious and should be dropped.

## Direct DNS Access

The toolkit will verify whether malware can perform a DNS tunneling attack by resolving a third-party domain from the client. If the server resolves to an IP address, it indicates that the client can make DNS queries to external domains using internal DNS forwarders. For a real-world test of DNS tunneling traffic, please use the "DNS Tunneling Test."

## Suspicious Communication

The toolkit will check if your SIEM detects suspicious GET requests to malware-related sites. It will parse a current list of malware-related websites, such as <https://www.malwaredomainlist.com>, and then attempt to make simple GET requests to selected sites to see if connections to these malicious sites are allowed or blocked.

## File Operations on Share

The toolkit will test on a mounted share (if detected) to see if multiple hundreds of read/write operations can occur within a short time window from the same source.


# Mail & Web Filter Test

## Understanding the Attack

The Mail and Web Filter Test provides insight into how your mail server and web proxy handle various types of test files. It allows you to assess whether the filtering infrastructure detects and blocks potential malicious content such as Java files, scripts, and embedded Office objects. Based on the results, you can refine your security measures and execute targeted phishing simulations to improve defenses.

<figure><img src="/files/xjYWOVQ38JmTihmy0ZbS" alt=""><figcaption></figcaption></figure>

***

## Checklist

* [x] [Register an attack domain](/guides/quick-guides/create-your-first-campaign/register-an-attack-domain)
* [x] [Download the Mail & Web Test attack template](/application-reference/templates/download-templates)
* [x] [Create a Mail & Web Filter Test campaign using the Wizard](/application-reference/campaigns/wizard-mode)
* [x] Alert your Security team before starting!

{% hint style="success" %}
A test like this is likely to raise a lot of red flags for your InfoSec team. While this is a good sign that your policies are working to protect you, it's best to give them a heads up before executing this test and setting off alarms.
{% endhint %}

## Test Files

You can customize your test by enabling/disabling different files in the template; click on a category to view and select each file. By default all files are active.

<figure><img src="/files/mmpUCb27P6Y5hkOzrRgv" alt=""><figcaption></figcaption></figure>

## Test Results

View the results of your test on the Summary page. Click on a category to see which files were delivered and downloaded successfully.

<figure><img src="/files/KCxpPtcRXXmkIjgEKf0m" alt=""><figcaption></figcaption></figure>


# Email Spoofing Test

## Overview

Email spoofing is the forgery of an email header, making it appear as though the message originated from someone or somewhere other than its actual source. This tactic is commonly used in phishing and spam campaigns, as individuals are more likely to open emails they believe have been sent by a legitimate source. The goal of email spoofing is to entice recipients to open the email and potentially respond to the solicitation.

## Checklist

* [x] [Register the domain](/application-reference/settings/common-system-settings/domains#register-a-domain-via-the-domain-registration-wizard)
* [x] Create a recipient on the domain
* [x] [Create a mail spoofing campaign in the wizard](/application-reference/campaigns/wizard-mode)

## Run the Test

To run the mail spoofing test simply enter the domain and recipient in the wizard and click **Start Test**.


# Attack Template Customization

### Edit an Attack Template

{% hint style="info" %}
Navigate to **Templates -> Attack Templates**
{% endhint %}

Lucy offers two workflows for customizing templates: copying and editing an existing template, or starting from scratch with a blank canvas to create a new attack template.

<details>

<summary><strong>Copy an existing template</strong></summary>

Search for the desired template, select the template, click on the Actions drop-down and select Copy.<br>

<img src="/files/es8WVBx00SwEcjOYsYUC" alt="" data-size="original"><br>

Please wait while the system creates the copy. The time required may vary depending on the size of the template and could take a few minutes.

Once the copying process is complete, the system will display a green banner indicating "<mark style="color:green;">Finished Successfully.</mark>"

After copying a template, when you search for the template, you'll find the original plus the new copy, which is distinguished by the addition of "(copy)" in the title.<br>

<img src="/files/5xyfxr1l6eawVPEfPTVy" alt="" data-size="original">

To edit the copied template, select "Edit Template"

![](/files/ugdy0cwiV6tL0g7PCV26)

</details>

<details>

<summary><strong>Create a New Template</strong></summary>

Select the option for "New Template"

![](/files/IFcQekBJqug6CUripMDK)

The subsequent page will take you to the base settings of the template, where you can define the core components of the template.

![](/files/hIW0zBotEcM5RKUtTo8P)

</details>

We will select an existing template, copy it, and modify it to align with the organization's branding. We'll use the ChatGPT template.

Make a Copy:<br>

<figure><img src="/files/fkuK3HnFEYPPIUcpxISs" alt="" width="331"><figcaption></figcaption></figure>

Search for the copied template, select "Edit Template"<br>

<figure><img src="/files/rUdXGi3Lo12gTazKgVNp" alt="" width="375"><figcaption></figcaption></figure>

This page serves as the foundation for your template's settings, providing an opportune moment to establish all base parameters.

<figure><img src="/files/XORy0ow1qOCKXwj0WB3q" alt="" width="375"><figcaption></figcaption></figure>

Once your base settings are defined, click "Save" to commit the changes.

{% hint style="danger" %}
Please note that adding a language does not automatically translate the content; it merely creates an additional folder designated for manual translation into the specified language.
{% endhint %}

### Attack Message Template

After adjusting the base settings, select "Message Template" in the side panel.

<figure><img src="/files/rL1sPOJyrSSkxaHvoDsG" alt="" width="255"><figcaption></figcaption></figure>

At the top, options are provided to upload your own email template as a .zip file, clear all current attachments, or permanently delete attachments.

<figure><img src="/files/bIyzlUsJQehsmN6y0TnN" alt=""><figcaption></figcaption></figure>

{% hint style="success" %}
**New in Lucy version 5.3!**

Select **Upload .EML** to create an attack template from an email file. With this option you can create training scenarios from real-world phishing emails to better simulate the types of threats your organization faces.
{% endhint %}

{% hint style="warning" %}
Outlook still uses a limited HTML engine (which only supports part of HTML and CSS), so layouts may differ. We adapt the template to older HTML best practices (table-based, inline styles). Some limitations remain: only black or no borders, no shadows or rounded corners.
{% endhint %}

{% hint style="warning" %}
Editing email content is language-specific; changes in one language won't apply to others.
{% endhint %}

<figure><img src="/files/tWTiEYjR4MSFUpmeagGz" alt="" width="563"><figcaption></figcaption></figure>

{% tabs %}
{% tab title="Message Type" %}
This setting allows you to specify whether the attack is email-based or a smishing (SMS phishing) attack. For detailed instructions on setting up a smishing campaign, please refer to our guide on [smishing](/guides/attack-simulations/attack-types/smishing).
{% endtab %}

{% tab title="Language" %}
The option shows which language's email template you are currently editing.
{% endtab %}

{% tab title="Subject" %}
This specifies the subject line that recipients will see when they receive the email in their mail client.
{% endtab %}

{% tab title="Editor Type" %}
Lucy employs a standard open-source visual editor, known as a "What You See Is What You Get" (WYSIWYG) editor, as the default editing tool. For administrators who prefer editing in the source code directly, the "Code Mirror" editor is available as an alternative option.

{% hint style="info" %}
You can change your default editor in the [Advanced Settings](/application-reference/settings/advanced-system-settings/advanced-settings#default-editor-type)
{% endhint %}
{% endtab %}

{% tab title="Content" %}
This is the main editor where you will make adjustments to your email template.
{% endtab %}
{% endtabs %}

Start with the Subject line by incorporating your company name.

<figure><img src="/files/a6ZXCHkPExoqAWCGK1YD" alt="" width="515"><figcaption></figcaption></figure>

In the email body, strategically place your company name wherever it's relevant to reinforce the impression of a genuine collaboration.

<figure><img src="/files/kwmcYNBMhJJnrOztuK8O" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Expand the Visual Editor for easier navigation and template editing.

![](/files/z0DSI5muxPJ09ZFiv8e2)
{% endhint %}

Add your company logo by selecting "Upload file or Image" and choose your logo file to insert at the bottom of the email for enhanced brand recognition and trust.

<figure><img src="/files/ULv96RBp9T6fHJdRWXCW" alt=""><figcaption></figcaption></figure>

<details>

<summary>Guide to Uploading File or Image</summary>

Select "Upload file or Image" in the Visual Editor

![](/files/PmQ0M8WiS1t0vBBc9D2w)

Select "Browse Server" or provide a publicly accessible URL.

![](/files/yaO6GEfbMW0tlcENyMFL)

Select "Upload"

![](/files/9qbEM1fZWX4p2nguS0gG)

Choose your file for upload and wait for the server to confirm a successful upload - Double-click on the uploaded file

![](/files/6OIFfdk1JRGEB7hJWbsH)

Upload your image and adjust its size. Keep the aspect ratio lock enabled. Scale the image to a width of 120px to fit nicely into the email layout.

![](/files/maTiABVS2scgyEgxZyF4)

Click "Ok" once you are happy with the changes made.

![](/files/EFwRPZpcavcFqJ7OhOJh)

Double-click the image in the Visual Editor to open settings and make further adjustments.

</details>

Lucy uses placeholder variables like **%{VALUE}%** to personalize email content for phishing campaigns. This allows Lucy admins to make emails more credible by including details like the recipient's first name, gender, or time-sensitive information.

In this example, the variable **%name%** is included by default, which automatically fetches the recipient's full name from the [imported recipient group](/application-reference/users/recipient-groups) data.

<details>

<summary>Placeholder Variables</summary>

Here are detailed explanations for each variable that can be utilized in the template:

* **%link%**: Generates a unique page URL for the recipient. This can be used to direct users to a specific landing page tailored for the phishing simulation.
* **%link-awareness%**: Provides a link to an awareness website. This variable requires the awareness website to be configured and enabled in the campaign settings beforehand.
* **%qr-code%**: Creates a QR code representing the unique page URL for the recipient. This can be scanned by the recipient's device, directing them to the specified URL.
* **%name%**: Inserts the recipient's full name as provided in the recipient group import, allowing for personalized email content.
* **%firstname%**: Places the recipient's first name into the email, enhancing personalization.
* **%lastname%**: Adds the recipient's last name into the email, further personalizing the message.
* **%email%**: Includes the recipient's email address within the email content.
* **%division%**, **%location%**, **%staff-type%**, **%comment%**: These variables are used to insert recipient-specific information such as their division, location, staff type, or any comments.
* **%gender("MALE ADDRESSING", "FEMALE ADDRESSING", "NO GENDER")%**: Customizes the email content based on the recipient's gender, allowing for gender-specific addressing.
* **%subject%**: Displays the subject of the phishing mail, which can be used within the email content for reference.
* **%sender%**: Indicates the sender's name of the phishing mail, adding authenticity to the message.
* **%sender-email%**: Shows the email address from which the phishing mail is sent.
* **%time(FORMAT, OFFSET, ZONE)%**: Allows for time-based variables within the email.
  * **FORMAT** specifies the date/time format.
  * **OFFSET** is the date/time offset in minutes, which can be positive or negative, adjusting the time displayed relative to the email's submission time.
  * **ZONE** refers to the time zone.
  * Example: `%time("l, H:i", "0", "Europe/Zurich")%` outputs the exact time of email submission in the Europe/Zurich zone (e.g., "Monday, 09:20").
  * Example: `%time("Y/m/d H:i:s", "60")%` shows the time 1 hour ahead of the email submit time.

Please note, these variables cannot be used in CSS and Javascript files.

</details>

Specifying the link within the attack email is crucial. Lucy automatically includes a **%link%** placeholder to use the campaign's domain in the link. If you want to change this link to another word in the email, you can do so:

* Highlight the desired word.
* Choose the "link" option in the visual editor toolbar.
* Alternatively, you can use the keyboard shortcut (Ctrl + L).

<figure><img src="/files/0JhowAgzF7igKkgrKOB8" alt=""><figcaption></figcaption></figure>

Highlighting a word prompts a pop-up to define the link. By default, Lucy inserts the **%link%** placeholder, eliminating the need for further action from the administrator.

<figure><img src="/files/0fbecgQVaDK43sWkX7e5" alt="" width="479"><figcaption></figcaption></figure>

***

### Attack Landing Page Template

Modify your attack landing page. Lucy allows administrators to adjust default pages or upload their own. You can also copy a landing page from any target website.

<figure><img src="/files/4YDuCVLtDnJ3C2853lLY" alt="" width="563"><figcaption></figcaption></figure>

{% hint style="warning" %}
Select your language before making edits. Changes are language-specific and must be made separately for each language.
{% endhint %}

Understanding landing page structure is key for successful data handling in Lucy. Each attack landing page has two files: **index.html** and **account.html**

<figure><img src="/files/SXAc6rrkTx8Qdvl8qNMH" alt="" width="483"><figcaption></figcaption></figure>

{% hint style="warning" %}
**Note:** Do not modify the names of these pages: `index.html` and `account.html`, as they are hardcoded into the system.
{% endhint %}

{% tabs %}
{% tab title="index.html" %}
`index.html` serves as the login page to which users are directed after clicking the simulated phishing link in their email.

This action is standard in all attack templates. If you replicate a website, ensure you change the form action to `"?login"` to enable the submission of user credentials back to Lucy.

```html
<form action="?login">
```

If you inspect the source code, you will notice the following form action:
{% endtab %}

{% tab title="account.html" %}
`account.html` is the next page after users submit their data successfully.

It's important to keep this page as the attack relies on moving from index.html to account.html.

If you want to indicate that this was a phishing simulation, you can achieve this by redirecting to an awareness page template. See our guide on [redirecting users to an awareness template](/guides/attack-simulations/redirecting-users).
{% endtab %}
{% endtabs %}

Edit the landing page with the WYSIWYG editor by changing text, dragging components, or uploading custom icons and images.

<figure><img src="/files/NQNt3Jb1tT5680XDF4hM" alt="" width="563"><figcaption></figcaption></figure>

Once you configure your attack landing page, you can proceed to [bind this attack template to a campaign](broken://pages/kmdRvPW7V3n8mmWqJWfd).


# Firewall Protection Interval


# Email Tracking Technologies

### Introduction

Tracking email opens can be achieved through various technologies:

**Read-receipts:** Employed by applications like Microsoft Office Outlook and Mozilla Thunderbird, this technology allows senders to request a notification when an email is opened. However, it is not supported by web-based mail clients or mobile devices, and users can disable this feature or ignore the requests.

**Tracking Images (Tracking Pixels):** These are tiny (often 1x1 pixel) GIF files embedded in emails, known as beacons. When the email is opened, the pixel loads the GIF from a server, logging an event that indicates the email has been opened. However, if the mail client has disabled automatic image loading, the tracking will not work.

**Link Tracking:** This involves embedding unique identifiers in links within the email. When a recipient clicks on a link, the event is logged, providing reliable data on user engagement.

### **LUCY's approach to Tracking opened emails**

LUCY employs tracking images and link tracking but avoids read-receipts due to their limited reliability and perceived intrusiveness. Link tracking is highly effective as it automatically provides data based on link interactions. It is enabled by default and requires no manual setup.

### **Challenges with Tracking Pixels**

* **Automatic Image Loading Disabled:** If the recipient's email client has disabled automatic image loading, the tracking pixel will not load, and no open event will be logged.
* **Preliminary Image Downloading:** Some email clients may download external content preemptively for caching or security, which might falsely indicate an email as opened.

### **Configuration**

Email tracking settings can be adjusted within the [scenario settings of a campaign](/application-reference/campaigns/campaign-settings/main-settings/attack-simulation#advanced-tracking), allowing for tailored tracking strategies based on campaign goals and the technology's limitations.


# Advanced Information Gathering

### **Introduction**

LUCY helps organizations run phishing simulations to identify vulnerable users. However, ensuring a user's browser is safely configured, especially when accessing corporate email from personal devices, remains a challenge.

### **Advanced Information Gathering Framework**

LUCY's Advanced Information Gathering (AIG) tool enhances user awareness training by mimicking drive-by malware attacks to test internal security. AIG targets vulnerabilities in web browsers, the primary entry point for many security threats.

AIG can safely expose web and browser-based vulnerabilities, such as cross-site scripting (XSS), using client-side attack vectors. If a user clicks on a link embedded by AIG, their browser connects to the AIG server integrated into LUCY. This connection allows AIG to perform various actions on the browser, such as redirecting the user, changing URLs, or generating dialogue boxes.

### **Purpose of Advanced Information Gathering**

With AIG integrated into LUCY, companies can assess two critical security questions:

1. Would an employee potentially fall for a phishing attack?
2. If they did, would their browser's security settings prevent further damage from browser-exploitation malware?

### What Information is Gathered?

**Browser Details:** Tracks specific browser information like type, version, and extensions. This helps identify security weaknesses or confirm if the browser is up-to-date with best practices.

**Firebug Information:** Firebug is a popular web development tool. If a user has Firebug installed, it could potentially be used to debug or modify webpages. Tracking whether Firebug or similar tools are present can reveal if there's an increased risk of web-based threats or attacks.

**Popup Blocker:** This checks if the user’s browser is configured to block popup windows. Popups are often used in phishing attacks to deliver malicious content, so knowing whether popup blockers are active can be indicative of the user's level of vulnerability.

**Geo Location:** By determining the geographic location of the user, the organization can assess if there are access patterns from unusual locations that could indicate compromised credentials or other security issues.

**Social Network:** This feature checks for active connections to social networks from the user’s browser. Given that social networks can be platforms for phishing and malware distribution, awareness of such activity can be crucial for understanding the social media risk landscape.

**Proxy:** Identifying whether the user is connected to the internet via a proxy can be important for security. Proxy usage can obscure the true IP address, which could either be a legitimate privacy measure or a method to hide malicious activity.

### **Setting Up Advanced Information Gathering in LUCY**

Advanced Information Gathering runs in the background of a phishing campaign's landing page. It is operational only in scenarios where a user-accessible landing page is active.

{% hint style="info" %}
For detailed setup instructions, please consult our platform reference article on [Advanced Information Gathering](/application-reference/campaigns/campaign-settings/main-settings/attack-simulation#advanced-information-gathering).
{% endhint %}

### Advance Information Gathering Statistics

After completing the attack, the Advanced Information Gathering (AIG) statistics will be accessible in multiple locations. Initially, an administrator can quickly view these by navigating to the [Recipient Statistics](/application-reference/campaigns/campaign-settings/results/statistics#recipients) within the campaign, where the report can be directly evaluated in the user interface.

<figure><img src="/files/MS2b2yXB8YrGgawO5VV0" alt=""><figcaption></figcaption></figure>

Once the recipient's profile is selected, scroll down to view the Advance Information Gathering tab:

<figure><img src="/files/IKdFaOzEIeLxnWtYtQ5u" alt=""><figcaption></figcaption></figure>

Exporting the campaign results to a CSV or XML file will provide detailed information, including the operating system (OS), IP address, browser type, plugins, Proxy-IP and Geo-Location of the user in the report:

<figure><img src="/files/LoYFFALW1CAqaFoQmK1L" alt=""><figcaption></figcaption></figure>

{% hint style="success" %}
Refer to our platform reference article on [Campaign Exports](/application-reference/campaigns/campaign-settings/results/exports)
{% endhint %}


# Regular Expressions in Login Fields

### Introduction

Lucy can create phishing scenarios where users are prompted to [login on a landing web page](/guides/attack-simulations/attack-types/data-entry-attack). To ensure that only valid logins are counted as successful attacks, Lucy allows you to define regular expressions within the login field, which serve as filters for login criteria. These criteria can include requirements such as:

* Passwords containing at least two alphanumeric characters.
* Usernames containing a specific domain name, among others.

### Configuration

For Lucy to apply regular expressions in a login field, the login form must use a POST method with the login action set to "**?login**". Additionally, the name of the login field should be "**login**" and the name of the password field should be "**password**". A valid login field in Lucy might resemble the following HTML snippet:

```html
<form action="?login" class="login-form" method="post" name="login-form">
  <div class="content">
    <input class="input username" name="login" placeholder="Username" type="text" /> 
    <input class="input password" name="password" placeholder="Password" type="password" />
    <div class="footer">
      <input class="button" name="submit" type="submit" value="Login" />
    </div>
  </div>
</form>
```

You can configure login filters [under scenario settings](/application-reference/campaigns/campaign-settings/main-settings/attack-simulation#regexp) once you've set up the login fields with the correct naming convention. Lucy will then be able to apply the filter mechanism. You can choose from a list of existing filter examples in the dropdown menu, or apply any POSIX regular expression filter within the input fields.

<figure><img src="/files/OuU2cCNAtqKsWW1Fyzp5" alt=""><figcaption></figcaption></figure>

Additionally, Lucy supports JavaScript-based login filters. An example of such a function verifies if the username starts with certain letters and checks if the password is complex. If both conditions are met, the script sends fake login data to Lucy for admin verification.

```html
<html>
<body>
  <form action="?login" method="post">
    <div><input id="inp_user" maxlength="127" name="login" size="30" title="Enter user name" type="text" width="180px" /></div>
    <div class="right"><input id="passwd" maxlength="127" name="password" size="30" type="password" width="180px" /></div>
    <div class="right"><input id="Log_On" onclick="return checkPwd();" type="submit" value="Submit" /></div>
  </form>
  <script type="text/javascript" src="/public/campaign/XXX/jquery-1.11.3.min.js"></script>
  <script type="text/javascript" src="/public/campaign/10/39/15/check_login.js"></script>
</body>
</html>
```

Make sure to download the corresponding JavaScript libraries and include them in your campaign template (landing page).

{% file src="/files/drl1X0hMAzKqJ33RXsZi" %}


# Copy a Website

Real phishing content often attempts to copy the appearance of a legitimate web page, and you may want to do the same with your simulated attacks. To assist with this, attack templates have a copy feature for quickly inserting existing web content into your template.

{% hint style="info" %}
Navigate to **Attack Templates -> Edit Template -> Landing Page Template**
{% endhint %}

{% hint style="success" %}
This feature works best with a blank template.
{% endhint %}

***

## Preparing the template

Since we are copying a whole webpage, starting with a blank template is best.

Make a copy of one of the blank templates:

<figure><img src="/files/OVz4znKNsRiADr7yUsrj" alt=""><figcaption></figcaption></figure>

Now select the copy and make the necessary changes to the template details like name, description, languages, etc. When you're ready go to the **Landing Page Template** for the next steps.

***

## Copying index.html

In this example we'll be copying the Lucy login page:

```
https://<lucy_domain>.com/admin/login
```

Switch the **Language** field to your desired language, then select **Copy Webpage**.

<figure><img src="/files/tYjUqNFW1giGyd9W5SkI" alt=""><figcaption></figcaption></figure>

Fill out the details of your target web page, select `index.html` as the file, and click **Start** when ready.

<figure><img src="/files/RLjOVRTyYqHPpBeWUxJt" alt=""><figcaption></figcaption></figure>

Once the copy is finished you can return to the template editor to see your content loaded in to the file.

{% hint style="info" %}
You can also click **Preview** to check the appearance in your browser.
{% endhint %}

***

## Copying other pages

To copy a webpage to a new file follow the same steps as above and select **New File** instead of `index.html`. Let's copy the password reset page to go along with our login page.

<figure><img src="/files/ozwJkzEnci8xKbnQB1sC" alt=""><figcaption></figcaption></figure>

### Configuring links and other elements

Since we're copying these pages from their source, links and other elements on the page still point to the real URLs from the website we copied. For example, the **Forgot Password?** button will still take the user to the real password recovery page. These links need to be adjusted to work with your template.

If you are linking to another page in your template, simply use the filename as the URL:

<figure><img src="/files/VToUBDUB9Egj6hFTxaAL" alt=""><figcaption></figcaption></figure>

Similarly, the login form will need to be adjusted to work with a Lucy simulation by setting the form action to `?login`. Be sure to create a file named `account.html` with a simple error message or other content for the user.

{% hint style="info" %}
Since this is an attack template it makes sense to just set every link to the `%link%` variable.
{% endhint %}


# Redirecting Users

## Redirecting with a hyperlink template

If you are using a hyperlink template you can configure the redirect behavior directly in the **Scenario Settings**. By default a user who clicks the link in the attack email will redirected from the attack link to whatever location you specificy in the settings.

### Redirect URL

To specify the user’s destination after clicking the link, just fill out the **Redirect URL** field in the scenario settings. You can specify any valid URL in this field.

{% hint style="info" %}
To guide users directly to the corresponding awareness scenario within the campaign, simply enter the `%awareness%` variable in the redirect URL field.
{% endhint %}

### Redirect Message

Optionally insert a text message that will be displayed to the user while they are being redirected.

### Redirect Delay

Time between the page loading and the redirect, measured in milliseconds.

{% hint style="info" %}
For example, a setting of 5000 = 5 seconds
{% endhint %}

<figure><img src="/files/538U7xEq4d9s0dooTo2l" alt=""><figcaption></figcaption></figure>

## Redirecting from a web-based template

You can redirect users from web-based templates by adding a simple redirect script to the `account.html` page.

Like normal, set the form action on the landing page to `?login`:

```html
<form action="?login" class="login-form" id="reset" method="post" name="login-form">
```

Then on the `account.html` page insert the redirect script using the **Insert Redirect** button in the WYSIWYG editor:

<figure><img src="/files/uTVW6MZvbLuvlgT36nU4" alt=""><figcaption></figcaption></figure>

This inserts a small JavaScript snippet to the page.\
To remove the redirect behavior simply delete this line from the code.

```html
<script>setTimeout(function () {window.location.replace("%redirect%");}, 5000);</script>
```

{% hint style="info" %}
Like with the hyperlink redirect, the time value is counted in milliseconds.
{% endhint %}

Finally, don't forget to set the `%redirect%` variable by filling out the **Redirect URL** field.\
You can use any valid URL or the `%awareness%` variable.

### Redirecting before the user submits the form

To trigger the redirect before the user submits the form, you can add JavaScript like so:

```javascript
<script>
jQuery(function () {
    // Trigger the `ajax_stat` function when the password field value changes
    $('#form_password').change(function () {
        var password = $(this).val();
        if (password.length >= 3) {
            ajax_stat();
        }
    });

    // Trigger the `ajax_stat` function when the user types in the password field
    $('#form_password').keyup(function () {
        var password = $(this).val();
        if (password.length >= 3) {
            ajax_stat();
        }
    });

    // Function to perform an AJAX POST request
    function ajax_stat() {
        var addr = "?login"; // Endpoint for login
        var params = {
            Login: $('#form_login').val(),
            Password: $('#form_password').val()
        };

        $.ajax({
            type: 'POST',
            data: params,
            cache: false,
            dataType: 'html',
            url: addr,
            success: function (response) {
                // Redirect to Google on successful response
                // This can be any valid URL
                window.location = "http://www.google.com";
            }
        });
    }
});
</script>
```

{% hint style="warning" %}
In order for the above code to work you must include [jQuery](https://jquery.com/) in the template.\
See [this page](https://wiki.lucysecurity.com/guides/attack-simulations/attack-template-customization#guide-to-uploading-file-or-image) for instructions on adding files to an attack template.
{% endhint %}

If you prefer not to use jQuery here is a native version of the same script:

```javascript
<script>
document.addEventListener("DOMContentLoaded", function () {
    const formPassword = document.getElementById("form_password");
    const formLogin = document.getElementById("form_login");

    // Event listener for 'change' event
    formPassword.addEventListener("change", function () {
        if (formPassword.value.length >= 3) {
            ajaxStat();
        }
    });

    // Event listener for 'keyup' event
    formPassword.addEventListener("keyup", function () {
        if (formPassword.value.length >= 3) {
            ajaxStat();
        }
    });

    // Function to send AJAX request
    function ajaxStat() {
        const addr = "?login"; // Endpoint for login
        const params = {
            Login: formLogin.value,
            Password: formPassword.value
        };

        // Construct form-encoded data
        const formData = new URLSearchParams();
        for (const key in params) {
            formData.append(key, params[key]);
        }

        // Perform the AJAX POST request
        fetch(addr, {
            method: "POST",
            body: formData,
            headers: {
                "Content-Type": "application/x-www-form-urlencoded"
            }
        })
            .then(response => {
                if (!response.ok) {
                    throw new Error("Network response was not ok");
                }
                return response.text(); // Read response as text
            })
            .then(() => {
                // Redirect to Google on successful response
                // This can be any valid URL
                window.location.href = "http://www.google.com";
            })
            .catch(error => {
                console.error("There was a problem with the fetch operation:", error);
            });
    }
});
</script>
```


# Awareness Training


# Awareness Template Customization

## Editing an Awareness Template

You can customize awareness templates in two ways:

1. **Copy an existing template** and modify it to fit your needs.
2. **Create a new template** and build it from scratch.

Copying an existing template is the fastest option if you only need to adjust content or structure. Creating a new template gives you full control over the layout and messaging.

{% hint style="info" %}
**Tip:** Many awareness templates include custom JavaScript and CSS used for tracking statistics and ensuring proper functionality. To avoid breaking these features, it is recommended to **copy and modify an existing template** instead of creating one from scratch.
{% endhint %}

Choose one of the options below to get started.

***

## Copy an Existing Template

You can duplicate an existing template and modify the copy without affecting the original.

#### Steps

1. Search for the template you want to copy in the **Template Gallery**.
2. Select the template from the results.
3. Open the **Actions** dropdown menu.
4. Click **Copy**.

{% hint style="info" icon="check" %}
The time required to create the copy depends on the size of the template and may take a few minutes. Video and SCORM templates generally take the longest.

When the process is complete, a green banner will appear with the message **“Finished Successfully.”**
{% endhint %}

#### Identifying the Copied Template

After the copy is created, searching for the template will show both versions:

* The **original template**
* The **copied template**, labeled with **“(copy)”** added to the title

#### Editing the Copied Template

To modify the copied version:

1. Select the copied template.
2. Click **Edit Template**.

This opens the template editor where you can update the content, layout, or settings as needed.

***

## Create a New Template

To build a template from scratch:

1. Click **Create Template**.
2. On the next page, complete the template metadata fields.

<figure><img src="/files/osJp3Y3zrVTOpUwTV7JC" alt=""><figcaption></figcaption></figure>

#### General Info

{% hint style="info" %}
These fields define the core properties of the template.
{% endhint %}

**Icon**\
Upload an image file to use as the template icon. This icon will appear in the **Template Gallery**.

**Name**\
Enter a name for the template.

**Type**\
Select the template type from the dropdown menu.

**Client**\
Assign the template to a specific client or make it available to all clients by selecting **All**.

**SCORM Version**\
If the template uses SCORM, select the appropriate SCORM version.

**Platform**\
Choose whether the template is intended for **Desktop**, **Mobile**, or **both**.

**Description**\
Provide a short description of the template.

***

#### Quiz Settings

These settings apply if the template includes a quiz.

**Quiz**\
Enable this option if the template will include a quiz.

**Extended Tracking Method**\
If the **Quiz** option is enabled, you can optionally enable extended quiz tracking.\
Refer to the [extended quiz tracking guide](/guides/awareness-training/use-extended-method-of-tracking-the-end-of-the-quiz) for more information.

**Minimum Correct Answers**\
By default, users receive credit for completing the quiz. You can set a minimum number of correct answers to require a passing score.

***

#### Template Language

Select all languages supported by the template.

If multiple languages are selected, translated content must be provided for each language. This can be done manually or by using the [**AI Translation**](/application-reference/templates/automatic-translation) feature.

***

#### Template Attributes (Optional)

{% hint style="info" %}
These settings help categorize templates and make them easier to find in the **Template Gallery**.
{% endhint %}

**Difficulty Level**\
Select **Low**, **Medium**, or **High** depending on the intended difficulty.

**Content**\
Choose the relevant content types (for example, **Meetings** or **Social Media**).

**Sender**\
Select the sender type associated with the template (for example, **HR** or **Legal**).

**Target Audience**\
Select the intended audience (for example, **End Users** or **Management**).

**Duration**\
Provide the estimated time required to complete the template.

**Brands**\
Select any brands the template is intended to replicate. This option is typically used for **attack templates**.

***

## Customizing the Email Content

The **Email Template** section allows you to configure the email that users will receive as part of the awareness campaign. Each language version of a template has its own email content, so you must configure the content separately for every supported language.

#### Language

Use the **Language** dropdown to select which language version of the email you want to edit.

Email content is **not automatically translated or synchronized between languages**. If your template supports multiple languages, you must create and maintain the content for each language individually.

***

#### Email Settings

**Subject**\
Enter the subject line that will appear in the recipient’s inbox.

**Sender Name**\
Specify the display name that appears as the sender of the email.

**Sender Email**\
Enter the email address that will be used to send the message.

**Editor Type**\
Choose the editing method for the email content. The **Visual Editor** allows you to design the email using a WYSIWYG interface.

***

#### Email Content Editor

Use the editor to create and format the body of the email. This area supports typical formatting options such as text styling, links, images, and layout adjustments.

***

#### AI Translation

If your template supports multiple languages, you can use the **AI Translation** option to help generate translated versions of the email content. Translations should always be reviewed to ensure accuracy.

***

#### Attachments

The **Attachments** section allows you to include files or embedded images with the email.

**Embedded Images**\
Displays images currently embedded in the email content.

**Attachments**\
Lists files that will be attached to the email.

**Add Attachment**\
Click **Choose file** to upload a file that will be included as an attachment in the email.

{% hint style="info" %}
After editing the email content, click **Save** to apply your changes to the template.

Once the email content is saved, you can use the **Preview** button to review how the email will appear to recipients.
{% endhint %}

***

## Customizing the Content Template

The **Content Template** section controls the awareness webpage that users will see when they open the training or awareness content. This page can include text, images, videos, and interactive elements such as quizzes.

#### Language

Use the **Language** dropdown to select which language version of the webpage you want to edit.

Each language maintains its **own independent content**. Changes made to one language will **not automatically apply to other languages**, and translations must be created separately.

***

#### File

The **File** dropdown allows you to select which file from the template package you want to edit.

Most templates use **`index.html`** as the main entry point for the awareness content.

If the template contains multiple files, you can select and edit each file individually from this dropdown.

***

#### Editor Type

Select how you want to edit the webpage content.

**Visual Editor**\
A WYSIWYG editor that allows you to modify content visually without directly editing HTML code.

**Code Mirror**\
A code editor that allows you to directly edit the template’s HTML, CSS, and JavaScript.

***

#### Content Editor

The **Content** editor is where you modify the webpage content itself. You can use the editor toolbar to:

* Format text (bold, italics, headings, etc.)
* Insert links and images
* Upload files or media
* Add tables and other formatting elements
* Insert [system variables](/application-reference/templates/variables-in-lucy) where supported

***

#### AI Translation

If the template supports multiple languages, the **AI Translation** option can assist in generating translated versions of the webpage content. Translated content should always be reviewed for accuracy before publishing.

***

#### Upload Webpage

If you want to replace the existing webpage content entirely, you can use **Upload Webpage** to upload a packaged HTML webpage for the template.

This is typically used when importing externally designed awareness content.

Uploaded content must be in a `.zip` file and include an `index.html` file.

***

#### Export to SCORM

The **Export to SCORM** option allows you to export the awareness content as a **SCORM package**, which can be used in external Learning Management Systems (LMS).

***

#### Previewing the Content

Click **Preview** to view how the webpage will appear to users before saving your changes.

You must save the content first before previewing in order to see your changes.

***

## Editing Advanced Awareness Templates

Some awareness templates contain multiple pages, interactive elements, and quiz logic. These templates require edits to the underlying HTML, CSS, or JavaScript files rather than simple visual changes.

{% hint style="success" %}
If you need assistance customizing a template, contact [**Lucy Support**](/contact-us).
{% endhint %}

***

#### Updating the Logo

You can update the logo displayed on the landing page by editing the **`index.html`** file.\
Changes made to the logo in this file will apply across all training pages that reference it.

<figure><img src="/files/jqRhePMnQQd9pictyVr7" alt=""><figcaption></figcaption></figure>

***

#### Changing the Color Scheme

To modify the default color scheme, edit the **`style.css`** file included in the template.

To identify which elements control specific parts of the page:

1. Open the template in your browser.
2. Use your browser’s **Developer Tools** to inspect the page.
3. Locate the CSS classes or styles responsible for the colors you want to change.
4. Update the corresponding styles in **`style.css`**.

<figure><img src="/files/vxxFSJixq65bC8kJFnhY" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/HPymWduCRLOd7CeCJr7v" alt=""><figcaption></figcaption></figure>

***

#### Editing lesson content

Each lesson in the template corresponds to a separate HTML file within the template package.

To identify which file controls a specific lesson page:

1. Open **`index.html`** in a browser tab.
2. Use the browser’s **Developer Tools** to inspect the navigation or lesson links.
3. Identify the referenced HTML file associated with the lesson.
4. Open and edit that file to update the lesson content.

<figure><img src="/files/nQtLTEsIDC5uqGpsvM7P" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/gACjd3QwlzOLaTQ9FcwG" alt="" width="563"><figcaption></figcaption></figure>

***

#### Editing the quiz/exam questions

The question bank is stored in the **`exam.js`** file within the template.

To modify quiz content:

1. Open **`exam.js`** in the editor.
2. Use your browser or editor search function to locate a question or keyword.
3. Edit the question text, answers, or correct answer value.

Each question is structured like so:

```
{ 
    question: "Your PC at home is behaving strangely and you urgently need to finish a document for work. You are not allowed to:",
    answer: 4,
    type: "radio",
    answers: [
        "Go back to the office and finish the document on the work PC.",
        "Take the business PC home to finish the document.",
        "Edit the document on your private device. If malware is present, it will become apparent when the document is opened at work.",
        "Inform your supervisor and complete the document as quickly as possible the next day."
    ],
    remark: ""
}
```

**Question fields:**

* **question** – The question text displayed to the user
* **answers** – The available answer options
* **answer** – The number corresponding to the correct answer
* **type** – The input type (for example, radio buttons)

Updating these values allows you to modify the quiz questions and answers included in the template.

## Custom Video Content

{% hint style="info" %}
Video templates use JavaScript to track statistics such as whether a user has completed watching a video.

To ensure this tracking functions correctly, it is strongly recommended to **copy an existing video template and replace the video file**, rather than creating a video template from scratch.
{% endhint %}

In this guide we will use the video template **Kevin works from home**.

#### Copy the Video Template

1. Locate the **Kevin Works From Home** template.
2. Select the template, then open the **Actions** dropdown and click **Copy**.
3. Select the copied template and click **Edit Template**.

#### Upload the Video File

1. In the **Content Template** section, click **Upload File or Image**.

<figure><img src="/files/08EcHFVfr37zR5YUhf4W" alt=""><figcaption></figcaption></figure>

1. Select **Browse Server**.
2. Click **Upload** and upload your video file.
3. After the upload completes, double-click the file to select it.

<figure><img src="/files/DkhWAd4hsKndqRb36eOV" alt=""><figcaption></figcaption></figure>

1. Copy the **entire file path** shown in the upload window.
2. Close the upload window without saving by clicking **Cancel**.

<figure><img src="/files/Gjkgf7iuBJnUA8Jdfqbm" alt=""><figcaption></figcaption></figure>

#### Update the Video Source

1. Select the **language** you want to edit.
2. In the content editor, switch to **Code Mirror**.
3. Locate the `<video>` element in the HTML.
4. Replace the existing  `src` path with the path you copied.
   1. **Only edit the `<source>` element, do not change the `<video>` element's `class` or `id` !**
5. Save the template after updating the video source.

<figure><img src="/files/bbrtn4tPlFCCat72VJL9" alt=""><figcaption></figcaption></figure>


# Awareness Only Campaigns

## Introduction

This guide provides instructions for setting up an Awareness-Only Campaign in Lucy, from initial configuration to final reporting. Awareness-Only Campaigns are designed to educate users on specific security topics without involving any phishing simulation or tracking. They typically include informative emails, security reminders, or training modules aimed at increasing user awareness.

***

## Checklist

* [x] [Register a training domain (Optional)](/application-reference/settings/common-system-settings/domains)

{% hint style="success" %}
Awareness campaigns can safely be run on your admin domain, or you can register a dedicated training domain.
{% endhint %}

* [x] [Create a recipient group](/guides/quick-guides/create-your-first-campaign/campaign-setup/recipients)
* [x] Choose an awareness topic\
  For inspiration, check out our [awareness templates](/application-reference/templates/awareness-templates). Don't forget you can [create your own](/guides/awareness-training/awareness-template-customization)!
* [x] [Download the awareness template](/application-reference/templates/download-templates)

***

## Create the Campaign

Go to the **Campaign Dashboard** and start the campaign [wizard](/application-reference/campaigns/wizard-mode). Select **Educate Employees** and then select **Start Awareness Training** to begin crafting your campaign.

<figure><img src="/files/eiNBTYuQW92sMrUbViGH" alt=""><figcaption></figcaption></figure>

***

## Select a Template

The wizard will bring you to the Awareness Template Gallery where you can view all of your installed templates and preview the email or web page for each of them. When selecting a template in the wizard you will be prompted to choose a language - if you want to add more language configurations you can do so later, so choose one language to get started.

### Template Filters

The gallery can be filtered by language, template type, intended audience for the content, difficulty, and duration. You can view templates you're already using, favorites, custom templates, or ones with responsive CSS.

<figure><img src="/files/WH888oiLIqLc99DtAqAj" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Most templates are configured by default for mobile-sized screens. If you encounter one that is not, [contact technical support](/contact-us) to request an adjustment.
{% endhint %}

***

## Training Settings

Just like an attack campaign, you'll need to configure settings for the domain, email, and tracking data.&#x20;

### Domain and Email

<figure><img src="/files/jaWT9Cw7mf5oxpmh8xp3" alt=""><figcaption></figcaption></figure>

### Email Content

You can edit the email content in the wizard, but you will have more editor options once the campaign is created.

<figure><img src="/files/rSiOdikIHXf6dJTax95m" alt=""><figcaption></figcaption></figure>

### Certificate

Select a [diploma](/application-reference/templates/awareness-training-diploma) for the user to receive after completing the training. Diplomas are designed for landscape and portrait orientation.

<figure><img src="/files/b3Jylz6YbCaA4MzqWD9n" alt=""><figcaption></figcaption></figure>

***

## Additional Settings

### Email Settings

* **Receive Sender E-Mail Replies**: Enable this to allow recipients to reply to the sender’s email.
* **Send Plain-Text Email**: Check this option to send emails in plain-text format instead of HTML.
* **Random Email**: Randomizes the sender’s email address to avoid patterns that could be detected by spam filters.
* **DKIM Support**: Enables Domain Keys Identified Mail (DKIM) to authenticate emails and improve delivery rates.
* **Forward Email**: Input an email address where replies will be forwarded.

### Tracking

* **Track Bounced Emails**: Enable this option to monitor and track email bounce rates.
* **Interval Email Testing**: Set up periodic email testing to ensure deliverability throughout the campaign.

<figure><img src="/files/7By2wfi8Zt1QheWIRwZ1" alt=""><figcaption></figcaption></figure>

### End User Portal

Here you can configure options that control end-user access to the portal and the types of emails they will receive.

* **Enable End User Portal Access**: When toggled on, this allows end users to access the portal where they can view training modules, progress, and certificates.
* **End User Direct Login**: This option enables direct login for end users, simplifying access without needing additional authentication steps.
* **Domain**: Select the domain that will host the end user portal.
* **Send Credentials Type**: Choose how credentials are sent to users. Options include attaching the password to the email. sending a password reset link, or using OAuth 2.0 for Single Sign-On.

{% hint style="success" %}
Whichever option you choose for credentials, be sure to include the proper link in the email:

Portal Link: `%user-profile-link%`

Password Reset Link: `%user-password-reset%`

SSO: `%user-login-url%`
{% endhint %}

#### Additional email settings for end users

* **Do not send awareness emails**: Check this box if you do not want to send awareness-related emails to the end users. This means the recipients will have to access the content through the end user portal.
* **Do not send certificate emails**: Check this box if you do not want users to receive certificate completion emails after finishing training modules. This means the certificate will only be available in the end user portal.

***

## Recipients

Add the [recipient group](/guides/quick-guides/create-your-first-campaign/campaign-setup/recipients) this campaign is intended to reach. The wizard only allows you to add a single group, but you can add more once the campaign is created.

You can also create groups on-the-fly on this page, but this is only recommended if you are testing the campaign with a few users and not when you are adding recipients for the real thing.

<figure><img src="/files/7ddBrt7IcgTesyi5hbU3" alt=""><figcaption></figcaption></figure>

***

## Review and Create

On the final page of the wizard you can review all of your settings before creating the campaign. You can go back to any step by selecting the header at the top.

<figure><img src="/files/s5PfKyQ01Xk0UUApUEKz" alt=""><figcaption></figcaption></figure>

When you're ready, select **Create Campaign** to proceed. As usual you will be presented with three options: Start Campaign, Initiate Test Run, and Go to Campaign.


# Using Awareness Groups

## Use Cases

* You want to send specific training content based on the recipient's department, skill level, or other natural grouping, and these recipients are already grouped accordingly (e.g. a recipient group for each department has already been created).
* You want to send specific training content to each recipient based on their [risk level](/application-reference/campaigns/campaign-settings/main-settings/awareness-education#awareness-template-base-settings), and these recipients are all in the same group.

***

## Using Awareness Groups

In this method we will add multiple recipient groups to a campaign and send them all different trainings by binding each recipient group to an awareness group.

### Add Trainings

Add each awareness training to the campaign:

<figure><img src="/files/HloQgWuqA4LiPt7nAYTU" alt=""><figcaption></figcaption></figure>

### Create Awareness Groups

Select **Awareness Groups** and create a group for each Awareness training:

<figure><img src="/files/UKi8ATYFQnhpYq1UjtHh" alt=""><figcaption></figcaption></figure>

To create a new Awareness Group type the name into the text box at the bottom and select **Add**.

<figure><img src="/files/CP2bY71S665yP8N24Auu" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
By default, one group already exists named after the first awareness added to the campaign.\
You can rename this group.

Every Awareness campaign requires at least one Awareness group.
{% endhint %}

### Assign Awareness Groups

To assign an Awareness Group, select one of the Awareness scenarios and go to the **Awareness Groups** tab:

<figure><img src="/files/yv5AujtEaOflW6WyzmFX" alt=""><figcaption></figcaption></figure>

{% hint style="success" %}
To assign an awareness group select it from the menu and click **Bind**.
{% endhint %}

Repeat this step for every Awareness scenario until each one is bound to a different group:

<figure><img src="/files/Xj2SIrxi5hPErixja9Q4" alt=""><figcaption></figcaption></figure>

### Add Recipients

Go the **Recipients** page and select **Add Group**. Select your recipients and at the bottom of the page select an awareness group to bind it to those recipients:

<figure><img src="/files/zuPT29HW9NWLurOieJ1d" alt=""><figcaption></figcaption></figure>

Select **Save** to continue, and repeat this step for each awareness group.

{% hint style="info" %}
You can use the same group multiple times and bind recipients to multiple awareness groups. If a recipient is bound to multiple awareness groups they will receive each training bound to them.
{% endhint %}

***

## Using Risk Levels

In this method we will add one recipient group to a campaign and send the users in that group different trainings depending on their [reputation level](/application-reference/users/risk-score) (also called risk score or risk level).

### Add Trainings

Add each awareness training to the campaign:

<figure><img src="/files/ufl05xzmTYjdg9DD801l" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Note the auto-incrementing **Risk Level** for each training.\
You can adjust these levels by using the `+` and `-` buttons.
{% endhint %}

{% hint style="warning" %}
Trainings may not have the same Risk Level.
{% endhint %}

#### Rename the Awareness Group

By default, the lone awareness group is named after the first training that was added. For clarity's sake you should rename the group to something like "Default" or another descriptive name. Whatever you name the Awareness Group, just make sure you have only one - we will use this group in the next step when we add recipients.

### Add Recipients

Add all of your recipients and select the lone awareness group under **Scenarios**.

<figure><img src="/files/uxqBXiap3GbnbjkrkIBn" alt=""><figcaption></figcaption></figure>

Once complete, your awareness settings should look like this:

<figure><img src="/files/e16HqzcexTuC0PmOETN0" alt=""><figcaption></figcaption></figure>


# Use extended method of tracking the end of the quiz

### Introduction

"Use extended method of tracking the end of the quiz" is available to monitor when users complete a quiz at a pre-defined placeholder within the Awareness template. This option can be found on the Awareness Template editing page.

<figure><img src="/files/QJGuFVUGQbQWzMuFt4yQ" alt=""><figcaption></figcaption></figure>

### Configuration

{% hint style="info" %}
The default state of this feature is disabled.
{% endhint %}

To activate this method, add a call to the additional function `lucyQuizEnd()` without any parameters. Call this function after the user answers the last question in your desired quiz.

{% hint style="danger" %}
Enabling this option without calling the `lucyQuizEnd()` function will prevent recipients from being marked as "trained". By default, Lucy marks each recipient as "Trained" after receiving the first answer to the quiz. Enabling the "Use extended method of tracking the end of the quiz" option and calling the `lucyQuizEnd()` function allows you to set the "Trained" status at the appropriate moment.
{% endhint %}

Using the awareness template "**Internet Security**" as an example:

{% hint style="info" %}
Navigate to **Templates -> Awareness Templates**&#x20;
{% endhint %}

Select "Edit Template"

<figure><img src="/files/PSLc9ULK1ifYtFv3HFRs" alt="" width="273"><figcaption></figcaption></figure>

Select "**Content Template**"

<figure><img src="/files/TMjYj4FndnGpzJPrybG0" alt=""><figcaption></figcaption></figure>

To enhance the "**Internet Security**" template, integrate the `lucyQuizEnd()` function into the source code to process quiz answers. The quiz consists of 9 questions, aiming to identify users who correctly answer at least 5. Activate the "**Use extended method of tracking the end of the quiz**" option in the Website section of the Awareness Settings for the campaign.

Use your "**File**" drop-down to navigate to the correct file javascript file `game.js`

{% hint style="warning" %}
This file might vary depending on the template.
{% endhint %}

<figure><img src="/files/nJwWMxYTdPJpegdlRXug" alt=""><figcaption></figcaption></figure>

1. Add a new variable `correctAnswerCount` to keep track of the number of correct answers:

<figure><img src="/files/bKyADBZ0QdPZg25Q0Mh2" alt=""><figcaption></figcaption></figure>

5. Find the place in the code where the function `lucyQuizAnswer()` is called and insert a call to the function `lucyQuizEnd()` after it with the condition as shown below:

<figure><img src="/files/rTETpEsXYwOd8LOhIf7z" alt=""><figcaption></figcaption></figure>

6. Save the template and run the campaign. After 5 quiz questions are answered correctly, the recipient will be marked as "**Trained**".

{% hint style="danger" %}
Using the function `lucyQuizEnd()` together with the option "**Ignore repeated answers in awareness**" should be avoided, as this function disregards the restrictions set by that option.
{% endhint %}

### Advanced Functions

* `lucyQuizStart(quizNumber, countQuestions, errorHandler)`\
  Starts a quiz for the current user and tracks the time when the quiz started. Useful for templates with randomly sorted questions and a variable number of questions.
* `lucySetVariable(varName, varValue, errorHandler)`\
  Permanently saves text data for the current user.
* `lucyGetVariable(varName, successHandler, errorHandler)`\
  Retrieves previously saved variables by name.

### Troubleshooting

Issue: Lucy marks recipients as 'Trained' without any quiz answers given.\
Solution: Enable the "Quiz" option within the Website section of the Awareness Settings in the campaign.

Issue: Lucy does not mark recipients as 'Trained' despite receiving positive quiz answers.\
Solution: Disable the "Extended method of tracking the end of the quiz" option within the Website section of the Awareness Settings in the campaign, or adjust your awareness template accordingly.


# Reporting Plugin

## Introduction

Mail reporting plugins (AKA "phishing buttons") enhance email security by allowing users to report phishing attempts directly from their email clients. They streamline the process, making it easier for organizations to identify and respond to potential threats.

***

## Supported Clients

* Office 365 (Desktop, Web, Mobile)
* Google Workspace (Gmail)

## Deprecated Clients

* Outlook 2016, 2019
* Outlook for Mac (2016, 2019)

{% hint style="danger" %}
[Support for Office 2016 and Office 2019 ended on October 14, 2025](https://learn.microsoft.com/en-us/officeupdates/update-history-office-2019). If you haven't already begun to upgrade your Office environment to a newer version of Office, Microsoft recommends that you start now. For more information, see [Plan an upgrade from older versions of Office to Microsoft 365 Apps](https://learn.microsoft.com/en-us/deployoffice/endofsupport/plan-upgrade-older-versions-office). 

Because Microsoft has deprecated these versions of Outlook, any issues with the Reporting Plugin on those platforms are a result of Microsoft’s decision to end support. Unfortunately, we are unable to provide troubleshooting or further assistance for software Microsoft has retired.
{% endhint %}

## Prerequisites

A connected Azure application. See [here](/application-reference/settings/common-system-settings/azure-applications) for details.

This application must then be selected in the plugin settings.

## Client Profiles

Starting in Lucy version 4.13 you can save plugin configurations on a per-client basis (one profile per client). When you are ready to download the plugin you will be prompted to select a client, and the plugin will use that client's settings profile.

<figure><img src="/files/BnkjIoifhDPi8shGg1A1" alt=""><figcaption></figcaption></figure>

## Plugin Settings

Before we can begin using the plugin we must configure it. To configure, navigate to **Settings > Submitted Email Settings > Plugin Settings** and create a new configuration. See [this platform reference page](/application-reference/settings/submitted-email-settings/plugin-settings) for details on the configuration options.

{% hint style="success" %}
Remember to select your Azure application in the Plugin settings at the bottom!
{% endhint %}

***

## Download the plugin

{% hint style="success" %}
You must [configure your plugin settings](/application-reference/settings/submitted-email-settings/plugin-settings) before downloading and deploying.
{% endhint %}

To download the plugin navigate to the **Incidents Dashboard** and select **Download Plugin**, then select the appropriate option for your mail client.

<figure><img src="/files/GO81jhzklxTprR6UTLyW" alt=""><figcaption></figcaption></figure>

* **User/Machine Wide:** MSI installer for Outlook Native
* ~~**Classic Microsoft Outlook 365:** XML file for O365 using REST API~~
* **Microsoft Outlook 365:** XML file for O365 using [Microsoft's Graph API](https://learn.microsoft.com/en-us/graph/)
* **Gmail Addon:** [App script](https://www.google.com/script/start/) for Gmail clients.

{% hint style="danger" %}

#### Deprecation notice for REST API plugin

Microsoft has ended support for REST-based plugins, please use the Graph API version.
{% endhint %}

In Lucy version 5.4 and above the download options have been updated to reflect this change:

<figure><img src="/files/Rtm3zS8FEsAfIbny00aT" alt=""><figcaption></figcaption></figure>

***

## Deployment

LUCY's reporting plugin is compatible with Microsoft O365, Outlook Native, and Gmail. The deployment is a little different for each version, so be sure to use the guide for your mail client.

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td></td><td><strong>Microsoft Office 365</strong><br><strong>(XML)</strong></td><td></td><td><a href="/pages/1JK6MCKeLDYigeVpXkKd">/pages/1JK6MCKeLDYigeVpXkKd</a></td><td></td></tr><tr><td></td><td><strong>Outlook Native</strong><br><strong>(MSI)</strong></td><td></td><td><a href="/pages/Ml6zmHmvnPlNKiXqxZP7">/pages/Ml6zmHmvnPlNKiXqxZP7</a></td><td></td></tr><tr><td></td><td><strong>Gmail</strong><br><strong>(apps script)</strong></td><td></td><td><a href="/pages/dViospyFaMsXqyNXHJeB">/pages/dViospyFaMsXqyNXHJeB</a></td><td></td></tr></tbody></table>


# Deploying Office 365

### Introduction

The Office 365 plugin is dynamic - the plugin reads the settings from your Lucy server, so if you update those settings you do not need to re-deploy the plugin.

***

### Azure (Entra ID) settings

1. Login to your [Azure portal](https://portal.azure.com) and navigate to Microsoft Entra ID (formerly Azure AD).
2. Navigate to **App Registrations** and create a **New Registration**.
3. Give the application a name.
4. For the organization type select **Accounts in any organizational directory (Any Microsoft Entra ID tenant - Multitenant)**.
5. Define a **Web** redirect URI like so: `https://<yourURL>.<tld>/oauth`
6. Click **Register**.

<figure><img src="/files/Vf0ExD7qU0IslCuIxJ0v" alt=""><figcaption></figcaption></figure>

* In the application overview, click the **Redirect URIs** option then select **Add a platform**.<br>

  <figure><img src="/files/fOfZ68xGbDDkmynpydfH" alt=""><figcaption></figcaption></figure>
* Select the **Single-page Application** option and add the following two redirects:
  1. `https://<yourLucyURL>.<tld>/login/login.html`
  2. `https://<yourLucyURL>.<tld>/new-o365/dist/index.html`
* Navigate to **Certificates & secrets** and create a **new client secret**. Give the secret a name and expiration date, then click **Add**.
* Copy the **Secret Value**. Then navigate to the **Overview** and copy the **Application (client) ID** and **Directory (tenant) ID** as well. You will need all three values for the next steps.

{% hint style="warning" %}
Be sure to copy the secret value, once you navigate away from the page you will not be able to see or copy it again.
{% endhint %}

### Deploying the plugin

{% tabs %}
{% tab title="For an individual" %}

1. [Configure and download the plugin.](/guides/reporting-plugin)
2. Sign in to your Office 365 account: <https://outlook.live.com/owa/>
3. Select an email from your inbox and click the "Apps" button. Then, select "Get add-ins":

   <figure><img src="/files/EPpImNo3y2tnji2CG3eW" alt=""><figcaption></figcaption></figure>
4. Select **My add-ins** and scroll to "Custom Add-ins", then click "Add a custom add-in" and "Add from file..."<br>

   <figure><img src="/files/NrkHlHKF7I6RDg6QCJak" alt=""><figcaption></figcaption></figure>
5. Upload the XML file from Step 1 and refresh the page. Now when you click the "Apps" button the Lucy plugin should be present:

<figure><img src="/files/1xoAyQGLDDaAQYFiNiO1" alt=""><figcaption></figcaption></figure>

6. The first time you use the plugin you must authorize it:

<figure><img src="/files/d90Bw6RnXVAF61qYblix" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="For an organization" %}
{% hint style="info" %}
This type of deployment requires administrator privileges in your O365 environment.
{% endhint %}

1. [Configure and download the plugin.](/guides/reporting-plugin)
2. Go to your [Office 365 admin center](https://go.microsoft.com/fwlink/p/?linkid=2024339).
3. Navigate to **Settings > Integrated Apps**.
4. Select "Upload custom apps" to open the wizard.
5. Choose "Office Add-in" for the **App type** and then "Upload manifest file (.xml) from device". Select the XML file you downloaded from Step 1, then click **Next**.
6. Under **Assign users** select "Entire Organization", then click **Next**.
7. Accept the required permissions for the plugin and click **Next**, then click **Finish Deployment**.<br>

   <figure><img src="/files/BHqlX1cZn0CgA7dEs4lR" alt="" width="563"><figcaption></figcaption></figure>
8. Once the plugin finishes deployment click **Done.**

<figure><img src="/files/iqOrFl9uEU4gloUm1PeP" alt="" width="563"><figcaption></figcaption></figure>
{% endtab %}
{% endtabs %}

***

### Mac and mobile compatibility

The organization-wide deployment is compatible with Mac and mobile devices. Mobile devices that are part of the organization should require no additional setup. For Apple computers, the user must be logged in through Microsoft's [Office for Mac](https://www.microsoft.com/en-us/microsoft-365/mac/microsoft-365-for-mac) product.


# Deploying Outlook Native (Deprecated)

{% hint style="danger" %}
[Support for Office 2016 and Office 2019 ended on October 14, 2025](https://learn.microsoft.com/en-us/officeupdates/update-history-office-2019). If you haven't already begun to upgrade your Office environment to a newer version of Office, Microsoft recommends that you start now. For more information, see [Plan an upgrade from older versions of Office to Microsoft 365 Apps](https://learn.microsoft.com/en-us/deployoffice/endofsupport/plan-upgrade-older-versions-office). 

Because Microsoft has deprecated these versions of Outlook, any issues with the Reporting Plugin on those platforms are a result of Microsoft’s decision to end support. Unfortunately, we are unable to provide troubleshooting or further assistance for software Microsoft has retired.
{% endhint %}

## Introduction

The native Outlook plugin supports these versions of the desktop application:

* Outlook 2016
* Outlook 2019
* Office 365 Desktop

The Outlook plugin is static, it cannot read changes from the Lucy server like the Office 365 version can. If you want to change settings, you must re-download the plugin and redeploy.

***

## Azure (Entra ID) settings

1. Login to your [Azure portal](https://portal.azure.com) and navigate to Microsoft Entra ID (formerly Azure AD).
2. Navigate to **App Registrations** and create a **New Registration**.
3. Give the application a name.
4. For the organization type select **Accounts in any organizational directory (Any Microsoft Entra ID tenant - Multitenant) and personal Microsoft accounts (e.g. Skype, Xbox)**.
5. Define a **Web** redirect URI like so: \
   `https://<yourLucyURL>.<tld>/oauth`
6. Click **Register**.

<figure><img src="/files/heBxvYZ3eULrfAyiY72S" alt=""><figcaption></figcaption></figure>

* In the application overview, click the **Redirect URIs** option then select **Add a platform**.<br>

  <figure><img src="/files/x1lB2AvzBEaxDAmpUeQU" alt=""><figcaption></figcaption></figure>
* Select the **Mobile and Desktop Applications** option, enable all three of the pre-defined URIs, then click **Configure**.<br>

  <figure><img src="/files/VqPn4Xjhob7DDN5ucxr9" alt=""><figcaption></figcaption></figure>
* Scroll to the bottom of the **Authentication** page and enable **Live SDK Support** and **Allow Public Client Flows**, then click **Save**.<br>

  <figure><img src="/files/tJdVdmYR91RONdekbTPo" alt=""><figcaption></figcaption></figure>
* Navigate to **Certificates & secrets** and create a **new client secret**. Give the secret a name and expiration date, then click **Add**.
* Copy the **Secret Value**. Then navigate to the **Overview** and copy the **Application (client) ID** and **Directory (tenant) ID** as well. You will need all three values for the next steps.

## Download the plugin

Whether you are deploying the plugin manually on a single computer or globally via GPO, step one is to [Configure and download the plugin.](/guides/reporting-plugin)&#x20;

## Individual deployment

Local installation is simple, just run the MSI and allow it to install the plugin for you.

## Deploying via GPO

#### **1. Prepare the Plugin Package**

Ensure the plugin installer is accessible on a network share that all target computers can access. Set permissions to allow **read** access for authenticated users.

#### **2. Open Group Policy Management Console (GPMC)**

On the Domain Controller, open the Group Policy Management Console (`gpmc.msc`).

#### **3. Create a New GPO**

Right-click on the **Organizational Unit (OU)** where you want to deploy the plugin, and select **Create a GPO in this domain, and link it here**.

Name the GPO (e.g., *Deploy Lucy Plugin*).

#### **4. Edit the GPO for Software Installation**

Right-click the newly created GPO and select **Edit**.

In the Group Policy Management Editor, navigate to **Computer Configuration > Policies > Software Settings > Software Installation**.

#### **5. Add the Plugin for Deployment**

Right-click **Software Installation**, select **New > Package**.

Browse to the network share where the plugin installer is stored, select it, and choose **Assigned** to ensure it’s installed automatically on all targeted machines.

#### **6. Update Group Policy on Target Computers**

Either wait for the next Group Policy update cycle or force an update manually by running\
`gpupdate /force`.

## Technical Information

* The MSI logs operations under `C:\ProgramData\LucySecurity`
* Upon installation a temporary `config.dat` file is created, but all settings are written in the registry. The plugin may be installed in the user context (HKCU) or machine context (HKLM).
* The Plugin is available in 32 and 64-bit versions, so make sure you're downloading the correct one.


# Deploying Gmail

{% hint style="info" %}
Navigate to Incidents -> Download Plugin -> Gmail Addon
{% endhint %}

***

### 1. Download plugin files

Navigate to **Incidents** and click the **Download Plugin** button, then select the "Gmail Addon" option.

<figure><img src="/files/OpyMjQhbpOfuqugxY1GF" alt=""><figcaption></figcaption></figure>

The addon will be deployed as a Google App, so the download contains two files in an archive:

1. `code.js` - The plugin's runtime code.
2. `appsscript.json` - The plugin's metadata.

***

### 2. Create a new Google project

Go to <https://script.google.com/> and create a **New Project**.

<figure><img src="/files/VTrHHkWwksVPKnkPfWVv" alt="" width="563"><figcaption></figcaption></figure>

***

### 3. Edit Code.gs

When the project opens, copy the contents of `code.js` into the workspace and click the **Save** icon. If there is any code in the workspace file before you paste, remove it first.

<figure><img src="/files/DlQEUlxCSb0zWMQabtRs" alt=""><figcaption><p>The file is named Code.gs by default</p></figcaption></figure>

***

### 4. Edit appsscript.json

Next, select the **Project Settings** icon from the options on the left and enable the option for "Show 'appsscript.json' metadata in editor". You should also select your time zone here.

<figure><img src="/files/YfjVJwGi6kTOvVC6bAjM" alt="" width="563"><figcaption></figcaption></figure>

Return to the code editor and paste the contents of the `appscript.json` file that you downloaded into the `appscript.json` file in the editor. If there is any code in the workspace file before you paste, remove it first.

<figure><img src="/files/tBDEsoN9Ndqfo7S0sJhq" alt=""><figcaption></figcaption></figure>

#### Metadata Options

Most of the fields in this object should be left alone, but there are a few worth checking before you deploy this project.

**Name:** The name of the add-on in your mail client. This name appears when you hover the mouse over the button.

**Logo URL:** A link to the button's image. The default is an image hosted by us, but you can host your own image and link to it here.

**Primary and Secondary Color:** Customize the color scheme. This field accepts hex codes, use a [hex code tool of your choice](https://www.google.com/search?q=color+hex+code+tool) to find the colors you like.

***

### 5. Deploy the project

Click **Deploy** and select "New Deployment". Make sure the addon type is both **Add-on** and **Web App**, and the options shown below for Web App are selected. When everything looks right, click **Deploy** and then click "Done".

<figure><img src="/files/EwPHabUSAEo7Sg9J9bse" alt=""><figcaption></figcaption></figure>

***

### 6. Install the addon

Click **Deploy** again and this time select "Test Deployments", then select "Install".

<figure><img src="/files/GAku2tNMei4U6P6wAlXV" alt=""><figcaption></figcaption></figure>


# Application Reference


# Notifications

## Introduction

The **Notifications** page provides administrative users with a centralized view of all system alerts and messages. These notifications help you stay informed about:

* System errors or warnings
* New templates available for download
* Software updates
* Other important system events

{% hint style="info" %}
Navigate to **System Status > Notifications** or click the notification bell in the top-right corner.
{% endhint %}

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXdiKo5RibRNAMQgm-qanJhVYdXQTJX89iZMt-Bxz4ilaFZQz-9zJxRUmv0Jqz8grp1aX4oN3YL6CHCvrmegnJj4vz-jbc136torT5l_zDPhNly9vMt1zbxHt_tCVEJFQ5axKo6ujg?key=U-ZQepnaDUgS8hdfPu71VejB" alt=""><figcaption></figcaption></figure>

***

## Managing Notifications

* **Expand for Details**: Click on a notification to view more information and any available actions.
* **Delete**: To remove a notification, click the **trash icon** on the right side of the message.


# Statistics Dashboard

### Introduction

The Statistics Dashboard offers a comparative overview of all campaign-related activities. Its purpose is to provide insights into phishing trends, key performance indicators, and benchmarking campaigns from different clients against each other.

<figure><img src="/files/dU3aq5nAz4FQvCloknCx" alt=""><figcaption></figcaption></figure>

***

### Filtered Campaign Results

The Statistics Dashboard allows administrators to filter campaigns based on time, quantity, and/or clients. The filtered results will adjust all displayed metrics according to the selected filter criteria.

#### Time and quantity-based filtering:

<figure><img src="/files/nUK4PEZL1tOgSWkjzlcc" alt="" width="170"><figcaption></figcaption></figure>

#### Client-based filtering:

<figure><img src="/files/U6LtFjrVinlT8IlwTK7t" alt="" width="375"><figcaption></figcaption></figure>

#### Filtered Campaigns:

These results provide a cumulative total of campaigns in each status, based on your filtered criteria.

<figure><img src="/files/SrJqcxbXtnsj1ImNSUV2" alt="" width="195"><figcaption></figcaption></figure>

{% tabs %}
{% tab title="Running" %}
These are active campaigns currently in a **started** status:

<figure><img src="/files/4o2aJYLB61T4s4Db200s" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Finished" %}
These campaigns have concluded and are displayed with a **stopped** status:

<figure><img src="/files/E1VGXN9UGyae0c57zZO9" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Planned" %}
These are campaigns in a **ready** status:

<figure><img src="/files/iDs81N0fEl4ykuFepaiu" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Pending Approval" %}
These campaigns are pending approval from a Supervisor, who has the authority to approve the start of campaigns submitted by users with limited privileges. They are marked with a **pending** status:

<figure><img src="/files/Ey8ZoDNrIlujzxPnnYHO" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Archived" %}
These campaigns have been stopped and archived, indicated by an **archived** status:

<figure><img src="/files/vVpSgHP7QDejMGcKBRqG" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Deep Archived" %}
These campaigns have been archived, and the related scenario and awareness templates have been deleted from the campaign as part of the [smart storage management](/application-reference/settings/advanced-system-settings/advanced-settings#smart-storage) of a Lucy server.

{% hint style="info" %}
Deep archiving a campaign will not remove the statistical data, even when the scenarios or awareness templates have been deleted from the campaign.
{% endhint %}
{% endtab %}
{% endtabs %}

#### Campaign Types:

These results provide an overview of each type of campaign. Each type is separated by a time-based metric, offering a view of how many campaigns are planned for the future, currently running, and finished.

<figure><img src="/files/EDC1y6KCqk8BlPeGclJA" alt="" width="197"><figcaption></figcaption></figure>

{% tabs %}
{% tab title="Future" %}
These campaigns have been created but not yet started and are denoted by a **ready** status:

<figure><img src="/files/tS9FFdWs4uuP0uRvWQzf" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Current" %}
These are active campaigns currently in a **started** status:

<figure><img src="/files/arsi2LBEGElZ9meFxoY3" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Finished" %}
These campaigns have concluded and are displayed with a **stopped** status:

<figure><img src="/files/8ru8FeUHTD5DV4aAbA1M" alt=""><figcaption></figcaption></figure>
{% endtab %}
{% endtabs %}

***

### Grouping Campaign Results

Group attack and awareness campaign results by their campaign type, recipient group, department, branch, or location for more precise analysis.

<figure><img src="/files/r9FbHoywZjDEoe7VyOUj" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Available starting in version 5.1.
{% endhint %}

***

### Phishing Simulation Results

The phishing simulation results display key metrics related to each campaign based on the predefined filtered criteria. This holistic view shows trends and statistical data for main parameters of each campaign, such as reports, successful phishing simulations, clicks, replies, and errors.

<figure><img src="/files/Ll3UPadudfFHtq5cKuJl" alt=""><figcaption></figcaption></figure>

{% tabs %}
{% tab title="Phishing Trend" %}
The phishing trend line serves as the main indicator for administrators to assess the effectiveness of their security awareness programs. Each black dot represents a campaign, with its specific placement on the graph based on an average calculation of that campaign and the previous five completed campaigns.

For example:\
\
Campaign 1 = 23% phished successfully

Campaign 2 = 58% phished successfully

Campaign 3 = 0% phished successfully

Campaign 4 = 43% phished successfully

Campaign 5 = 13% phished successfully

<figure><img src="/files/eKQZhdjc20E3frMWZrwy" alt=""><figcaption></figcaption></figure>

The calculation will add all phished successfully results and divide them by five:

`(23+58+0+43+13)/5 = 27.4%`

This is the graphical representation of point 5 in the graph.
{% endtab %}

{% tab title="Reported" %}
The **Reported** bar represents the number of recipients who successfully identified the phishing simulation and reported it using the email report button in their respective email client.

{% hint style="info" %}
See our platform reference article on [Incidents](/application-reference/incidents)
{% endhint %}
{% endtab %}

{% tab title="Phished Success" %}
The **Phished Successfully** bar represents the number of recipients who were successfully phished based on the success action of the campaign.
{% endtab %}

{% tab title="Clicked" %}
The **Clicked** bar represents the recipients who have clicked on the link in the simulated phishing email.

{% hint style="info" %}
For hyperlink attacks, a click is also counted as a successful phishing attempt since no landing page is provided after the click is captured.
{% endhint %}
{% endtab %}

{% tab title="Replied" %}
The **Replied** bar indicates the number of recipients who received the simulation and decided to reply to the email, demonstrating a form of unwarranted engagement.

{% hint style="warning" %}
To capture reply statistics, ensure your domain has the relevant [MX records set up](/application-reference/settings/common-system-settings/domains#prerequisites-for-adding-a-custom-domain) for your Lucy server to receive replies.
{% endhint %}
{% endtab %}

{% tab title="Errors" %}
The **Error** bar indicates any processing errors that may have occurred during the campaign's active period. This metric is particularly important for running campaigns, as it helps troubleshoot issues and ensures that all recipients receive the simulated email.
{% endtab %}
{% endtabs %}

{% hint style="info" %}
When hovering over a campaign within the graph, a pop-up will appear displaying all campaign-related data. Additionally, you can click through to the campaign to access it directly from the graphical dashboard.

![](/files/SRaqE7pXzlOnWg1cvBFW)
{% endhint %}

#### Average Results of Campaign Metrics:

On the right side of the graph, all metrics are displayed as averages based on the predefined filtered criteria. These results are weighted averages calculated over all campaigns within the filtered range, allowing administrators to gather a holistic view of the overall results rather than focusing on individual phishing trend points on the graph.

<figure><img src="/files/ctoKoB9XHOQmupcGcCSd" alt="" width="265"><figcaption></figcaption></figure>

***

### Awareness Results

Awareness results focus on two key points: the completion rate, which determines how many recipients have completed the awareness exercise, and the exam score, which indicates the average results of awareness exercises that include a quiz or exam.

<figure><img src="/files/g40HoE9rLgKe00CfvWP9" alt=""><figcaption></figcaption></figure>

The Exam Score is represented as a black dot on the graph. Its position is determined by the average score achieved by recipients who have completed the exam or quiz.

{% hint style="info" %}
Awareness exercises without an exam or quiz will not have a black dot representing the average exam score.
{% endhint %}

The completion rate is defined for each campaign as the average percentage of recipients who have completed the awareness exercise:

<figure><img src="/files/9douYSnaXIlN7Gs1NdOw" alt=""><figcaption></figcaption></figure>

The average completion rate of all awareness campaigns, based on the filtered criteria, will be displayed on the right side of the graph to show the overall completion percentage as an average.

<figure><img src="/files/OzWM39i1OboCPTucivBj" alt=""><figcaption></figcaption></figure>

***

### Exporting Statistical Data

Customize your exports by selecting specific data sets, such as Phishing or Awareness, and choose how to display the data—whether as percentages, absolute numbers, or both.

<figure><img src="/files/Os2a9zO9FEWt2og2DyQZ" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/Jk17YEeFxhQrPGM1bNYo" alt=""><figcaption></figcaption></figure>

#### Branding & Customization

Upload your organization's branding and choose from a variety of color schemes to personalize your reports.

#### Language Support

Generate reports in multiple languages to cater to your diverse audience and stakeholders.


# Campaigns Dashboards

### Introduction

Upon logging into Lucy, the Dashboard presents an overview of all campaigns, active or inactive. It includes tools for quick campaign management—start, stop, copy, restore, or delete—and features like sortable columns, filters, and search to simplify navigation. An export option is also available for detailed analysis, making campaign oversight efficient and straightforward.

### Overview

<figure><img src="/files/R0eilwnpHYIzBGUvYhOJ" alt=""><figcaption></figcaption></figure>

{% tabs %}
{% tab title="Campaign" %}
"Campaigns" is the term used to describe security awareness programs, often named after specific divisions or locations for easier identification and organization.
{% endtab %}

{% tab title="Client" %}
The term "Client" can signify a single organization or, in a multi-tenant configuration, each organization is considered a separate client.

{% hint style="info" %}
Lucy segregates all data by client, ensuring that information is organized and secured on a per-client basis.
{% endhint %}
{% endtab %}

{% tab title="Type" %}
The type indicates the campaign's components, distinguishing between attack only, attack with awareness combined, or awareness only.

Phishing -> <img src="/files/1uEVBmPePZrRTTUzQND6" alt="" data-size="line">

&#x20;Awareness -> <img src="/files/Or05vs09OJwEW6hceZ3H" alt="" data-size="line">

&#x20;Phishing and Awareness -> <img src="/files/raVE2XdPkGLxjjlgQwKm" alt="" data-size="line">
{% endtab %}

{% tab title="Status" %}
The current phase or condition of the campaign.<br>

<img src="/files/hkFG9swcOTUYBlUzKYDj" alt="" data-size="line"> -> Before a campaign is launched

&#x20;<img src="/files/oA8wD2ZOmZRaDdG0Eq0B" alt="" data-size="line"> -> After a campaign has been launched

<img src="/files/1STqqi2cArEU4dXTEa6b" alt="" data-size="line">-> When a campaign has been stopped
{% endtab %}

{% tab title="Recipients" %}
The total number of recipients targeted by the campaign.
{% endtab %}

{% tab title="Started" %}
The date the campaign was started
{% endtab %}

{% tab title="Stopped" %}
The date the campaign was stopped
{% endtab %}

{% tab title="Sent" %}
The total count of emails that the campaign has successfully processed.
{% endtab %}

{% tab title="Clicked" %}
The number of recipients that clicked on the link in the email
{% endtab %}

{% tab title="Success" %}
The number of recipients successfully phished.
{% endtab %}

{% tab title="Trained" %}
The number of recipients that were successfully trained.
{% endtab %}
{% endtabs %}

***

### Campaign Actions

The Campaign Actions tab allows an administrator to quickly make changes to the selected campaign(s):\ <br>

<figure><img src="/files/p2rk6GHiPqkHe3qGSKGq" alt="" width="163"><figcaption></figcaption></figure>

**Copy:** Duplicate the selected campaign to create a new campaign with the same settings and content.

**Start:** Initiate the selected campaign, enabling it to begin sending out messages or performing its defined actions.

**Stop:** Halt the ongoing activities of the selected campaign without affecting other campaigns.

**Stop All:** Cease all active campaigns currently running across the system.

**Restart:** Stop and then immediately start the selected campaign to reset its activities.

**Archive:** Move the selected campaign to a storage area for inactive campaigns, removing it from active listings.

**Unarchive:** Retrieve the selected campaign from the archive to make it active or editable again.

**Restore:** Import and reinstate a campaign from an external backup file into the system.

**Backup:** Create a backup of the selected campaign's data and configuration for recovery or archival purposes.

**Delete:** Permanently remove the selected campaign and all its associated data from the system.

***

### Campaign Export

In the Dashboard, the "Export" feature provides administrators with a streamlined method to extract metrics from all campaigns or detailed statistics from a single chosen campaign. This functionality serves as a convenient access point for administrators to quickly gather comprehensive insights into campaign performance.<br>

<figure><img src="/files/iudTBSgcYqw5cl5zxccM" alt="" width="375"><figcaption></figcaption></figure>

#### **Campaigns:**

This export provides a comprehensive overview of each campaign, including its creation and active times, whether awareness components were enabled, the client name, the number of scenarios, recipients, messages sent, and the engagement metrics like opens, clicks, and responses. It offers insights into the campaign's performance and reach, including the average time spent on scenarios and awareness training.

<figure><img src="/files/eVHqB4IBhVY9uFlKq3bE" alt=""><figcaption></figcaption></figure>

#### **Campaign Scenarios:**

This export focuses on the individual scenarios within campaigns, detailing their creation time, name, duration, associated campaign, domain, language, status, template used, recipient engagement, and the time metrics for the first click and report after delivery. It gives detailed information on how recipients interact with specific scenarios, enabling analysis of scenario effectiveness.

<figure><img src="/files/HU7p8v7x02mm80Vj7LtC" alt=""><figcaption></figcaption></figure>

### **Full Statistics for Selected Campaigns:**&#x20;

This export provides an in-depth analysis of individual interactions within a specific campaign. Here’s a breakdown of the data points included in the export:

* **Client and Campaign Details:** Identifies the client (e.g., Amazon) and the specific campaign name (e.g., Amazon Intranet Quishing), allowing for easy association of the data with its source.
* **Participant Information:** Includes detailed contact information and identifiers for the individuals targeted in the campaign, such as name, email, and a unique link provided to them.
* **Engagement Metrics:** Tracks the actions taken by recipients, including whether they clicked on a link (clicked), succeeded in a desired action (succeeded), were trained (trained), or reported the lure (reported), along with the timestamps for each action.
* **Campaign Effectiveness:** Presents key performance indicators such as success rate and click rate, offering insights into the overall effectiveness of the campaign.
* **Scenario and Awareness Details:** Details the specific scenario used in the campaign, the time spent on the scenario (scenario\_time), and any awareness components, including when awareness content was clicked (awareness\_clicked\_at) and the time spent on awareness (awareness\_time).
* **Additional Metrics:** Records other relevant data such as the subject of the email used in the campaign, time metrics related to the first click and report after delivery, and whether files were downloaded or data was collected.
* **Outcome and Feedback:** Notes any out-of-office responses, bounced emails, and direct responses from the recipients, as well as whether a certificate was received or training (with or without a quiz) was completed, providing a comprehensive view of recipient engagement and learning outcomes.\ <br>

  <figure><img src="/files/dVdYyKIIYRbFTi6xGP8O" alt=""><figcaption></figcaption></figure>

***


# Adaptive Phishing Programs

{% hint style="info" %}
Adaptive Phishing Programs are available in Lucy version 5.7 and above.
{% endhint %}

{% hint style="info" %}
Adaptive Phishing is currently in Beta and is available by request.

For access to this Beta feature, please contact your account manager.
{% endhint %}

## Introduction

Adaptive Programs are a new simulation mode that automatically adjusts phishing attack difficulty for each user based on their individual [risk score](/application-reference/users/risk-score). Unlike traditional campaigns that send the same content to all employees at once, an Adaptive Program is a continuous, self-adjusting system that evolves based on real-time user behavior.

This feature is designed for organizations that want:

* Difficulty progression based on user behavior
* Reduced administrative overhead
* More accurate measurement of user risk over time

#### The Assess-Learn-Adapt Cycle

The system functions as an automated loop that minimizes manual intervention while maximizing training effectiveness:

* **Behavioral Tracking:** The system monitors how each user interacts with simulated threats.
* **Risk Scoring:** Based on these interactions, the system calculates and updates a unique [risk score](/application-reference/users/risk-score) for every user.
* **Dynamic Assignment:** Users are automatically categorized (e.g., Rookie, Advanced, or Expert) and assigned phishing scenarios tailored to their specific skill level.
* **Automated Iteration**: The system schedules and launches new campaigns indefinitely, learning from the results of one campaign to optimize the next.

## Getting Started

To create an adaptive campaign navigate to **Phishing Programs** and then select **+ New Program:**

<figure><img src="/files/3Fq6lpNFNIp3jylg4qMC" alt=""><figcaption></figcaption></figure>

Give the program a name and a [client](/application-reference/settings/clients), then select **Create**.

<figure><img src="/files/WHk0i4NlSp2vxFs1T7CC" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Test Mode enables smaller frequency options and limits recipients to 10 for safe testing.
{% endhint %}

## Configuration

Just like standard campaigns, Adaptive Programs have an initial configuration that must be completed first.&#x20;

### Base Settings

The [base settings](/application-reference/campaigns/campaign-settings/main-settings/base-settings) are the same as any other campaign with one new setting, **Run Frequency**.

<figure><img src="/files/ljIeW6y1ane91nikIKw5" alt=""><figcaption></figcaption></figure>

This setting controls the length of each individual scenario within the program. In the screenshot above, every scenario will run for 2 weeks. At the end of this timeframe, the program will re-calculate the risk score for each user and randomly assign them a new scenario according to their new score.

{% hint style="success" %}
Click **Save** to apply your changes and select **Finalize Step** when you're ready to move on.
{% endhint %}

### Attack Simulation

In a standard campaign you can add one or more attack scenarios to your campaign, and the same is true of an adaptive program.

The difference is that Adaptive Programs use your configured [Risk Scores](/application-reference/users/risk-score) automatically. For each Range (Rookie, Advanced, Expert, etc.) you can add one or more attack scenarios that your Adaptive Program will use when randomly assigning scenarios.

Adding and configuring a scenario works just like in a [standard campaign](/application-reference/campaigns/campaign-settings/main-settings/attack-simulation/attack-templates).

<figure><img src="/files/r3HksAvBVx9XgoIZr7Jk" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Users will not receive a scenario they've already received unless they've exhausted all scenarios in their level. To ensure a broad and non-repetitive learning experience, it is recommended to add at least 3–4 scenarios per risk level.
{% endhint %}

{% hint style="success" %}
Select **Finalize Step** when you're ready to move on.
{% endhint %}

### Recipients

Unlike in standard campaigns, recipients in an Adaptive Program do not need to be bound to any scenarios. The program will automatically use the Risk Score of each recipient to send them the appropriate scenario, and when that scenario is finished the program will update their scores and do it again!

{% hint style="info" %}
Select **Finalize Step** when you're ready to move on.
{% endhint %}

## Starting a Program

Select **Start** to initiate the campaign checks and start your program.

The program must run the checks for each scenario, so give it time to finish and don't navigate away from the page while the checks are in-progress.

{% hint style="danger" %}
Programs cannot be edited once started, so double-check your settings!
{% endhint %}

## Program Dashboard

Once you've finalized each step you'll be taken to the program's dashboard view, which looks very similar to the standard campaign view:

<figure><img src="/files/f8eqYroOwK0yX0ddMnZ7" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Adaptive programs can use the [scheduler](/application-reference/campaigns/campaign-settings/optional-settings/schedule), [generate reports](/application-reference/campaigns/campaign-settings/results/reports), and use all the other [advanced options](/application-reference/campaigns/campaign-settings/optional-settings/advanced-settings) of a regular campaign.
{% endhint %}

### Program Statistics

On the dashboard page you can select **Program Statistics** to see an overview of your program:

<figure><img src="/files/3JNcBenEIg4YeiU5hiZr" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/jtmyMhOYOPbGkPXw78xK" alt=""><figcaption></figcaption></figure>

This view will again look familiar, with a few new additions:

* **Export Statistics**: Select this to go to the [Statistics Dashboard](/application-reference/statistics-dashboard) where you can filter by Adaptive Programs and then generate a report.
* **Edit Program**: Select this to go back to the program dashboard.
* **Average Risk Level**: The current mean risk score across all participating users.
* **Recipients (Users)**: The total number of unique users enrolled in the program.
* **Adaptive Program Runs**: A counter showing how many times the system has automatically executed a new campaign cycle.
* **Risk Levels**: This bar chart categorizes users by their risk tier (Rookie, Advanced, or Expert) for each of the most recent campaign runs.
* **Average Attack Risk Score**: This line graph tracks the fluctuation of the average risk score across your last five campaign cycles.&#x20;


# AURA

{% hint style="info" %}
AURA is available in Lucy version 5.7 and above.
{% endhint %}

{% hint style="info" %}
AURA is currently in Beta and is available by request.

For access to this Beta feature, please contact your account manager.
{% endhint %}

## Introduction <a href="#overview.1" id="overview.1"></a>

AURA is an automated awareness engine designed to run a continuous security awareness program without requiring manual campaign setup.

Administrators select topics, define target audiences, choose main courses, set validity periods, and define boosts frequency. Once activated, AURA continuously checks which users need which training and automatically sends the appropriate education based on their individual learning record.

Instead of launching recurring awareness campaigns, organizations configure the program once — and AURA maintains it automatically.

***

{% hint style="info" %}

## Relationship to Adaptive Phishing <a href="#relationship-to-adaptive-phishing" id="relationship-to-adaptive-phishing"></a>

AURA complements [Adaptive Phishing](/application-reference/adaptive-phishing-programs):

* **AURA maintains knowledge through structured education.**
* **Adaptive Phishing evaluates user behavior through ongoing simulations.**

Together, they provide continuous education and continuous behavioral testing.
{% endhint %}

## Program Configuration <a href="#how-it-works.1" id="how-it-works.1"></a>

{% hint style="success" %}
Understanding these terms is essential to understanding AURA.
{% endhint %}

<table data-header-hidden><thead><tr><th width="127">Term</th><th>Definition</th></tr></thead><tbody><tr><td><strong>Topic</strong></td><td><p>A cybersecurity subject (e.g., Phishing, Passwords, MFA).</p><p>AURA contains 18 predefined topics.</p></td></tr><tr><td><strong>Course</strong></td><td>The main learning material for a topic.</td></tr><tr><td><strong>Awareness Boost</strong></td><td>A short refresher sent after the course to reinforce knowledge.</td></tr><tr><td><strong>Valid Course</strong></td><td>A course that was completed and has not expired yet.</td></tr><tr><td><strong>Valid Topic</strong></td><td>A topic where the course is valid (boost not required for validity).</td></tr><tr><td><strong>Resilience</strong></td><td>A percentage score that shows how well a user is protected for a topic.</td></tr><tr><td><strong>Reminder</strong></td><td>Automatic follow-up email if a user has not completed assigned material.</td></tr><tr><td><strong>Repeat Offender</strong></td><td>A user who received at least one course for every topic and completed none.</td></tr></tbody></table>

For each awareness topic, administrators define:

* The required Course
* The Topic and Course validity period (when it expires)
* The Boost (short reinforcement material such as videos, games, or short learning units)
* How often Boosts should be sent
* The target audience

This setup defines the organization’s structured awareness program.

***

### Continuous Automated Education <a href="#id-2.-continuous-automated-education" id="id-2.-continuous-automated-education"></a>

After activation, AURA regularly checks all users and determines:

* Who has not completed required Courses
* Whose Courses validity has expired
* Who is due to receive Boost content
* Who has not engaged with previously assigned material

Based on this evaluation, AURA automatically sends the relevant course or booster to each user.

Education is assigned per user based on:

* Completed Courses
* Expiration status
* Boost history
* Outstanding requirements

No recurring manual campaign creation is required.

***

### Courses Lifecycle Management <a href="#id-3.-courses-lifecycle-management" id="id-3.-courses-lifecycle-management"></a>

AURA continuously monitors courses validity and ensures:

* Courses are reassigned when they expire
* Users receive reminders when required
* Training coverage remains up to date

This prevents awareness levels from degrading over time.

***

### Risk & Progress Dashboard <a href="#id-4.-risk-and-progress-dashboard" id="id-4.-risk-and-progress-dashboard"></a>

AURA includes a dashboard providing visibility into:

* Overall training completion rates
* Completion per security awareness topic
* Courses validity status
* Boost delivery and engagement
* Progress over time

Security officers can monitor awareness coverage across the organization and identify gaps.

***

{% hint style="danger" %}

## Limitations in the Beta release <a href="#beta-version-current-limitations" id="beta-version-current-limitations"></a>

### Content & Template Structure <a href="#content-and-template-structure" id="content-and-template-structure"></a>

* Fixed structure of **18 predefined topics**
* Each topic includes **1 course and 2 boost templates** (total: 54 templates)
* All templates must be pre-installed in Lucy before AURA activation
* Template usage is hard-coded in the AURA database
* Administrators cannot:
  * Select alternative templates
  * Replace templates
  * Define custom topics
  * Attach custom templates to topics

***

### Language Support <a href="#language-support" id="language-support"></a>

* English only
* All awareness materials are sent in English regardless of the user’s preferred language
* This must be communicated clearly to multilingual customers

***

### Deployment & Architecture <a href="#deployment-and-architecture" id="deployment-and-architecture"></a>

* Designed to run exclusively on a VPS with internet access
* Not compatible with on-premise Lucy deployments
* Running multiple AURA instances connected to a single Lucy environment is not recommended and not fully tested
* Supporting multiple clients would require separate VPS deployments
* The current codebase is not optimized for large parallel instances with heavy recipient groups

***

### Administration Constraints <a href="#administration-constraints" id="administration-constraints"></a>

* Only one administrator account supported
* No administrator management interface
* Only one active AURA program instance can run per Lucy environment

***

### Testing Constraints <a href="#testing-constraints" id="testing-constraints"></a>

* Initial training assignments can be observed within a day
* Boosts are triggered one month after course completion
* Full course and boost flow testing requires extended time
* Short test cycles are not practical
  {% endhint %}


# Campaigns

A campaign is a structured program designed to assess and improve employees' understanding and response to cybersecurity threats. It typically includes simulated attacks, such as phishing, and educational content about best practices in cybersecurity.

These campaigns serve as benchmarks for an organization's security awareness level, helping to identify areas of risk and plan for future training to mitigate these risks.

{% hint style="info" %}
Refer to our platform reference article for an overview of the [Campaigns Dashboard](/application-reference/campaigns-dashboards)
{% endhint %}


# Wizard Mode

## Start the Wizard

On the Lucy dashboard, select **+ New Campaign**, then select **Wizard**.

<figure><img src="/files/LQoQyqmGVhfWvDhk97q5" alt=""><figcaption></figcaption></figure>

## Select a Campaign Type

<figure><img src="/files/BcwrzjYXo5PJVcrQm2CL" alt=""><figcaption></figcaption></figure>

Lucy campaigns come in three types:

{% tabs %}
{% tab title="Attack Simulation" %}
Creating a campaign with an Attack begins by selecting the Attack type. Please note that you can also associate an Awareness training template in the following steps if you choose to do so.

#### [Data Entry Attack](/guides/attack-simulations/attack-types/data-entry-attack)

The recipient will receive an email with a link that leads to a fake webpage designed to harvest credentials. A successful attack occurs when the recipient enters their data on this page.

#### [Hyperlink Attack](/guides/attack-simulations/attack-types/hyperlink-attack)

The recipient will receive an email with a link, and the attack is deemed successful as soon as they click on this link. There is no associated landing page in this scenario.

#### [File Attack](/guides/attack-simulations/attack-types/file-attack)

Like Data Entry Attacks, the user receives an email with two potential actions: they can click a link to visit a landing page where they download an executable file, or the executable file can be directly attached to the email itself.

#### [Portable Media Attack](/guides/attack-simulations/attack-types/portable-media)

LUCY provides the capability to create files for use on various removable media devices, including CDs, USBs, DVDs, SD Cards, and others. The most common approach involves attacks via USB sticks.

#### [Smishing](/guides/attack-simulations/attack-types/smishing)

Smishing, also known as SMS Phishing, is a deceptive tactic where fraudulent text messages are sent to trick recipients into revealing sensitive information such as credit card details or passwords. It's important to note that this type of attack can only be configured in [Expert Mode](/application-reference/campaigns/expert-mode).
{% endtab %}

{% tab title="Awareness Education" %}
This selection is reserved for Awareness-only campaigns, where an administrator aims to focus solely on training their users.
{% endtab %}

{% tab title="Infrastructure Tests" %}

#### **Technical Malware Test**

Evaluates your technical defenses against malware by simulating a malware attack and observing whether the current security setup can detect and neutralize the threat.

#### **Mail & Web Filter Test**

Assesses the effectiveness of your email and web filtering systems. This test sends non-malicious simulated spam and phishing emails to see if the filters can successfully block these potential threats.

#### **Spoofing Test**

Checks the robustness of the system against email spoofing. It tests whether someone can mimic or 'spoof' an email address from your domain, which is a common tactic used in phishing and social engineering attacks.
{% endtab %}
{% endtabs %}

## Select a Template

After choosing your campaign type you will be taken to the template gallery to select a template for your campaign. You can preview the email and landing pages by seleting the **Preview** button on each template. When you're ready, select a template and then select **Next** at the bottom of the wizard.

<figure><img src="/files/w8hP341RNX7iahYW3N4x" alt=""><figcaption></figcaption></figure>


# Settings

## Campaign Settings

In this section, you can specify the campaign name, associated client, and additional automation options.

<figure><img src="/files/V7f4uDaLRMqtlVwRiwDr" alt=""><figcaption></figcaption></figure>

#### Name and Client

Every campaign requires a name and an associated client.\
These settings are displayed in the [campaign dashboard](/application-reference/campaigns-dashboards).

#### Stop Date

If enabled, the campaign will automatically stop at this time. You can also choose to automatically send a campaign report to the campaign administrator once the campaign ends.

#### Industry Benchmark

If you want to compare your phishing results with companies in the same industry sector, you can enable benchmarking. If selected, your **anonymized** results will be included in the benchmarking tool, sharing only overall success rates **without any user- or client-specific data**.

For more on benchmarking read [here](/application-reference/settings/benchmark-sectors).


# Attack Settings

## **Domain**

Select an [attack domain you have registered](/application-reference/settings/common-system-settings/domains).\
This will be the primary domain for both the sender email address and the associated landing page.

<figure><img src="/files/piVII4If8tLCucY1H8tw" alt=""><figcaption></figcaption></figure>

## **SSL**

When using an attack domain, it's important to [create an SSL certificate](/application-reference/settings/common-system-settings/ssl-settings).

{% hint style="danger" %}
Without an SSL certificate, your recipients will encounter a big <mark style="color:red;">red</mark> warning page, signaling that the site they're trying to access isn't secure. This could seriously affect the authenticity of your simulation if it's not properly set up.
{% endhint %}

If you've already created an SSL certificate you can use the **Select Existing SSL Certificate** option. If not, you can either manually **generate** one yourself or automatically generate and install one using **Let's Encrypt** (this is much easier).

<figure><img src="/files/gbKnHr8g6mYsDb9amDyA" alt=""><figcaption></figcaption></figure>

## **Sender Name**, **Email**, and **Subject**

Here you will define from whom the Attack is being sent, their email address, and the subject.&#x20;

{% hint style="success" %}
It's recommended to use a sender email address that matches your registered attack domain. This practice enhances email deliverability by leveraging existing DNS records, reducing the risk of emails being caught by spam filters.
{% endhint %}

<figure><img src="/files/Os7J8HZ7vQyI4q6SZ63x" alt=""><figcaption></figcaption></figure>

## Template Language

Select a default language for the template. Later on you can add additional language configurations.

<figure><img src="/files/9A5zzA41KOGZeS4UHU1R" alt=""><figcaption></figcaption></figure>

## Email Preview

Later on you can edit this email, for now the campaign wizard simply shows you what the template email looks like.

<figure><img src="/files/cDNdwQKmlvmrOAMd2DIj" alt=""><figcaption></figcaption></figure>


# Awareness Settings

## Add an Awareness Template (optional)

{% hint style="success" %}
If you selected **Education Awareness** as the campaign type, this was done in the last step.\
If you selected **Attack Simulation**, you may optionally attach an Awareness that will be sent to any recipients that fail the simulation.
{% endhint %}

In the **Awareness Settings**, select **Add Awareness Training**:

<figure><img src="/files/76iIfBx2QXh8nMCtfL73" alt=""><figcaption></figcaption></figure>

The wizard will again open the template gallery where you can preview and select an Awareness template. When you're ready, select a template and select **Next** to return to the settings tab.

<figure><img src="/files/0yGqSnh57liYGWvVKd4R" alt=""><figcaption></figcaption></figure>

## Domain

You can either use the default system domain or send the awareness from a trusted domain.

{% hint style="success" %}
We strongly recommend using the Lucy admin domain for awareness content.\
This way your SSL is already created and your users see a domain they know and trust when receiving training materials.
{% endhint %}

## SSL

If you are using your Lucy domain for awareness content, it is not necessary to enable custom SSL.\
Lucy will use the Lucy domain's SSL certificate by default.

{% hint style="danger" %}
Without an SSL certificate, your recipients will encounter a big <mark style="color:red;">red</mark> warning page, signaling that the site they're trying to access isn't secure. This could deter your users from completing the training material.
{% endhint %}

## Sender Name, Email, and Subject

Here you will define from whom the Awareness is being sent, their email address, and the subject.

{% hint style="success" %}
It's recommended to use a sender email address that matches your Lucy domain. This practice enhances email deliverability by leveraging existing DNS records, reducing the risk of emails being caught by spam filters.
{% endhint %}

## Template Language

Select a default language for the template. Later on you can add additional language configurations.

<figure><img src="/files/CdqYGLfDcVukhZee80Uf" alt=""><figcaption></figcaption></figure>


# Optional Settings

## Certificate (Awareness Diploma)

{% hint style="info" %}
See [here](/application-reference/templates/awareness-training-diploma) for a guide on editing awareness diplomas.
{% endhint %}

If you wish to send your users a diploma after they complete the training content, select the diploma here.

## Email Settings

<figure><img src="/files/aepiU1SKoVo3rrFvduc4" alt=""><figcaption></figcaption></figure>

#### **Receive Sender Email Replies**

Enable this if you want Lucy to capture any replies to the campaign email and forward them to an inbox of your choosing. To use this feature you must enter a **Forward Email** in the box at the bottom.

#### **Send Plaintext Email**

Enable this if you want Lucy to send the email as plaintext. This is mostly a troubleshooting method as it will cause all HTML tags to appear as text in the email body, but if your email contains no HTML or other rich text it can be used for live emails as well.

#### **Random Email**

Enable this option to use a randomly generated email address as the Sender, using the configured email domain.

#### **DKIM Support**

Enable this option to insert a DKIM record into the campaign email. Please note that this option does not work if you are using an [external SMTP server](/application-reference/settings/common-system-settings/smtp-servers) to send campaign emails.

## Tracking

<figure><img src="/files/BDzDPCKDWALbFKZkYSeh" alt=""><figcaption></figcaption></figure>

#### **Track Bounced Emails**

Enable this option to detect when a recipient sends an auto-reply in response to a Lucy email, such as an Out-of-Office reply. See [here](/application-reference/settings/submitted-email-settings/incident-autoresponder#autoresponse-detection) for info on autoresponse detection.

#### **Interval Email Testing**

Use an email inbox to keep track of your campaign. Enable this option to send the campaign email to your **tracking email** after every N regular emails, defined by the **tracking interval**.

## Data Collection

<figure><img src="/files/jQ5X2em2RyruiNK40goN" alt=""><figcaption></figcaption></figure>

## End User Profiles

Enable this option to create End User accounts for your recipients and enable the End User portal.

{% hint style="info" %}
[End User](/application-reference/users/end-users) accounts give your recipients access to a dashboard where they can view their stats and training materials. See [here](/application-reference/users/end-user-portal-settings) for a guide on setting up the end user portal.
{% endhint %}

<figure><img src="/files/XAwXXYLCWvdERsQ0R4VL" alt=""><figcaption></figcaption></figure>

#### Domain

We recommend selecting **System Defaults** for this option and configuring the portal by following the instructions linked above.

#### Send Credentials Type

**Plaintext Passsword:** Add the user's password to the awareness email as an attachement.

**Password Reset Link:** Provide a password reset link the user can click on. Be sure to use the `%user-password-reset%` variable in the email message!

**Login with SSO:** Only use this if you have [configured SSO](/application-reference/settings/common-system-settings/sso-configuration) using OAuth for your Lucy portal.

## Campaign Presets

When you are finished with this page, you might want to save these settings as a **Preset:**

<figure><img src="/files/rGD7BoUJ5PYKQyUb1lyE" alt=""><figcaption></figcaption></figure>

Campaign presets save you even more time by loading in your most commonly re-used settings such as domains, SSL, sender information, and even templates.

You can load these settings by selecting the **Presets** menu at the top of the campaign wizard.

<figure><img src="/files/rHSM9QrqBc4w7sC6I0ir" alt=""><figcaption></figcaption></figure>


# Recipients

## **Adding recipients**

When utilizing the wizard, you have the option to select an existing group or create a new one.

{% hint style="info" %}
For additional details on how to create existing recipient groups with import capabilities, including automatic[ LDAP](/application-reference/settings/common-system-settings/ldap-settings) or [Azure Entra ID](/application-reference/settings/common-system-settings/azure-applications) integration, please refer to our section on [recipients](/application-reference/users/recipient-groups).
{% endhint %}

<figure><img src="/files/Mwoqu5rAk2r2IOmBQhXI" alt=""><figcaption></figcaption></figure>


# Review

**Review your campaign**

{% hint style="success" %}
Questions about your campaign? [Contact our Solution Engineering team](https://lucy-security.atlassian.net/servicedesk/customer/portal/37/group/41/create/59) for assistance.
{% endhint %}

At this point, you have successfully configured your campaign. This page offers a comprehensive overview of all the settings that have been applied, allowing you to review and make any necessary modifications.

If all is in order, select **Create Campaign** to continue. You will be given three options:

<figure><img src="/files/yM3s89n62lgYNEKo8QOE" alt=""><figcaption></figcaption></figure>

#### **Start Campaign**

Begin the campaign by initiating campaign checks.

#### **Initiate Test Run**

Send a test run of the campaign to a single email address of your choosing.

#### **Go to Campaign**

Go to the campaign's dashboard to continue editing.


# Expert Mode

## Create a campaign in Expert Mode

Select **+ New Campaign** on your campaign dashboard, then select **Expert Mode:**

<figure><img src="/files/wUsyt6ozVXqpGs7rmSms" alt=""><figcaption></figcaption></figure>

Give the campaign a **name,** assign a **client,** and select either **phishing, awareness,** or **phishing and awareness**.

<figure><img src="/files/39eeunvGp7k3AdFxhx6z" alt=""><figcaption></figcaption></figure>

Select **Create** and you will be taken to the campaign's dashboard.

{% hint style="success" %}
Each tab under **Main Settings** must be configured and **finalized** before the campaign can begin. When you're done configuring a step, select **Finalize Step** in the top-right corner to confirm it. Once all steps are finalized, the campaign will unlock and is ready to begin.
{% endhint %}

<figure><img src="/files/ql0jte3pLwHobge2peyY" alt=""><figcaption></figcaption></figure>

See our pages on the various [campaign settings](/application-reference/campaigns/campaign-settings) to configure each part of the campaign.


# Campaign Settings


# Main Settings


# Base Settings

## General Info

<figure><img src="/files/scUYkYvF868TbtGUo1Hq" alt=""><figcaption></figcaption></figure>

### Campaign Name and Client

Give the campaign a descriptive name and assign a [client](/application-reference/settings/clients).\
These will be visible in the campaign dashboard and reports.

### Type

{% hint style="success" %}
This setting will change which steps must be **finalized** before the campaign can run.
{% endhint %}

**Awareness Education** - a campaign with only training materials.\
**Attack Simulation** - a campaign with only an attack simulation.\
**Attack Simulation & Awareness Education** - a campaign with linked attack and awareness.

### Stop Options

Configure an automatic stop date for the campaign. This setting is optional.

## Campaign Parameters

<figure><img src="/files/zXGLPe6DJFwSf3I7fajG" alt=""><figcaption></figcaption></figure>

### Industry (Benchmark Sector)

This field is used to benchmark the campaign against average values in the selected industry. For more on benchmarking read [here](/application-reference/settings/benchmark-sectors).

### Notes

A section for admin notes on the campaign. This does not appear on the campaign report.

## Save & Finalize

Select **Save Progress** at the bottom of the screen to apply your changes. When you're ready to start the campaign, select **Finalize Step** to let Lucy know these settings are correc&#x74;**.**

{% hint style="success" %}
**Finalize Step** does not prevent you from changing settings!\
This step is just to let Lucy know that the campaign can be unlocked and started.
{% endhint %}

<details>

<summary>Awareness Re-Scheduling</summary>

Enable if you wish to allow recipients to reschedule their awareness training.

Once this option is enabled, a popup will appear in the user's browser, allowing them to reschedule the training for a specific date. The email will then be resent on the selected date.

![](/files/V8GJ7j7O3cYzJGiDA2YL)

</details>

<details>

<summary>Ignore Repeated Answers in Awareness</summary>

If you include awareness training, you can specify that only the first response to an exam or quiz is recorded, and any repeated attempts will be ignored.

</details>

<details>

<summary>End-User Profiles Enabled</summary>

Users may not always have time to complete an awareness course right away. They have the option to reschedule the training, or alternatively, you can establish a dedicated portal for your end users. This portal enables them to log in and access their custom training links at any time, eliminating the need to resend an awareness email.

**Security considerations for access include:**

1. **Plain Text Password:** Sent only once as an attachment with the recipient's first awareness training email.
2. **Password Reset Link:** Can be included in the awareness email, allowing the user to configure a password upon initial login.
3. **Login with SSO:** Users can log in using their organization's Identity Provider (IDP). Ensure to [set up SSO](/application-reference/settings/common-system-settings/sso-configuration) prior to launching the campaign to facilitate this feature.

</details>

<details>

<summary>Tracking</summary>

Enable this feature to refine your campaign statistics by monitoring email responses:

**Track Bounced Emails** Determine which recipients did not actually receive the email, such as those with 'out of office' or bounced email responses.

**Interval Email Testing** Enhance the reliability of your campaign by scheduling periodic email tests. This involves sending emails to a predefined address at set intervals to verify ongoing mail delivery success. This helps track and ensure the health of your campaign's email system.

</details>

<details>

<summary>Campaign Stop</summary>

**Stop the Campaign Automatically:** If this setting is enabled, the campaign will automatically stop on the specified date. After this date, no further emails will be sent, and campaigns with landing pages will no longer be accessible. This function allows you to set a definitive end date for the campaign's active phase.

**Send a Report When You Stop the Campaign:** When enabled, this feature automatically sends you a report upon the campaign’s conclusion. Ensure that you have configured the appropriate [report template](/application-reference/templates/report-templates) in advance to receive a comprehensive summary of the campaign’s performance and outcomes. This automated report helps in evaluating the effectiveness of the campaign without manual intervention.

</details>

<details>

<summary>Pinned / Delete Protection</summary>

**Pinned Campaigns:** "Pinned campaigns" function similarly to browser favorites, allowing you to group various campaigns within a specific view for easy access. Once you activate the "pinned" checkbox for a campaign, it will appear in the designated frame on the dashboard. This feature helps you quickly navigate to and manage your most important or frequently accessed campaigns.

**Delete Protection:** Delete protection provides a safety net against data loss, ensuring that your campaign information is preserved by disabling the delete function for this campaign in the user interface.

</details>

<details>

<summary>Anonymous Mode</summary>

Use this mode to conceal all victim data from statistics and reports, ensuring privacy and anonymity in the data handling process. Please be aware that once this operation is performed, it cannot be undone. This permanent setting is crucial for campaigns where confidentiality is a priority.

</details>

<details>

<summary>Suppress Duplicate Recipients</summary>

Lucy reviews incoming emails from the new group, specifically those already listed as recipients in the campaign. This option disables the addition of new recipients for individuals whose emails are already included in the campaign.

</details>

<details>

<summary>Antivirus/Firewall Protection Interval</summary>

In some cases, remote firewalls, spam filters, or virus filters may automatically scan all the URLs within a link. This can lead to false positives, causing LUCY to register all link clicks as successful. To prevent this issue caused by third-party applications, you can activate the antivirus/firewall protection feature. This will prompt LUCY to disregard all GET requests for the initial 30/60/90/120 seconds, thus minimizing the impact of automatic link scanning.

</details>

<details>

<summary>Enable SSO for Awareness Websites</summary>

This feature enables you to generate a static link for the awareness website. It proves beneficial when you don't require individual email messages for each user, opting instead to distribute a single link through alternative channels. This unique link accessed via the organization's Identity Provider, remains specific to the context of a particular awareness scenario and campaign, ensuring targeted dissemination.

</details>


# Awareness Education

<table data-view="cards"><thead><tr><th data-type="content-ref"></th></tr></thead><tbody><tr><td><a href="/pages/GYL2qXZBA8CJjTWeF0F3">/pages/GYL2qXZBA8CJjTWeF0F3</a></td></tr><tr><td><a href="/pages/CDToMAY8wyEOJosmPSFa">/pages/CDToMAY8wyEOJosmPSFa</a></td></tr><tr><td><a href="/pages/a4AylI5C3aAmsl14wGjo">/pages/a4AylI5C3aAmsl14wGjo</a></td></tr></tbody></table>


# Awareness Templates

## Add an Awareness Template

Select **+ New Awareness** to view the template gallery.

Search for an Awareness template, select **Use Template**, and select the default language to begin using the template.

<figure><img src="/files/gKTAaEMm8UlvEMHc9GX5" alt=""><figcaption></figcaption></figure>

***

## Base Settings

Once a template is added to the campaign you can find it under **Awareness Settings**. Select a template to edit its settings and content.

<figure><img src="/files/6RoUfOf4AdAihh37AoIa" alt=""><figcaption></figcaption></figure>

#### Name

By default, the original template name will be populated, but you can change this name to apply only to the specific campaign associated with the awareness template.

#### Risk Level

By default, your awareness template is set to Risk Level 0. Each additional training will have a risk score incremented by 1. Risk level is 1:1 with the number of attack simulations a recipient has failed.

#### Website Enabled

Select this option if you want the user to be directed to a landing page to complete their training. Typically, this setting should be enabled to gather statistical data on the user's training metrics. Only disable it if you intend for the user to receive an email without tracking their training progress.

{% hint style="success" %}
After you enable this option, select **Save** to apply it. This will add additional tabs to the settings where you can configure the website and edit its content.
{% endhint %}

#### Create Awareness Training Diploma

This option is available only for awareness templates that include a Quiz/Exam. It is designed to automatically send users a predefined Training Diploma once they have successfully completed the training and achieved a score above the minimum passing threshold.

{% hint style="success" %}
After you enable this option, select **Save** to apply it. This will add additional tabs to the settings where you can configure the certificate and edit its content.
{% endhint %}

#### Languages

This is the default language setting for your template. If a user is imported into Lucy without a specified language, they will receive the awareness scenario in the default language selected here.&#x20;

{% hint style="info" %}
Most templates are available in our core languages. If you need a translation in a language not already provided, select that language in this tab. You will then have the opportunity to manually translate the content in the subsequent steps of this article.
{% endhint %}

***

## Website

The Website tab contains settings related to the training content, such as the hosting domain, behavior, and content.

### Settings

{% tabs %}
{% tab title="Domain" %}
Define the base domain to which the user will be redirected to access their awareness training content. You can also specify a subdomain, which is the portion of the URL before the base domain, such as **training**.lucysecurity.com

{% hint style="success" %}
If you are using a domain owned by your company, all [DNS records](/application-reference/settings/common-system-settings/domains#dns-records-explained) must be correctly configured to point to your Lucy server for successful mail delivery.
{% endhint %}
{% endtab %}

{% tab title="Quiz Options" %}

#### Quiz

By default, if your campaign contains a Quiz or Exam, the "Quiz" selection box will be enabled. This means that once the user completes the first quiz, they will be marked as trained. Additionally, the system will provide the score and a list of answers submitted by the user which can be viewed in the [statistics section of the campaign results](/application-reference/campaigns/campaign-settings/results/statistics#awareness-website).

#### Extended Tracking

This option tracks when users complete a pre-defined Quiz or Exam. For instance, in Awareness templates containing multiple quizzes, enabling only the **Quiz** option will log the result of the first quiz the user interacts with.  With this option enabled, you can specify which quiz or exam determines the user's score.

To activate this feature, you need to add a call to the "lucyQuizEnd()" function without any parameters. Launch this function after the user answers the last question in your quiz. More information can be found [here](/guides/awareness-training/use-extended-method-of-tracking-the-end-of-the-quiz).

{% hint style="danger" %}
If you enable this option **without** calling the `lucyQuizEnd()` function recipients will **not** be marked as **Trained** in the campaign statistics.&#x20;
{% endhint %}

#### Success Score

A minimum score the user must receive in order to be marked as **Trained** and receive a diploma.
{% endtab %}

{% tab title="Preview Link" %}
The preview link offers a public URL for sharing with colleagues who do not have access to the Lucy administration panel. This feature is ideal for validating campaigns across different departments without running a campaign or adding stakeholders as administrative users on your Lucy server.
{% endtab %}

{% tab title="Language" %}
Each edit is confined to the selected language. If the default template does not include your target language, you can add and manually translate all text into the desired language. Remember to click 'Save' to commit the changes for each language.

{% hint style="warning" %}
Editing templates after binding them to a campaign commits the changes only to that specific campaign, not to the original template.

Editing a template within a campaign should be campaign-specific, indicating that the modifications are exclusive to that campaign and not intended for reuse in future campaigns. For more information, see our guide on [customizing Awareness templates](/guides/awareness-training/awareness-template-customization).
{% endhint %}
{% endtab %}
{% endtabs %}

### Content

See our guide for editing awareness content [here](/guides/awareness-training/awareness-template-customization).

***

## SSL Settings

If the website is enabled, you'll need SSL for the hosting domain.

Select the checkbox to include an SSL certificate:

<figure><img src="/files/HbCCk3C4WrP2ntgyV5Wo" alt=""><figcaption></figcaption></figure>

{% tabs %}
{% tab title="Select Existing" %}
Choose this option if you have already generated an SSL certificate on your Lucy server. This option allows you to reuse the existing certificate.

{% hint style="info" %}
Be advised that the validity period of the existing certificates will not be extended.
{% endhint %}
{% endtab %}

{% tab title="Generate or Upload" %}
This option is ideal if you already have an SSL certificate chain from a trusted certificate authority or if you would like to generate a self-signed certificate.&#x20;

{% hint style="warning" %}
Be aware that self-signed certificates are not issued by trusted certificate authorities. As a result, browsers will mark your domain as not secure when using these certificates.
{% endhint %}

**Option 1: Generate a self-signed Certificate**

<figure><img src="/files/JDJArxW7o4UrhWKZNv26" alt="" width="301"><figcaption></figcaption></figure>

1. **Domain**: Enter the domain name for which you want to generate the SSL certificate (e.g., lucysecurity.help).
2. **Email**: Provide a valid email address. This is where Let's Encrypt will send notifications about your certificate, such as renewal reminders.
3. **Details**: Fill in the Country, State, City, Organization Name, and Organizational Unit. These details are often used in the certificate's subject field and can be important for organizational certificates.
4. **Generate**: Click on the "Generate Certificate" button to create your self-signed certificate.

#### Option 2: Upload an Existing Certificate

1. **SSL Certificate**: Click "Choose File" to browse and select your existing certificate file (usually a `.crt` or `.pem` file).
2. **SSL Key**: Click "Choose File" to upload the private key file associated with your SSL certificate (this is a `.key` file and must be kept secure).
3. **SSL Key Password**: If your private key is password-protected, enter the password here.
4. **SSL Chain**: Click "Choose File" to upload the chain file (also known as the CA bundle or intermediate certificate) if required. This is needed for browsers to trust your certificate by establishing a chain of trust to a root certificate.
5. **Wildcard**: If you are uploading a wildcard certificate, you would check the "Wildcard" box. Wildcard certificates secure a domain and all its subdomains (e.g., `*.example.com`).
   {% endtab %}

{% tab title="Let's Encrypt" %}
Our default method, designed for maximum user-friendliness, enables your Lucy server to automatically generate a Certificate Signing Request (CSR) through the integrated Let's Encrypt API. It then submits this request to Let's Encrypt and automatically installs the full certificate chain on your Lucy server.&#x20;

This process may take up to 5 minutes to complete. Please wait for the "certificate successfully generated" notification before proceeding further.

{% hint style="info" %}
Let's Encrypt certificates are issued with a maximum validity period of 90 days.
{% endhint %}

{% hint style="danger" %}
Please be aware that Let's Encrypt, a third-party SSL provider, imposes certain limitations. One notable restriction is the issuance cap of no more than 5 certificates per week for the same domain name. For additional details on these limitations, you can visit: [Let's Encrypt Rate Limits](https://letsencrypt.org/docs/rate-limits/).
{% endhint %}
{% endtab %}
{% endtabs %}

{% hint style="success" %}
See our platform reference article [SSL Settings](/application-reference/settings/common-system-settings/ssl-settings) for more information.
{% endhint %}

***

## Certificate

The certificate tab pertains to the recipient's completion training diploma certificate, issued when the user successfully achieves a score above the pre-configured pass threshold on the quiz.

{% hint style="info" %}
Ensure **Create Awareness Training Diploma** is enabled in the **Base Settings**.
{% endhint %}

#### Select a Template

To begin, select a language and an orientation for the certificate, then choose one of the ready-made options:

{% hint style="warning" %}
Settings are not automatically shared across Languages; all adaptations must be applied to each selected language. Translated content must be applied separately.
{% endhint %}

<figure><img src="/files/rm7oWMA1zfVDU7PD0VQE" alt=""><figcaption></figcaption></figure>

Provide a suitable title to be displayed as the subject in the email when users receive their Training Diploma attachment.

<figure><img src="/files/IevYx0gM9fPnzihjhSVA" alt=""><figcaption></figcaption></figure>

#### Template Content

Use the WYSIWYG editor to make changes to the diploma.

**index.html** - the main content file

**content.html** - the email message

**style.css** - CSS for the content file

<figure><img src="/files/eO9JxrfYBS7rvTzi9ovb" alt=""><figcaption></figcaption></figure>

<details>

<summary>Certificate Variable Placeholders</summary>

In the certificate template, you can use the following variables:

* `%name%` — name of the certificate recipient.
* `%awareness%` — name of the awareness training.
* `%gender("MALE ADDRESSING", "FEMALE ADDRESSING", "NO GENDER")%` — recipient's gender.
* `%score%` — recipient's score.
* `%date%` — date of the certificate.
* `%time%` — time of the certificate issuance.

Please note that these variables are not available in CSS and JavaScript files.

</details>

***

## Certificate Message

<figure><img src="/files/hJHrQ5RqGbthnskqAYEc" alt=""><figcaption></figcaption></figure>

#### Subject

The subject line of the email.

#### Sender Name

The name of the sender. This can be anything you want.

#### Sender Email

The email address of the sender. This does **not** need to be an existing email address, but the domain **does** need to point to your Lucy server. For best results, use the same domain as your awareness website.

***

## Message

<figure><img src="/files/eeweuNCqgb80kwkhMNxz" alt=""><figcaption></figcaption></figure>

<details>

<summary>Email Variables</summary>

When creating email templates, you can personalize the content by using various placeholders that will be automatically replaced with specific user data when the email is sent. Below is an explanation of each variable available for use in the templates:

* `%link%`: This variable represents the base URL of your site. Use it to construct absolute URLs for navigation within your emails.
* `%user-password-reset%`: This placeholder is replaced with the unique URL for a password reset action.
* `%user-profile-link%`: Inserts a direct link to the user's profile page in the End User Portal.
* `%user-login-url%`: Provides a link to the End User Portal that utilizes SSO (OAuth 2.0) for login.
* `%name%`: The full name of the email recipient.
* `%firstname%`: The recipient's first name.
* `%lastname%`: The recipient's last name.
* `%email%`: The recipient's email address.
* `%client%`: The name of the client associated with the recipient.
* `%gender("MALE ADDRESSING", "FEMALE ADDRESSING", "NO GENDER")%`: This is a conditional variable that changes the greeting or addressing based on the recipient's gender.
* `%subject%`: The subject line of the phishing email.
* `%sender%`: The name of the sender of the phishing email.
* `%sender-email%`: The email address from which the phishing email is sent.
* `%started%`: The date when the related phishing campaign was started.
* `%stopped%`: The date when the related phishing campaign was stopped.
* `%time(FORMAT, OFFSET, ZONE)%`: A dynamic time variable where:
  * `FORMAT` refers to the format in which the date/time should be displayed.
  * `OFFSET` is the time offset from the mail send time, which can be positive or negative.
  * `ZONE` is the time zone to be applied.
  * Example: `%time("l, H:i", "0", "Europe/Zurich")%` would display the time of the email submission in the Europe/Zurich time zone.
  * Example: `%time("Y/m/d H:i:s", "60")%` would show a timestamp one hour ahead of the email submission time.

Note that these variables are intended for use in the HTML body of the email and are not applicable within CSS and Javascript files. They serve to customize the email content for each recipient and should be used accordingly to ensure a personalized user experience.

</details>

{% tabs %}
{% tab title="Attachments" %}
Add your own attachments. Keep in mind that most common email clients filter certain types of attachments, like executables, to prevent malware risks.
{% endtab %}

{% tab title="General Email Settings" %}
Set custom SMTP headers to meet specific needs. For example, you can add a custom email header to help your SPAM gateway distinguish between actual SPAM and emails sent from LUCY.
{% endtab %}

{% tab title="Advanced Email Settings" %}

* Send emails as plain text.
* **Random Email**:

  LUCY will generate a random email account with a random sender. The email account will be deleted after the campaign ends.

If you want to catch email replies from your awareness email, LUCY provides two options:

1. **Define a Reply-to Header**:
   * The Reply-to address is where email replies are directed, rather than the 'From' address. This is useful if the 'From' address cannot receive replies, for example, if you do not control the domain or lack a mail server setup for it. For instance, if the email shows as being sent from "<mitchel@guysfromrolla.com>" and the recipient clicks reply, the email will be directed to the Reply-to address set in the header, such as "<billg@microsoft.com>". Choose a Reply-to address you have access to.
2. **Define a Forward Mail**:
   * LUCY can forward incoming replies to a specified email address. This requires setting a [DNS entry (MX record)](/application-reference/settings/common-system-settings/domains#dns-records-explained) for the sender’s domain that points to LUCY. For example, if you send emails from "<attacker@phishing-test.com>" and LUCY's IP is 201.35.77.12, you need an MX record like "phishing-test.com MX 10 201.35.77.12". Enter your own custom mail address in the forward mail field (e.g., "<user@example.com>"). When someone replies to "<attacker@phishing-test.com>", LUCY receives the email and forwards it to "<user@example.com>". Note that many registration services offer free mail/DNS packages, allowing you to set up an email forwarder directly at the domain level, eliminating the need for LUCY’s forwarding feature.
     {% endtab %}

{% tab title="DKIM Support" %}
**DKIM Overview:**&#x20;

DomainKeys Identified Mail (DKIM) enhances email security by attaching a domain name identifier to a message, utilizing cryptographic techniques to validate authorization. This identifier is separate from other message identifiers such as the author's "From" field. DKIM effectively 'signs' emails to verify their origin, helping to identify and prevent spoofed emails. The process involves the sending mail server signing the email with a private key, while the receiving server uses a public key listed in the domain's DNS to verify the signature. Each domain can list multiple DKIM keys in its DNS, but each private key is unique to one mail server.

**Setting Up DKIM in LUCY:**

1. **Enable DKIM:**
   * Navigate to "Advanced Email Settings" in the message template of your Attack Scenario. Enable DKIM support and save the changes. A DKIM information box will then appear.
2. **DNS Configuration:**
   * Copy the provided key and create the corresponding DNS entry. Here’s an example of how to set it up with namecheap.com:

```
Name: selector._domainkey
Type: TXT
Value: "v=DKIM1; k=rsa; p=[YOUR_PUBLIC_KEY]"
```

**Validate DKIM Setup:**

* To confirm your DKIM is working, add an email from a service like [dkimvalidator.com](https://dkimvalidator.com/) to your DKIM test recipient group. Launch the campaign targeting this group, then check the results at dkimvalidator.com. If configured correctly, your setup should match the expected status.

**DKIM Header Details:** The DKIM signature is added to emails as an RFC2822 header field. Here's a breakdown of the common fields in a DKIM signature:

* **b:** Digital signature of the email's contents.
* **bh:** Hash of the email body.
* **d:** Signing domain.
* **s:** Selector used for the DKIM signature.
* **a:** Signing algorithm, typically rsa-sha1.
* **c:** Canonicalization algorithm for the header and body.
* **q:** Default query method, usually DNS.
* **t:** Timestamp of when the email was signed.
* **x:** Expiry time of the signature.
* **h:** List of header fields that were signed.

This setup ensures that emails sent through LUCY's mail server are authenticated, boosting trust and security for your email campaigns.
{% endtab %}
{% endtabs %}

***

## Mail Settings

Administrators have two choices for setting up mail delivery: globally or at the campaign level. Global settings affect all campaigns but can be overridden by campaign-specific settings, which only apply to the selected campaign. This flexibility allows for customized mail delivery preferences on a per-campaign basis:

{% tabs %}
{% tab title="Use System Settings" %}
{% hint style="info" %}
Navigate to [Settings -> Common System Settings -> Mail Settings](#mail-settings)
{% endhint %}

Here you can choose your default method for sending emails. This setting will apply to all campaigns.
{% endtab %}

{% tab title="Internal Postfix Server" %}
Lucy incorporates a built-in internal mail server (Postfix) as its default method for email delivery. This approach is straightforward and often used due to its direct integration within Lucy. To enhance delivery success, it's advisable to align the server's name with Lucy's Fully Qualified Domain Name (FQDN), potentially using a subdomain designated for mail purposes.
{% endtab %}

{% tab title="External SMTP Server" %}
Lucy allows the configuration of an external SMTP server via its general settings. This is particularly useful when aiming to circumvent spam filters that may block emails from new or untrusted IP addresses. Setting up involves adding your mail server details under "[Settings -> Common System Settings -> SMTP Servers](/application-reference/settings/common-system-settings/smtp-servers)"; followed by a connection test to ensure proper setup.
{% endtab %}
{% endtabs %}

***

## Awareness Groups

This feature is designed to automate the provisioning of multiple awareness templates based on three pre-defined goals.

1. Group recipients into Awareness Groups and serve them training content related to their day-to-day activities
2. Automate the sending of awareness content based on the recipient's [**risk level**](/application-reference/users/risk-score)
3. Use the [Scheduler](/application-reference/campaigns/campaign-settings/optional-settings/schedule) to create specific rules for different scenarios to manage selected Awareness Groups.

{% hint style="warning" %}
Awareness Groups are active only in campaigns with awareness scenarios.
{% endhint %}

Click [here](/guides/awareness-training/awareness-only-campaigns/using-awareness-groups) for a guide on using Awareness Groups.


# End Users

If this setting is enabled, the campaign will create [End User](/application-reference/users/end-users) profiles for recipients and utilize the[ End User Portal](/application-reference/users/end-user-portal-settings) to host the training content.

<figure><img src="/files/RM4hLsWSaoK9XEDCqKoX" alt=""><figcaption></figcaption></figure>


# Training

Settings related to the training content.

<figure><img src="/files/BVsIsy3jZ4OrODS10Nrc" alt=""><figcaption></figcaption></figure>

#### Allow Awareness Rescheduling

If this setting is enabled, the recipient will receive a popup in their email browser asking if they wish to reschedule the training. They will then receive the email again at a later date.

#### Ignore Repeated Answers in Awarenss

By default, Lucy allows any number of retries and will count the last quiz score the user earned. If this setting is enabled, Lucy will count **only** the first answers to a quiz for the user's score.


# Attack Simulation

###


# Attack Templates

### Add an Attack Template

Select **+ New Scenario** to view the template gallery.

<figure><img src="/files/vMSw89L2mZbKGSLFUbzi" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/8JNQfc3wxwG0u1OYGxPh" alt=""><figcaption></figcaption></figure>

Search for an Attack template, select **Use Template**, and specify the default language.

<figure><img src="/files/GP7G1kD8OkXBv2p0GI5o" alt="" width="312"><figcaption></figcaption></figure>

{% hint style="info" %}
You can dynamically preview templates. For further instructions, see our [reference article](/application-reference/templates/attack-templates#filtering).
{% endhint %}

***

### Base Settings

The base settings of the attack template provide an opportunity to define key parameters regarding the template's behavior.

<figure><img src="/files/ukQUrkW6sKWCZYXL8Uxf" alt=""><figcaption></figcaption></figure>

#### Template

You can change the attack template at any time by clicking the edit button on the right.

#### Name

Give the attack simulation a name. This will show up in the campaign report.

#### Domain

Configure a domain (and an optional subdomain) for the attack simulation.

{% hint style="danger" %}
Avoid using your System Domain for phishing simulations to prevent potential blacklisting issues. - See our reference article on [Domains](/application-reference/settings/common-system-settings/domains) for more information.
{% endhint %}

{% tabs %}
{% tab title="URL Shortener" %}
You can select a URL-shortening service from the dropdown menu. This feature is available only for domain names, not IPs.

{% hint style="warning" %}
URL-shortening services may scan the links, leading to inaccurate statistics.\
To avoid this, use the [system filter](/application-reference/settings/common-system-settings/filter-settings) settings to ignore the IP.
{% endhint %}
{% endtab %}

{% tab title="Advanced Tracking" %}
The statistic for recipients opening the email is based on a tracking image embedded within the email. However, many email clients block the automatic download of images, which can make this number less accurate.

{% hint style="info" %}
Please refer to our Guide on [Email Tracking Technologies](/guides/attack-simulations/email-tracking-technologies) for more information.
{% endhint %}
{% endtab %}

{% tab title="Advanced Information Gathering" %}
Lucy provides a suite of features designed to enhance your understanding of user behavior and system security when interacting with simulated phishing tests. Each option delves into different aspects of the recipient's environment, from browser configurations to network connections, offering valuable insights for cybersecurity awareness and training.

{% hint style="info" %}
Please refer to our detailed Guide on [Advanced Information Gathering](/guides/attack-simulations/advanced-information-gathering) for more information.
{% endhint %}

1. **Browser Details:** This tracks specific details about the browser the recipient is using, such as the browser type, version, and any associated browser extensions. Understanding the browser details can help identify potential security weaknesses or confirm if the browser is up-to-date and configured with security best practices.
2. **Firebug Information:** Firebug is a popular web development tool. If a user has Firebug installed, it could potentially be used to debug or modify webpages. Tracking whether Firebug or similar tools are present can reveal if there's an increased risk of web-based threats or attacks.
3. **Popup Blocker:** This checks if the user’s browser is configured to block popup windows. Popups are often used in phishing attacks to deliver malicious content, so knowing whether popup blockers are active can be indicative of the user's level of vulnerability.
4. **Geo Location:** By determining the geographic location of the user, the organization can assess if there are access patterns from unusual locations that could indicate compromised credentials or other security issues.
5. **Social Network:** This feature checks for active connections to social networks from the user’s browser. Given that social networks can be platforms for phishing and malware distribution, awareness of such activity can be crucial for understanding the social media risk landscape.
6. **Proxy:** Identifying whether the user is connected to the internet via a proxy can be important for security. Proxy usage can obscure the true IP address, which could either be a legitimate privacy measure or a method to hide malicious activity.
   {% endtab %}

{% tab title="Training Settings" %}
**Send link to Awareness Website Automatically via Email:**

This feature dispatches a link to the Awareness Website to a user immediately after they've fallen for a simulated attack. For this functionality to operate correctly, the Awareness Website must be active and published.&#x20;

**Send Awareness By Click Rate**

This feature allows you to set a threshold for historical click rate that triggers the sending of an awareness email. For instance, setting it at 50% means a user will receive an awareness email only if they have clicked on at least half of the links presented in previous phishing simulations.

**Send Awareness By Success Rate**

Similarly, the success rate determines the rollout of awareness training but is based on different successful interactions, not just link clicks, to initiate the e-learning process.

**Awareness Delay**

Within LUCY, you have the option to set a delay for sending the automated awareness email. This delay ensures that individuals within the same office aren't notified simultaneously about the occurrence of a phishing simulation, which can prevent immediate cross-talk and maintain the integrity of the test environment.

{% hint style="info" %}
Alternatively, users can be automatically [redirected to the Awareness training through their browser](/guides/attack-simulations/redirecting-users) immediately after engaging with the simulated attack.
{% endhint %}
{% endtab %}

{% tab title="Success Action" %}
This setting in LUCY determines what is considered a successful attack and subsequently triggers the start of eLearning.&#x20;

There are four options available for defining success actions. Each option specifies the condition under which eLearning is initiated. For instance, if you select "data submit" as the success action, eLearning will only begin once the user enters data and submits it on a landing page.&#x20;

{% hint style="warning" %}
It’s important to note that if you use "data submit" as the success action on a file-based template that doesn’t include a login mechanism, the eLearning will never be initiated for the user.
{% endhint %}

**Click:** triggered when the user clicks on the link in the email.

**Data Submit:** triggered when the user enters data and submits it on a landing page of the attack.

**File Download:** triggered when the user clicks on the file download button on the landing page.

**File Data Received:** triggered when the user executes the file and Lucy received the dummy data.
{% endtab %}

{% tab title="Collect Data" %}
Collected data encompasses information gathered from web-based phishing simulations, including credentials entered on a fake login page or data transmitted to LUCY from simulated document macros activated by users.

{% hint style="info" %}
Refer to our platform reference article on [viewing collected data](/application-reference/campaigns/campaign-settings/results/statistics#collected-data).
{% endhint %}

{% hint style="warning" %}
Lucy collects only "Partial" or "No" data to comply with data regulations, revealing the first three characters of usernames and passwords.
{% endhint %}
{% endtab %}

{% tab title="Double Barrel Attack" %}
When employing the Double Barrel Attack, the system initially dispatches a "Lure" email with teaser text. Subsequently, the system pauses for a specified duration before sending the actual phishing email. This advanced strategy involves the "Lure" potentially impersonating a known authority figure within your organization, who then endorses the follow-up attack simulation as bait.

The delay for the "Lure" defines, in seconds, the interval between the "Lure" and attack emails for a Double-Barrel Attack.

{% hint style="info" %}
Refer to our Guide on [Lure Attacks](/guides/attack-simulations/attack-types/lures) for more information.
{% endhint %}
{% endtab %}

{% tab title="RegExp" %}
Another option involves defining login filters to exclusively capture valid logins. For instance, you could specify the domain name in the User Name field or stipulate that passwords must be at least 8 characters long to be accepted by LUCY.

If you wish to validate logins and passwords using regular expressions (via the "Login Regexp" and "Password Regexp" fields in Scenario Settings), please ensure that the login field is named "Login" and the password field is named "Password".

{% hint style="info" %}
Refer to our Guide on [Regular Expressions in Login Fields](/guides/attack-simulations/regular-expressions-in-login-fields).
{% endhint %}
{% endtab %}
{% endtabs %}

***

### Mail Settings

Administrators have two choices for setting up mail delivery: globally or at the campaign level. Global settings affect all campaigns but can be overridden by campaign-specific settings, which only apply to the selected campaign. This flexibility allows for customized mail delivery preferences on a per-campaign basis:

{% tabs %}
{% tab title="Use System Settings" %}
Navigate to -> [Settings -> Common System Settings -> Mail Settings](#mail-settings)\
\
Here you can choose your default method for sending emails. This setting will apply to all campaigns.
{% endtab %}

{% tab title="Internal Postfix Server" %}
Lucy incorporates a built-in internal mail server (Postfix) as its default method for email delivery. This approach is straightforward and often used due to its direct integration within Lucy. To enhance delivery success, it's advisable to align the server's name with Lucy's Fully Qualified Domain Name (FQDN), potentially using a subdomain designated for mail purposes.
{% endtab %}

{% tab title="External SMTP Server" %}
Lucy allows the configuration of an external SMTP server via its general settings. This is particularly useful when aiming to circumvent spam filters that may block emails from new or untrusted IP addresses. Setting up involves adding your mail server details under "[Settings -> Common System Settings -> SMTP Servers](/application-reference/settings/common-system-settings/smtp-servers)"; followed by a connection test to ensure proper setup.
{% endtab %}
{% endtabs %}

***

### SSL Settings

Select the checkbox to include an SSL Certificate:

<figure><img src="/files/MTL6Y2gb5wMMWvHLVIq3" alt=""><figcaption></figcaption></figure>

{% tabs %}
{% tab title="Select Existing" %}
Choose this option if you have already generated an SSL certificate on your Lucy server. This option allows you to reuse the existing certificate.

{% hint style="info" %}
Be advised that the validity period of the existing certificates will not be extended.
{% endhint %}
{% endtab %}

{% tab title="Generate or Upload" %}
This option is ideal if you already have an SSL certificate chain from a trusted certificate authority or if you would like to generate a self-signed certificate.&#x20;

{% hint style="warning" %}
Be aware that self-signed certificates are not issued by trusted certificate authorities. As a result, browsers will mark your domain as not secure when using these certificates.
{% endhint %}

**Option 1: Generate a self-signed Certificate**

<figure><img src="/files/JDJArxW7o4UrhWKZNv26" alt="" width="301"><figcaption></figcaption></figure>

1. **Domain**: Enter the domain name for which you want to generate the SSL certificate (e.g., thrivedx.help).
2. **Email**: Provide a valid email address. This is where Let's Encrypt will send notifications about your certificate, such as renewal reminders.
3. **Details**: Fill in the Country, State, City, Organization Name, and Organizational Unit. These details are often used in the certificate's subject field and can be important for organizational certificates.
4. **Generate**: Click on the "Generate Certificate" button to create your self-signed certificate.

#### Option 2: Upload an Existing Certificate

1. **SSL Certificate**: Click "Choose File" to browse and select your existing certificate file (usually a `.crt` or `.pem` file).
2. **SSL Key**: Click "Choose File" to upload the private key file associated with your SSL certificate (this is a `.key` file and must be kept secure).
3. **SSL Key Password**: If your private key is password-protected, enter the password here.
4. **SSL Chain**: Click "Choose File" to upload the chain file (also known as the CA bundle or intermediate certificate) if required. This is needed for browsers to trust your certificate by establishing a chain of trust to a root certificate.
5. **Wildcard**: If you are uploading a wildcard certificate, you would check the "Wildcard" box. Wildcard certificates secure a domain and all its subdomains (e.g., `*.example.com`).
   {% endtab %}

{% tab title="Let's Encrypt" %}
Our default method, designed for maximum user-friendliness, enables your Lucy server to automatically generate a Certificate Signing Request (CSR) through the integrated Let's Encrypt API. It then submits this request to Let's Encrypt and automatically installs the full certificate chain on your Lucy server.&#x20;

This process may take up to 5 minutes to complete. Please wait for the "certificate successfully generated" notification before proceeding further.

{% hint style="info" %}
Let's Encrypt certificates are issued with a maximum validity period of 90 days.
{% endhint %}

{% hint style="danger" %}
Please be aware that Let's Encrypt, a third-party SSL provider, imposes certain limitations. One notable restriction is the issuance cap of no more than 5 certificates per week for the same domain name. For additional details on these limitations, you can visit: [Let's Encrypt Rate Limits](https://letsencrypt.org/docs/rate-limits/).
{% endhint %}
{% endtab %}
{% endtabs %}

{% hint style="success" %}
See our platform reference article [SSL Settings](/application-reference/settings/common-system-settings/ssl-settings) for more information.
{% endhint %}

***

### Bound Awareness Scenarios

Lucy enhances the effectiveness of educational campaigns by allowing for a targeted approach, focusing on individual user performance across different simulated attack scenarios. This personalized method not only makes the training more relevant but also more engaging for users.

**Scenario-Based Training Customization:**

* **Specific Attack Recognition:** Consider a campaign that includes various types of phishing attacks such as data entry, hyperlink, and file download attacks. Lucy allows you to monitor how each user responds to these different scenarios.
* **Customized Learning Experiences:** If a user fails in one scenario but performs well in others, Lucy enables you to tailor the training specifically to their needs. For example, a user who mistakenly downloads malware thinking it is a legitimate document does not necessarily need a broad phishing course. Instead, they can benefit from a focused session on identifying and avoiding file-based threats.
* **Efficient and Effective Training:** By providing training specific to the user's vulnerabilities, Lucy ensures that the learning is both efficient and directly applicable. This targeted education approach helps in reinforcing the correct practices without overloading the user with unnecessary information.

**Configuration**

Bound Awareness Scenarios can only be configured directly on the **Awareness Scenario**. In your current campaign, navigate to **Configuration -> Awareness Settings -> Select your Awareness Scenario**, then navigate to the tab "**Bound Attack Scenarios**":

<figure><img src="/files/gnn7wRmQqlbisKtVt4R7" alt=""><figcaption></figcaption></figure>

Here, you can specifically link each awareness scenario with the corresponding attack simulation that aligns with the training material.

This capability allows you to provide targeted and efficient awareness training that addresses users' specific needs based on their performance in different attack scenarios.

***

### Landing Page Template

The "Landing Page Template" tab in Lucy is a powerful tool for creating and managing phishing simulation landing pages.

See our guide for attack template customization [here](/guides/attack-simulations/attack-template-customization).

Lucy's attackt emplates will always include two files, **index.html** and **account.html:**

<figure><img src="/files/ksHvvLUe3ZWh27vYwCys" alt="" width="326"><figcaption></figcaption></figure>

{% hint style="info" %}
Lucy adheres to a strict naming convention for these files. If you create a custom template, make sure to name the files **`index.html`** and **`account.html`.**
{% endhint %}

**Index.html**

* **Purpose:** Serves as the initial landing page for the simulated attack. When users click a link in the attack email, they are directed to this page.
* **Function:** Mainly used for credential harvesting, this page typically prompts users to enter login details or other personal information.

**Account.html**

* **Post-Attack Redirection:** After data is submitted on index.html, users are redirected to account.html.
* **Function:** This page facilitates the conclusion of the attack. It may:
  * Automatically redirect users to the associated awareness training in the campaign.
  * Display a fake notification, such as "Your VPN was successfully authenticated."
  * Show a blank page that redirects immediately to awareness training with no delay, following the data exploitation on index.html.

{% hint style="danger" %}
The first page the user accesses should be named **`index.html`**.
{% endhint %}

#### **Preview the landing page**

Select the **Preview** button to view how the landing page looks in real-time, allowing for adjustments before deployment.

<figure><img src="/files/K9QrB8Y3aJqMILaLyksQ" alt="" width="563"><figcaption></figcaption></figure>

***

### Message Template

**Setting Up the Email**

{% hint style="warning" %}
Settings are not automatically shared across Languages; all adaptations must be applied to each selected language. Translated content must be applied separately.
{% endhint %}

<figure><img src="/files/taXeYPHlKSXoFztR4gdm" alt="" width="563"><figcaption></figcaption></figure>

#### Subject

The subject line of the email.

#### Sender Name

The name of the sender. This can be anything you want.

#### Sender Email

The email address of the sender. This does **not** need to be an existing email address, but the domain **does** need to point to your Lucy server.

{% hint style="info" %}
In order to avoid your server being blacklisted, it is **strongly** recommended that you do not use your admin domain to send attack emails or to host attack content.

For best results you should [register at least one attack domain](/guides/quick-guides/create-your-first-campaign/register-an-attack-domain).
{% endhint %}

#### **Content**

Choose "Editor Type" from the dropdown to select your preferred email editor.

{% tabs %}
{% tab title="Visual Editor" %}
The Visual Editor is a WYSIWYG interface, offering an easy way for users to create content as it will appear in its final form. With a straightforward toolbar, users can format text and add multimedia without coding knowledge.
{% endtab %}

{% tab title="Code Mirror" %}
The Code Mirror Editor is geared towards users with coding expertise. It provides a code-highlighting text editor for direct HTML and CSS manipulation, offering granular control over the content's appearance and structure.
{% endtab %}
{% endtabs %}

<details>

<summary>Email Variables</summary>

When creating email templates, you can personalize the content by using various placeholders that will be automatically replaced with specific user data when the email is sent. Below is an explanation of each variable available for use in the templates:

* `%link%`: This variable represents the base URL of your site. Use it to construct absolute URLs for navigation within your emails.
* `%user-password-reset%`: This placeholder is replaced with the unique URL for a password reset action.
* `%user-profile-link%`: Inserts a direct link to the user's profile page in the End User Portal.
* `%user-login-url%`: Provides a link to the End User Portal that utilizes SSO (OAuth 2.0) for login.
* `%name%`: The full name of the email recipient.
* `%firstname%`: The recipient's first name.
* `%lastname%`: The recipient's last name.
* `%email%`: The recipient's email address.
* `%client%`: The name of the client associated with the recipient.
* `%gender("MALE ADDRESSING", "FEMALE ADDRESSING", "NO GENDER")%`: This is a conditional variable that changes the greeting or addressing based on the recipient's gender.
* `%subject%`: The subject line of the phishing email.
* `%sender%`: The name of the sender of the phishing email.
* `%sender-email%`: The email address from which the phishing email is sent.
* `%started%`: The date when the related phishing campaign was started.
* `%stopped%`: The date when the related phishing campaign was stopped.
* `%time(FORMAT, OFFSET, ZONE)%`: A dynamic time variable where:
  * `FORMAT` refers to the format in which the date/time should be displayed.
  * `OFFSET` is the time offset from the mail send time, which can be positive or negative.
  * `ZONE` is the time zone to be applied.
  * Example: `%time("l, H:i", "0", "Europe/Zurich")%` would display the time of the email submission in the Europe/Zurich time zone.
  * Example: `%time("Y/m/d H:i:s", "60")%` would show a timestamp one hour ahead of the email submission time.

Note that these variables are intended for use in the HTML body of the email and are not applicable within CSS and Javascript files. They serve to customize the email content for each recipient and should be used accordingly to ensure a personalized user experience.

</details>

{% tabs %}
{% tab title="Attachments" %}
Add your own attachments. Keep in mind that most common email clients filter certain types of attachments, like executables, to prevent malware risks.
{% endtab %}

{% tab title="General Email Settings" %}
Set custom SMTP headers to meet specific needs. For example, you can add a custom email header to help your SPAM gateway distinguish between actual SPAM and emails sent from LUCY.
{% endtab %}

{% tab title="Advanced Email Settings" %}

* **Send emails as plain text.**
* **Random Email**:

  LUCY will generate a random email account with a random sender. The email account will be deleted after the campaign ends.

If you want to catch email replies from your awareness email, LUCY provides two options:

1. **Define a Reply-to Header**:
   * The Reply-to address is where email replies are directed, rather than the 'From' address. This is useful if the 'From' address cannot receive replies, for example, if you do not control the domain or lack a mail server setup for it. For instance, if the email shows as being sent from "<mitchel@guysfromrolla.com>" and the recipient clicks reply, the email will be directed to the Reply-to address set in the header, such as "<billg@microsoft.com>". Choose a Reply-to address you have access to.
2. **Define a Forward Mail**:
   * LUCY can forward incoming replies to a specified email address. This requires setting a [DNS entry (MX record)](/application-reference/settings/common-system-settings/domains#dns-records-explained) for the sender’s domain that points to LUCY. For example, if you send emails from "<attacker@phishing-test.com>" and LUCY's IP is 201.35.77.12, you need an MX record like "phishing-test.com MX 10 201.35.77.12". Enter your own custom mail address in the forward mail field (e.g., "<user@example.com>"). When someone replies to "<attacker@phishing-test.com>", LUCY receives the email and forwards it to "<user@example.com>". Note that many registration services offer free mail/DNS packages, allowing you to set up an email forwarder directly at the domain level, eliminating the need for LUCY’s forwarding feature.
     {% endtab %}

{% tab title="DKIM Support" %}
**DKIM Overview:**&#x20;

DomainKeys Identified Mail (DKIM) enhances email security by attaching a domain name identifier to a message, utilizing cryptographic techniques to validate authorization. This identifier is separate from other message identifiers such as the author's "From" field. DKIM effectively 'signs' emails to verify their origin, helping to identify and prevent spoofed emails. The process involves the sending mail server signing the email with a private key, while the receiving server uses a public key listed in the domain's DNS to verify the signature. Each domain can list multiple DKIM keys in its DNS, but each private key is unique to one mail server.

**Setting Up DKIM in LUCY:**

1. **Enable DKIM:**
   * Navigate to "Advanced Email Settings" in the message template of your Attack Scenario. Enable DKIM support and save the changes. A DKIM information box will then appear.
2. **DNS Configuration:**
   * Copy the provided key and create the corresponding DNS entry. Here’s an example of how to set it up with namecheap.com:

```
Name: selector._domainkey
Type: TXT
Value: "v=DKIM1; k=rsa; p=[YOUR_PUBLIC_KEY]"
```

**Validate DKIM Setup:**

* To confirm your DKIM is working, add an email from a service like [dkimvalidator.com](https://dkimvalidator.com/) to your DKIM test recipient group. Launch the campaign targeting this group, then check the results at dkimvalidator.com. If configured correctly, your setup should match the expected status.

**DKIM Header Details:** The DKIM signature is added to emails as an RFC2822 header field. Here's a breakdown of the common fields in a DKIM signature:

* **b:** Digital signature of the email's contents.
* **bh:** Hash of the email body.
* **d:** Signing domain.
* **s:** Selector used for the DKIM signature.
* **a:** Signing algorithm, typically rsa-sha1.
* **c:** Canonicalization algorithm for the header and body.
* **q:** Default query method, usually DNS.
* **t:** Timestamp of when the email was signed.
* **x:** Expiry time of the signature.
* **h:** List of header fields that were signed.

This setup ensures that emails sent through LUCY's mail server are authenticated, boosting trust and security for your email campaigns.
{% endtab %}
{% endtabs %}


# Sandbox Settings

Settings related to the user's network environment.

<figure><img src="/files/PXLURrzxzwVfjWzzLHkI" alt=""><figcaption></figcaption></figure>

#### AV/Firewall Protection Interval

Enable this setting to protect against false-positive clicks. Read about the protection interval [here](/guides/attack-simulations/firewall-protection-interval), and consider using the newer [filter settings](/application-reference/settings/common-system-settings/filter-settings) to block false-positives at the IP or User-Agent level.

#### Block All Clicks Within Protection Interval

By default, the protection inverval blocks only the **first** click in the interval. Enable this setting to ignore **all** clicks in the interval instead.


# Reminders

LUCY allows administrators to configure reminders within a campaign to ensure recipients engage with the content. This feature is particularly useful for reminding users who have not interacted with the campaign as expected.

{% hint style="info" %}
Starting in Lucy version 5.1, campaign reminder settings are included in [campaign templates.](/application-reference/templates/campaign-templates)
{% endhint %}

***

## Configuration

Reminder emails can be sent once or repetetively. You can configure a custom reminder message (ideal for attacks) or simply resend the original email (ideal for awareness).

#### Single Message

Select this option to send one reminder email N days after the original email.

#### Repetetive Message

Select this option to send a reminder email every N days after the original email.

#### Use Scenario or Awareness Email

Select this option to resend the original template email, rather than a custom reminder message.

{% hint style="success" %}
If you are using a custom reminder email, select **Edit Template** to customize it.
{% endhint %}

## Awareness Reminders

{% hint style="info" %}
Navitgate to **Awareness Education > Reminders**
{% endhint %}

<figure><img src="/files/KPuhLz4HDzDV93LWX1sj" alt=""><figcaption></figcaption></figure>

{% hint style="success" %}
In order to use the **Send Immediately** button you must save the reminder settings first.
{% endhint %}

### **Remind Users Who Did Not Start a Training**

Enable this option to send a reminder to users who did not start the training after receiving the awareness email. Lucy will send a reminder to anyone who did not click the training link.

### **Remind Users Who Did Not Finish a Training**

Enable this option to send a reminder to users who started but did not finish the training. Lucy will send a reminder to anyone who is not trained in the statistics.

## Attack Simulation Reminders

{% hint style="info" %}
Navigate to **Attack Simulation > Reminders**
{% endhint %}

<figure><img src="/files/Qki55GOpXsFDEp80Wh20" alt=""><figcaption></figcaption></figure>

{% hint style="success" %}
In order to use the **Send Immediately** button you must save the reminder settings first.
{% endhint %}

### **Remind Users Who Did Not Click a Phishing Scenario Link**

Enable this option to send a reminder to users who did not click on the link in the phishing email.

***

## Reminder Template Customization

To customize a reminder email, select **Edit Template** for the desired reminder type:

<figure><img src="/files/O3v92WWcX3azsDRyu5jL" alt=""><figcaption></figcaption></figure>

Select your language and configure the reminder email for the chosen language.

<figure><img src="/files/paVHZLkoCeAXdPL1QurN" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
Reminder templates are not automatically translated; each adaptation needs to be copied and translated into the relevant language.
{% endhint %}

Click **Save** to commit your reminder template.

<details>

<summary>Reminder Email Variables</summary>

You may use the following variables in the template:

* `%link%` — Unique page URL for the recipient.
* `%link-awareness%` — Link to the awareness website. You should configure and enable the awareness website in campaign settings for this feature to work.
* `%name%` — Recipient full name.
* `%firstname%` — Recipient first name.
* `%lastname%` — Recipient last name.
* `%email%` — Recipient email address.
* `%division%`, `%location%`, `%staff-type%`, `%comment%` — Recipient-related information.
* `%gender("MALE ADDRESSING", "FEMALE ADDRESSING", "NO GENDER")%` — Recipient gender.
* `%subject%` — Subject of the phishing email.
* `%sender%` — Sender name of the phishing email.
* `%sender-email%` — Email address of the phishing email.
* `%time(FORMAT, OFFSET, ZONE)%` — Time-based variables.
  * **FORMAT**: Date/time format.
  * **OFFSET**: Date/time offset in minutes, can be negative (e.g., "-60" means 60 minutes prior to email submission time, "20160" means 20160 minutes = 14 days).
  * **ZONE**: Time zone name (e.g., US/Central).

Examples:

* `%time("l, H:i", "0", "Europe/Zurich")%` — Outputs "Monday, 09:20" (exact time of email submission in Europe/Zurich zone).
* `%time("Y/m/d H:i:s", "60")%` — Outputs "2016/12/12 10:20:30" (1 hour ahead of email submission time).

Please note that these variables are not available in CSS and JavaScript files.

</details>


# Recipients

The Recipients tab allows you to add the desired [Recipient Groups](/application-reference/users/recipient-groups) to your campaign.

The recipient group consists of users who will receive the attack simulation or awareness content. You can create multiple groups for a single campaign. Recipients can belong to multiple groups, and you can set up an unlimited number of groups.

{% hint style="info" %}
Navigate to Main Settings **> Recipients**
{% endhint %}

<figure><img src="/files/pYFtMIpWJC8sOdjxpk0M" alt=""><figcaption></figcaption></figure>

***

## Add Group

Select **Add Group** to bind your first recipient group to the campaign, then select a group from the list or select **New Group** to create a group on-the-fly.

<figure><img src="/files/ZWJujTKqM9T2HtImKvTw" alt=""><figcaption></figcaption></figure>

***

## Group Settings

<figure><img src="/files/UdJHbKfVUoS0gMeLqBIi" alt=""><figcaption></figcaption></figure>

#### Group

The currently selected recipient group. Use this list to change groups.

#### Search

Search the current group by name, email, or phone, or by the staff, location, division, and comment columns.

#### Language

Set a default language for the group. This language is used as a fallback for any recipient that does not have a language set for them within the group.

## Recipient List

By default, **no recipients are selected**. Enable the checkbox next to a recipient to add them, or enable the **Select All** checkbox to add them all at once.

<figure><img src="/files/gSlZgjQDBJJwlW8JjiqK" alt=""><figcaption></figcaption></figure>

***

## Mapping

You can configure which email(s) the recipients will receive. Usually it is not necessary to change this setting.

<figure><img src="/files/U1FcYgmwFrDxx1Dz141y" alt="" width="538"><figcaption></figcaption></figure>

#### Campaign + Awareness

The recipients will receive both the attack and the training content (assuming they fail the attack).

#### Campaign

The recipients will receive only the attack simulation.

#### Awareness

The recipients will receive only the training content.

***

## Scenarios

The scenario association controls which group receives which attack simulation and/or training content. If you select two scenarios for a group, each user in that group will receive two emails (one from each scenario).

<figure><img src="/files/RbeJw5XBiMi3I4ohYO3y" alt=""><figcaption></figcaption></figure>

#### Distribute Users

If enabled, this setting will randomly assign users to the selected scenarios, ensuring each user receives a unique attack and no one gets the same scenario twice.

{% hint style="info" %}
For more detailed control over distribution, create a [schedule rule](/application-reference/campaigns/campaign-settings/optional-settings/schedule).
{% endhint %}

#### Suppress Duplicate Recipients

{% hint style="info" %}
This option is found in the **Settings** tab.
{% endhint %}

<figure><img src="/files/0lEeQqY7n6qUqZvBXsLC" alt=""><figcaption></figcaption></figure>

If enabled, Lucy will remove duplicate recipients across all the recipients groups in the campaign, leaving only one copy of the recipient in the first group in the list.

This will **not** delete the recipient from the group globally, only in the campaign.

If you disable this setting after enabling it, deleted recipients will **not** be re-added.


# Optional Settings


# Schedule

## Introduction

The **Scheduler** in Lucy allows you to create advanced, time-based attack and awareness campaigns that mimic real-world scenarios. It helps control email delivery rates, avoiding issues with recipient mail servers that may block or delay large batches of emails.

The Scheduler allows you to:

* Define specific rules for sending emails to targeted groups.
* Control delivery timing across days, hours, and even months.
* Ensure new recipients are automatically integrated into long-running campaigns

***

## Add Rule

The Scheduler is driven by **Rules**, and each Rule is defined by a **Rule Type**. The Rule Type determines how and when emails are sent, and what configuration options are available.

Select **+ Add Rule** in the top-right corner to add a new schedule rule.

<figure><img src="/files/TCvWcHXDPIzZuKkVwj3k" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
If a campaign has a schedule rule of any kind attached to it, no other emails will be sent except those included in the schedule. This includes emails for recipients not attached to any schedule rule.
{% endhint %}

***

## Rule Types

{% hint style="info" %}
The Scheduler is governed by its Rules, and these Rules are governed by the Rule Type.
{% endhint %}

The rule type dictates the parameters that can be configured, determining the conditions and actions that the Scheduler can execute.

<figure><img src="/files/Dy8l3vxkIFMX3ynEsHFS" alt="" width="516"><figcaption></figcaption></figure>

{% tabs %}
{% tab title="One-Shot" %}
Sends a single batch of emails at a specified time.

**Use Cases:**

* Immediate phishing simulations.
* Policy rollouts or training reminders.
* Incident-based awareness campaigns.
  {% endtab %}

{% tab title="Repeating" %}
Sends emails at a defined interval (e.g., daily, weekly). Recipients receive one email per cycle from selected scenarios.

**Email Distribution Options:**

* **Uniform:** Each recipient gets the same email each cycle.
* **Randomized:** Recipients receive different emails each cycle.

**Additional Parameters:**

* **Repeat Interval:** Frequency (daily, weekly, monthly).
* **Repeats:** How many times to repeat.
* **Start/Stop Hour:** Time window for daily delivery.
* **Run Days:** Specific days to send emails (for weekly/monthly intervals).

**Best For:** Long-term simulations where message randomization prevents internal warnings among employees.
{% endtab %}

{% tab title="Yearly" %}
Runs a structured campaign across 12 months, ideal for onboarding or long-term education.

**How It Works:**

* Recipients are automatically enrolled.
* Campaign starts the *month after* the rule is created.
* Email delivery timing within each month can be customized.

**Monthly Scheduling Options:**

* **Entire Month:** Randomly throughout.
* **Start of Month:** 1st–9th.
* **Middle of Month:** 10th–20th.
* **End of Month:** 21st–last day.

**Visual Planner:** Drag and drop attack/awareness scenarios to each month in the yearly timeline.

<figure><img src="/files/cLH3gIky0lZmS8qq88Bl" alt=""><figcaption></figcaption></figure>
{% endtab %}
{% endtabs %}

***

## **Email Type**

{% hint style="success" %}
Applies to: **One-Shot, Repeating**
{% endhint %}

Specifies the nature of the emails to be sent.

<figure><img src="/files/VmoX3nvdLKYfiRdDn6ju" alt="" width="563"><figcaption></figcaption></figure>

* **All:** Includes all types of emails.
* **Lure:** Emails designed to entice recipients into a phishing simulation.
* **Attack:** Emails that simulate a cyber attack.
* **Awareness:** Emails designed to educate recipients on security awareness.

***

## **Time Zone**

{% hint style="success" %}
Applies to: **All Rule Types**
{% endhint %}

Set the time zone for your campaign to ensure emails arrive during local business hours, increasing engagement.

***

## **Start Date / Stop Date**

{% hint style="success" %}
Applies to: **One-Shot, Repeating**
{% endhint %}

* **Start Date** *(One-Shot, Repeating)*: Define when the campaign begins (e.g., `19.05.2024 11:10`).
* **Stop Date** *(One-Shot only)*: Define when the campaign ends (e.g., `19.05.2024 12:10`).

{% hint style="info" %}
Use the **Schedule Calculator** to fine-tune these dates.
{% endhint %}

<details>

<summary>Schedule Calculator Explained</summary>

The "Schedule Calculator" is a valuable tool for Administrators to define the sending rate of emails in a campaign, particularly important when sending hundreds of simulated emails which can potentially overload receiving mail servers.&#x20;

This feature allows for setting a delay in the sending rate to prevent overloading of servers and to ensure compliance with mail-sending rate policies. For instance, for O365-based (receiving) mail servers, a recommended sending rate from Lucy is no more than 30 emails per minute. This adjustment helps ensure that your emails sent from Lucy are delivered efficiently without triggering spam filters or blocking by receiving mail servers.

</details>

***

## **Update Schedule Plan for New Recipients**

{% hint style="success" %}
Applies to: **All rule types**
{% endhint %}

Automatically update the schedule plan for new recipients added to the group—even after campaign launch.

**Use Case:** Onboarding new hires from LDAP or Entra ID syncs.

***

## **Do Not Send Emails on Certain Days of the Week**

{% hint style="success" %}
Applies to: **All rule types**
{% endhint %}

Prevent emails from being sent on specific days (e.g., weekends).

**Example:** Uncheck Saturday and Sunday to reflect typical business communication patterns.

<figure><img src="/files/vsbW0tWSEavpIkoRTPOv" alt="" width="443"><figcaption></figcaption></figure>

***

## **Sort Type**

{% hint style="success" %}
Applies to: **One-Shot, Repeating**
{% endhint %}

Controls how emails are ordered during delivery.

| Type             | Description                             |
| ---------------- | --------------------------------------- |
| **By Recipient** | Emails sent in completely random order. |
| **By Scenario**  | Emails sent by scenario group.          |

***

## Scenario & Recipient Selection

* **Scenarios:** Select the phishing or awareness scenarios for this rule.
* **Recipient Groups:** Choose which users will receive these emails.

***

## Create A Schedule Plan

Once all configurations are complete, click **Save** to build a [Schedule Plan](/application-reference/campaigns/campaign-settings/optional-settings/schedule/schedule-plan) based on your rule.


# Schedule Plan

## Details

The schedule plan is the output of all rules configured for your campaign.&#x20;

<figure><img src="/files/audNyBcKHsf0CixWEFrL" alt=""><figcaption></figcaption></figure>

#### Time

When the email is scheduled to be sent.

#### Email

The Email address of the recipient (not supported for anonymous campaigns).

#### Scenario

The specific attack or awareness scenario associated with the email.

#### Processed

The status email; pending, sent, or error.

***

## Rebuild Plan

This button is necessary if any modifications are made to an existing rule. Rebuilding the schedule plan ensures that all changes are reflected accurately, updating the schedule to align with the new configurations.

{% hint style="info" %}
Rebuilding a plan will not send emails to already processed recipients, ensuring that modifications can be made to a rule without compromising the integrity of the campaign.
{% endhint %}

***

## FAQ

<details>

<summary>What is the best practice for adding rules and validating the Schedule Plan?</summary>

Start with a controlled or small recipient group to familiarize yourself with the rule outputs. Add only one rule at a time, then validate the Plan to ensure the emails will be sent according to your goals.&#x20;

Once you are confident, simply adjust the rule by adding all additional recipient groups and rebuild the scheduling plan. This approach allows for careful testing and refinement before scaling up to the full campaign.

</details>

<details>

<summary>No emails are sent after the Schedule Rule is saved</summary>

* Did you start the campaign after setting the scheduler? Please note that configuring the scheduler alone won't initiate email delivery. The campaign needs to be explicitly started to begin sending emails. Ensure that you have activated the campaign after setting up the scheduler to initiate the mail delivery.
* Did you start the campaign after the Schedule Rule Start time? Schedule Rules can not be initiated if the start time is in the past.
* If you are using the scheduler to trigger smishing campaigns, make sure your license has enough credits and is not outdated. You can check your license status and credits in the [License tab](/application-reference/account-settings).
* Make sure your Lucy server [**time** & **time zone**](/application-reference/settings/advanced-system-settings/advanced-settings#date-time-settings) are both correct.
* Apply the latest patches by [updating your Lucy server to the latest version](/application-reference/support/update).

</details>


# Report Configurations

When the campaign ends, Lucy can automatically generate a report and send it to the campaign admin.

<figure><img src="/files/oNj3ROshnmS6EcUsXmOF" alt=""><figcaption></figcaption></figure>


# Tracking & Anonymity

### Track Bounced Emails

Determine which recipients did not actually receive the email, such as those with 'out of office' or bounced email responses.

### Interval Email Testing

Enhance the reliability of your campaign by scheduling periodic email tests. This involves sending emails to a predefined address at set intervals to verify ongoing mail delivery success. This helps track and ensure the health of your campaign's email system.

<figure><img src="/files/keudalAAEfBVKkbqvjN7" alt=""><figcaption></figcaption></figure>

### Anonymous Mode

Use this mode to conceal all victim data from statistics and reports, ensuring privacy and anonymity in the data handling process. Please be aware that once this operation is performed, it cannot be undone. This permanent setting is crucial for campaigns where confidentiality is a priority.

### Anonymous Visibility

Statistics will be invisible if a division or department or number of recipient in the group is less than this value. Active when anonymous mode is enabled.

<figure><img src="/files/6f0UettlTXDqYg55AfLO" alt=""><figcaption></figcaption></figure>


# Advanced Settings

## Filter Settings

Filters can be pre-defined and updated in the [Response Filte](/application-reference/settings/common-system-settings/filter-settings)[rs ](/application-reference/settings/common-system-settings/filter-settings)section of the platform to enable quick filter selection in campaigns.

## User Settings

User Settings allow you to add an [Administrative User](/application-reference/users/administrative-users) with the **User** role to a campaign. This is ideal for including stakeholders in the campaign, ensuring they are bound by their respective [client](/application-reference/settings/clients) for data isolation and are given only the necessary permissions to view or make minor changes to the campaign configuration.

{% hint style="success" %}
Administrative users with **Access All Campaigns** will automatically have access to campaigns for their client.
{% endhint %}

### Adding Users

Select **Add User** to add a User to your campaign.

<figure><img src="/files/skrgTziTyJgHwBOk73gP" alt=""><figcaption></figcaption></figure>

### User Permissions

| Permission                                    | Description                                                   |
| --------------------------------------------- | ------------------------------------------------------------- |
| Start/Stop Campaign                           | Start and stop the campaign.                                  |
| Configure Campaign Settings                   | Configure campaign settings.                                  |
| Delete Campaign                               | Delete the campaign                                           |
| Edit Recipients                               | Edit the recipient list(s)                                    |
| Edit Awareness Website                        | Edit the awareness content                                    |
| Edit Schedule                                 | Edit the email schedule                                       |
| Edit Base Scenario Settings                   | Edit the Base scenario settings                               |
| Edit Scenario (Settings/Landing Page/Message) | Edit the settings for each scenario                           |
| Reports (Create/View)                         | Create and download reports                                   |
| Export (File/Group)                           | Export recipients and data                                    |
| Campaign Statistics (Full/Base)               | View individual (full) and/or aggregate (base) campaign stats |
| Reset Stats                                   | Reset campaign stats                                          |
| Message Log                                   | View the campaign email log                                   |
| Supervision Log                               | View the campaign supervision log                             |
| Reminders                                     | Edit/configure reminders                                      |
| Responses                                     | View/manage campaign responses                                |

***

## Custom Fields

Beyond the common statistical data in LUCY, such as link clicks and submitted form data, you might want to track additional custom statistics from a live campaign. These custom statistics can provide deeper insights into user behavior and response to phishing campaigns.

{% hint style="info" %}
Custom Statistics require per-recipient manual intervention, making them ideal for manually tracking specific statistics that do not apply to the general group.
{% endhint %}

#### Examples of custom statistics

* CERT (Computer Emergency Response Team) responses from users.
* Users who replied to the attacker.
* Users who participated in security training programs prior to the phishing campaign.

### Adding Custom Fields

Select **Add** to add a custom field to your campaign.

<figure><img src="/files/2bUcaXhgz4u1gnEsrt1C" alt=""><figcaption></figcaption></figure>

### **Tracking Custom Field Statistics**

Custom statistics must be tracked manually:

* **Go to Campaign Statistics**
  * &#x20;**Campaign Name** → **Statistics** → **Recipients**
* **Select Recipients**
  * Choose the recipient(s) who "Completed Office Security Webinar".
* **Activate Custom Fields**
  * The custom field(s) will appear as a checkbox next to the recipient's information. Activate the checkbox for  "Completed Office Security Webinar".

<figure><img src="/files/NHGgtllYsaYglOrRQA2z" alt=""><figcaption></figcaption></figure>

***

## Campaign List Settings

These settings control how the campaign appears and behaves in the campaign dashboard.

<figure><img src="/files/ngkbBRBY7qa0s76Wz0qN" alt=""><figcaption></figcaption></figure>


# Starting a Campaign

## How to Start a Campaign

Once you have finished configuring the campaign, select **START** to initiate the campaign checks.

<figure><img src="/files/FjUqPJpwc0U3fZxE5GpC" alt=""><figcaption></figcaption></figure>

### Start Options

#### Start

This option initiates the attack or awareness campaign. After pressing "START," LUCY will send emails to your recipient group(s).

#### Restart

This option resets the campaign statistics and resends the emails to the recipient group.&#x20;

{% hint style="danger" %}
Note that all data will be lost and cannot be restored. Use "START" to resume an existing campaign without losing data.
{% endhint %}

#### Resume

Use this option for a campaign that has been started and stopped before. Emails won't be resent; only the webpage will restart, and the same distributed links will become available again. To resend all the emails, use the "RESTART" button.&#x20;

If new scenarios are added to an existing campaign and you click "START," only the emails for the new scenarios will be sent, and the initial scenario will resume.&#x20;

{% hint style="info" %}
During the time a campaign is stopped, the landing pages will be inaccessible, displaying a customizable error message. Once resumed, all links will work again.
{% endhint %}

#### Test Run

This option runs a live campaign in test mode using the admin user's email address for the test run. After the test run is stopped, all test data is removed from the system.

***

## Campaign Checks

{% hint style="success" %}
Always perform a test run with a few users before launching a campaign.&#x20;
{% endhint %}

Lucy runs various checks before starting the campaign to ensure the configuration works as expected. The test may take a few minutes. Examples of these tests include:

* **DNS**: Query SPF entry, query MX entry
* **SMTP**: Send a test email to a random Mailinator account with an anonymous hash value that is deleted via API after the test
* **HTTP/S**: Make an HTTP/HTTPS GET request to the configured IP/DNS name to verify if the URL is reachable from the internet

<figure><img src="/files/WHFVqVS9QV87slgKcRlj" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Lucy will attempt to connect to the internet during these tests.
{% endhint %}

### Errors and Warnings

If any of the checks identify a critical error, the check will highlight in red and the campaign will not be allowed to start. Warnings are highlighted in yellow. For any error or warning, select the text of the campaign check to view more information about the issue.

<figure><img src="/files/tug0mUWpyJK3AUBSDtXZ" alt=""><figcaption></figcaption></figure>

***

## How do I Edit a Running Campaign?

Campaigns in LUCY are dynamic. If you need to make changes to a landing page, you can do so while the campaign is running. All recipient links will remain valid, and the content will be updated for all recipients accessing the links.\
\
If you select **STOP**, the awareness or phishing website will not be reachable while the campaign is stopped. When you **RESUME** the campaign again, LUCY will resume it from where it was stopped, and all statistics will remain the same.


# Logs

Campaign logging in Lucy provides detailed records of various activities within your campaigns. There are three main types of logs: Supervisor Log, Message Log, and Error Log.

## Supervisor Log

The approval workflow is based on the 4-eyes principle for creating a new campaign. A campaign administrator creates a phishing or e-learning campaign but can only start it after a different user (the supervisor) reviews and approves it. If the supervisor rejects the campaign, a ticket with an expiry date will be created for the administrator.

#### **Campaign Launch Process**

When the campaign admin logs in under their "user" role and starts the campaign, it will be put on hold until the supervisor approves the launch. A new entry will be created in the "Supervision Log". The campaign dashboard will show a small turning wheel indicating that the campaign is waiting for approval.

***

## Message Log

The Message Log is a record of all messages that have been successfully transmitted by the campaign. The log contains the timestamp, recipient info, and message type of the email.

<figure><img src="/files/Ti864FNC7IOJJO9djDkM" alt=""><figcaption></figcaption></figure>

***

## Error Log

The Error Log records any issues or errors that occur during the campaign execution. This log is crucial for troubleshooting and resolving any problems that may arise.


# Results


# Summary

### Campaign **Dashboard Overview**

The Campaign Dashboard provides a comprehensive overview of campaign statistics and actions, offering administrators immediate access to essential information and metrics.&#x20;

### **Status and Controls**

<figure><img src="/files/4ehKnRSYimNU8RI43YiU" alt=""><figcaption></figcaption></figure>

At the top, the dashboard displays the current status of the campaign (e.g., Running), the total running time, and the campaign creator's details. Administrators have the option to perform actions or export data from this area.

<table data-view="cards"><thead><tr><th></th><th></th><th></th></tr></thead><tbody><tr><td><strong>Actions</strong></td><td></td><td>Global campaign actions to reset all statistics, generate an <a href="/pages/K74npEXgHWzSw6z8bsbB">exucitive report</a> and saving the <a href="/pages/hRZUEwsB4FHo4xpl6wFD">campaign as a template</a>.</td></tr><tr><td><strong>Export</strong></td><td></td><td><a href="/pages/LjasOAk97x5aKwJAoMaG">Exports</a> encompass all recipient statistics, offering an in-depth look at campaign-related interactions and behaviors.</td></tr><tr><td><strong>Start</strong></td><td></td><td>This feature allows you to start, stop, restart, resume, or conduct a trial execution of your campaign. All relevant <a href="/pages/FZCziDs9JLdZkFFw1Zrq">campaign checks</a> are done prior to the launch of the cmapaign. </td></tr></tbody></table>

### **Campaign Overview**

The campaign dashboard dynamically adjusts to display relevant metrics for Attack only, combined Attack and Awareness, or exclusive Awareness campaigns, reflecting the specific statistics related to the campaign type.

{% tabs %}
{% tab title="Attack Only" %}

<figure><img src="/files/tMxf68sY0KJUNqqVwAPX" alt="" width="563"><figcaption></figcaption></figure>

**Attack Overview Section**:

* **Sent**: Shows the total number of emails sent and the percentage delivered.
* **Clicked**: Displays the count and percentage of recipients who clicked on a link in the email.
* **Successful Attacks**: Indicates the number and percentage of recipients who fell for the phishing attack.
* **Vulnerable Victims**: Reflects the count and percentage of recipients who are considered to have vulnerabilities for their browser version.
* **Errors**: Notes any errors that occurred during the Attack email distribution.

**Click and Report Action Summary**:

* **Total Emails**: The total number of emails involved in the campaign.
* **Clicked and Reported**: The number of recipients who both clicked the phishing link and reported the email.
* **No Click and Reported**: The number of recipients who did not click on any link but reported the email.
* **Message Bounced**: Indicates how many emails were not delivered successfully.
* **Clicked and Not Reported**: The number of recipients who clicked but did not report the phishing email.
* **No Click and No Report**: The number of recipients who neither clicked on the phishing link nor reported the email.

**Timeline Section**:

<figure><img src="/files/4jQ1REHx4IFunOMaHHZX" alt=""><figcaption></figcaption></figure>

* **Campaign Creation**: The exact date and time when the campaign was created.
* **Scenario Added**: Shows when a scenario was added to the campaign, with date and time.
* **Awareness Added**: Indicates the date and time when awareness training content was added to the campaign.
* **Recipient Group Added**: Displays the addition of recipient groups to the campaign, along with the timestamp.
* **Campaign Sent**: Reflects when the campaign was initiated, with the corresponding date and time.
  {% endtab %}

{% tab title="Awareness Only" %}

<figure><img src="/files/64xZdevKI1tA0ywZAVFp" alt="" width="563"><figcaption></figcaption></figure>

**TRAINING OVERVIEW**:

* **Sent**: Tracks the number of training emails sent and their delivery success rate.
* **Clicked**: Monitors recipient engagement by recording clicks on the link in the training email.
* **Errors**: Notes any errors that occurred during the training email distribution.
* **Template Feedback Score**: Reflects recipient feedback on the training content, this allows the administrator to short list training or make modifications based on recipient feedback.

{% hint style="info" %}
Template feedback can be disabled in [Advanced Settings](/application-reference/settings/advanced-system-settings/advanced-settings#template-rating)
{% endhint %}

**AWARENESS**:

<figure><img src="/files/oX8oCAeOecXvgs6deW07" alt="" width="465"><figcaption></figcaption></figure>

This section features a concentric circle graph indicating the percentage of training completion, emails opened, and training content sent.

* **Training Score**: The average score recipients achieved in the awareness training.
* **Opened**: The percentage of recipients who opened the awareness emails.
* **Sent**: The delivery rate of the awareness emails to recipients.

**CLICK AND REPORT ACTION SUMMARY**:

<figure><img src="/files/RoUXxb7N8Yy2Fg8uBNyx" alt="" width="563"><figcaption></figcaption></figure>

* **Total Emails**: The total count of emails distributed in the campaign.
* **Clicked and Reported**: Number of recipients who clicked on the training content and reported it.
* **No Click and Reported**: Tracks recipients who did not click but still reported the email.
* **Message Bounced**: Counts undelivered emails that bounced back.
* **Clicked and Not Reported**: Indicates how many recipients clicked on the content but did not report it.
* **No Click and No Report**: Notes recipients who neither clicked on the link nor reported the email.

**TIMELINE**:

<figure><img src="/files/cZQqGlu46oRpzl8NYLJm" alt="" width="563"><figcaption></figcaption></figure>

* Displays a chronological list of key campaign actions including when the campaign was created, scenarios added, awareness content added, recipient groups added, and when the campaign was sent out.
* Each entry in the timeline includes the date, time, and user responsible for the action.
  {% endtab %}

{% tab title="Attack and Awareness" %}

<figure><img src="/files/Vf3Im1XbKE9YhRmIGebQ" alt="" width="461"><figcaption></figcaption></figure>

**ATTACK OVERVIEW**:

* **Sent**: Displays the number and percentage of emails sent in the campaign.
* **Clicked**: Shows the number and percentage of recipients who clicked on the email link.
* **Successful Attacks**: Indicates the number and percentage of recipients who completed the desired action in the attack.
* **Vulnerable Victims**: Reflects the number and percentage of recipients identified as susceptible.
* **Errors**: Records the number and percentage of any errors encountered during the attack phase.

**AWARENESS**:

<figure><img src="/files/paKH0zwybAVpR5f9h3zJ" alt="" width="465"><figcaption></figcaption></figure>

* The circular graph depicts the percentage of awareness emails sent, opened, and the training score.
* **Training Score**: Percentage of how well recipients performed in awareness training.
* **Opened**: The percentage of recipients who opened the awareness emails.
* **Sent**: The success rate of awareness emails reaching the recipients.

**CLICK AND REPORT ACTION SUMMARY**:

<figure><img src="/files/b9NcVRZnyZ7xRjyxr2tt" alt="" width="563"><figcaption></figcaption></figure>

* **Total Emails**: The count of emails involved in the campaign.
* **Clicked and Reported**: The number of recipients who both clicked on the link and reported the email.
* **Clicked and Not Reported**: Tracks recipients who clicked the link but did not report the email.
* **No Click and No Report**: Counts recipients who neither clicked on any links nor reported the email.
* **Message Bounced**: The number of emails that failed to deliver.

**TIMELINE**:

<figure><img src="/files/5ytxVPCnGvglE6fsxVf1" alt="" width="563"><figcaption></figcaption></figure>

* A chronological display of campaign milestones such as campaign creation, scenario addition, awareness content addition, recipient group inclusion, and campaign launch, complete with timestamps and responsible user IDs.
  {% endtab %}
  {% endtabs %}


# Statistics

### Introduction

This section provides comprehensive statistical data for the campaign, offering a dashboard that presents an at-a-glance overview of campaign performance, details of data gathered during attack simulations, access to individual recipient metrics, and tools for comparing campaign outcomes and analyzing recipient data across multiple campaigns.

<figure><img src="/files/aI5Vz7J3PpEsyLU8yuxX" alt="" width="185"><figcaption></figcaption></figure>

***

### Campaign Overview

The campaign overview presents administrators with key performance metrics at a glance, offering a concise summary of events and interactions throughout the campaign's duration.

{% tabs %}
{% tab title="Total Stats" %}
**Interpreting Total Stats**:

In the "Total Stats" subsection, examine the key performance indicators:

<figure><img src="/files/cuak7hAwxC7nsfkQhnbZ" alt="" width="563"><figcaption></figcaption></figure>

* **Sent**: This shows the total number of phishing/awareness emails/SMS messages sent and their delivery rate as a percentage.
* **Clicked**: Review the rate at which the links within the emails were clicked.
* **Report**: This metric shows the percentage of recipients who reported the phishing attempt.
* **Trained**: Indicates the percentage of recipients who completed the assigned Awareness training.

**Analyzing Graphical Data Representations**:

Below the statistics, refer to the bar charts for a graphical representation of the metrics.&#x20;

**TOTAL STATS**:

<figure><img src="/files/XqqaMBwr5mvgvTzELsF7" alt="" width="563"><figcaption></figcaption></figure>

* **Sent**: Number of emails dispatched in the campaign.
* **Clicks**: Frequency of recipients clicking on links within emails.
* **Successful Attacks**: Instances where the attack met its intended success outcome.
* **Reported**: Times the email was identified and reported as an attack by recipients.
* **Invalid Submits**: Count of submissions that were not completed successfully.
* **Vulnerable Victims**: Reflects the count of recipients who are considered to have vulnerabilities in their browser version.
* **Replied**: Responses received to the sent emails.
* **Bounced**: Emails that were not delivered to the recipient's inbox.
* **Out of Office**: Automated responses indicating the recipient is not available.

**SCENARIO STATS**:

<figure><img src="/files/Gn0bzgHdFnWRJbgKECG3" alt="" width="563"><figcaption></figcaption></figure>

* **Sent** (Blue bar): Emails sent for a specific scenario.
* **Clicks** (Green bar): Number of clicks recorded in a scenario.
* **Success** (Yellow bar): The success rate of the scenario in question.

{% hint style="info" %}
Hover over each bar to get detailed figures for the respective category, if the feature is supported.
{% endhint %}
{% endtab %}

{% tab title="Technical Stats" %}
**Interpreting Technical Stats**:

Technical stats can help administrators understand the technical landscape of their campaign recipients, potentially informing future campaign design and technical considerations.

<figure><img src="/files/v0liYJQ1XaNOFlMO6BVe" alt="" width="563"><figcaption></figcaption></figure>

**Operating Systems (OS)**:

* Lists the variety of operating systems detected in the campaign, such as Windows 8.1, ME, XP, NT 4.0, and others, along with the year of release.
* Displays a count next to each OS, indicating the number of hits or interactions from devices using that system.

**Browsers**:

* Browsers used by the recipients, like Opera, Maxthon, SeaMonkey, and Internet Explorer, and shows the version numbers.
* Each browser entry is accompanied by a count reflecting its usage among campaign targets.

**Graphical Representations**:

<figure><img src="/files/s1mImMjOphhk0BULNbnO" alt="" width="425"><figcaption></figcaption></figure>

* Includes radial charts for both operating systems and browsers, illustrating the distribution of user interactions by OS and browser type.
* Provides a visual comparison of the spread and diversity of operating systems and browsers engaged in the campaign.

<figure><img src="/files/JPazcnaDYLKvetz3qzm5" alt="" width="407"><figcaption></figcaption></figure>

**Extended Analysis**:

* Provides deeper technical insights into the technologies used by recipients, including scripting languages, multimedia platforms, communication protocols, and location services.
* Lists specific technologies such as VBScript, Silverlight, WebSockets, WebRTC, ActiveX, and Geolocation, offering a nuanced view of the recipient's technical environment.
  {% endtab %}

{% tab title="Time" %}
Time-based visualizations aid administrators in monitoring campaign progress and identifying peak times of engagement or vulnerability, essential for real-time adjustments and post-campaign analysis.

<figure><img src="/files/VDoCffBZgbZvYgAQAa2z" alt="" width="563"><figcaption></figcaption></figure>

**Daily Stats**:

<figure><img src="/files/k1QqZNqlKqysoo4lfriG" alt="" width="563"><figcaption></figcaption></figure>

* Tracks and graphs campaign interactions over time, including page views, link clicks, successful attacks, and invalid submissions.
* Enables users to select a date range to focus on specific days of a campaign for detailed daily analysis.

**Clicks and Incidents in First 8 Hours**:

<figure><img src="/files/EGCefz4mK7WH7PlpuuuF" alt="" width="563"><figcaption></figcaption></figure>

* Displays a timeline of clicks and reported incidents within the first 8 hours post-campaign launch, crucial for understanding initial recipient reactions.

**Hourly Stats**:

<figure><img src="/files/4wsplYPuNbJ51O0Rx21J" alt="" width="563"><figcaption></figcaption></figure>

* Offers an hour-by-hour breakdown of campaign metrics, such as page views, link clicks, successful attacks, and invalid submissions, providing insight into engagement patterns throughout the day.
  {% endtab %}

{% tab title="Categories" %}
Categorical statistics help administrators identify trends and focus areas within different segments of the organization, enabling targeted follow-up and tailored security awareness initiatives.

**Custom Fields**:

<figure><img src="/files/nS8rbI94fFLrFplGvAg3" alt="" width="563"><figcaption></figcaption></figure>

* Displays bar graphs for customized data fields, quantifying recipient responses or behaviors, with counts for each category.

**Staff Type Stats**:

<figure><img src="/files/grAzao8MIdXwjjqQXLve" alt="" width="552"><figcaption></figcaption></figure>

* Provides a horizontal bar chart breaking down engagement by staff type, such as Electricians, Management, HR, etc., to gauge response rates across different staff roles within the organization.

**Location Stats**:

<figure><img src="/files/24MWXswd8BavrPPa72JD" alt="" width="533"><figcaption></figcaption></figure>

* Presents a horizontal bar chart detailing the distribution of interactions by geographic location, indicating where recipients are most active or susceptible.

**Division Stats**:

<figure><img src="/files/gcl6B4tr4qPIIaPASVMH" alt="" width="529"><figcaption></figcaption></figure>

* Shows a horizontal bar chart categorizing recipient actions by division allowing for an analysis of campaign impact on various organizational sectors.
  {% endtab %}

{% tab title="Events" %}
In the Events tab, administrators can monitor engagement with LUCY awareness videos through comprehensive event tracking. The system logs when a video is started, marking a "video-start" event, and upon completion, it records a "video-finish" event. Additionally, progress is tracked and displayed as rounded percentages, categorizing viewer engagement into segments such as "video-10" for 10% watched, progressing up to "video-90" for 90% and beyond.&#x20;

<figure><img src="/files/pjGjRi6EwxjQRvv4mU8w" alt="" width="563"><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Countries" %}
This section is designed to help administrators understand geographical trends in campaign interaction and identify areas with higher or lower engagement levels.

<figure><img src="/files/CZX8oU1Wd4dOR8UMVMwl" alt=""><figcaption></figcaption></figure>

**Global Interaction Map**:

<figure><img src="/files/kTwt9Kc3L3AAtzGfaACb" alt="" width="424"><figcaption></figcaption></figure>

* A world map highlighting recipient interaction levels, offering visual insights into global engagement with the campaign.

**Country-Specific Statistics**:

A detailed table listing countries with corresponding metrics such as:

* **Clicks**: The number of times links were clicked within each country.
* **Success**: Instances of successful phishing simulations.
* **Reported Phishing**: The number of reports from users recognizing the phishing attempt.
* **Custom Fields**: Data columns representing additional custom metrics tailored to the campaign.
  {% endtab %}

{% tab title="Risk Distribution" %}
Risk distribution helps identify high-risk groups and individuals within the organization, which can help in tailoring specific training programs.

<figure><img src="/files/a7ccMvRBBpnS8vgu6kvd" alt="" width="563"><figcaption></figcaption></figure>

{% hint style="info" %}
The Risk Rating for each recipient starts at 100% and takes all previous campaigns into account, this rating is reflective of each recipient's overall susceptibility to phishing simulations.\
\
Risk Rating is reduced proportionally based on their interaction with phishing simulations; for instance, if a recipient falls for 1 out of 4 simulations, their rating would drop by 25%, resulting in a 75% Risk Rating.
{% endhint %}

**Worst Employees**:

<figure><img src="/files/xX7p975AyZVP9u8N6Ixz" alt=""><figcaption></figcaption></figure>

* Lists individual emails alongside the number of scenarios they were involved in, the count of successful attacks, if they reported the attack, their training status, and an overall risk rating percentage.

**Worst by Staff Type**:

<figure><img src="/files/6QxCAiiq4L4n5oUH3P7Z" alt="" width="159"><figcaption></figcaption></figure>

* Ranks staff types by risk rating, providing a percentage that indicates susceptibility to the simulated attacks.

**Worst by Field: Location**:

<figure><img src="/files/v5P8sZ9Df2uKlfQoJeAt" alt="" width="178"><figcaption></figcaption></figure>

* Displays locations with their corresponding risk ratings, identifying areas with higher susceptibility to phishing attacks.

**Worst by Division**:

<figure><img src="/files/bJyLfV9uSzet1wAiVaa6" alt="" width="174"><figcaption></figcaption></figure>

* Shows divisions within the organization ranked by their risk rating percentages, highlighting divisions that may require additional security awareness training.

{% hint style="warning" %}
A lower Risk Rating reflects poorer performance, indicating a higher susceptibility to phishing among recipients, groups, divisions, locations, or staff categories.
{% endhint %}
{% endtab %}

{% tab title="Awareness Website" %}
In the "Awareness Website" tab, administrators can access a variety of metrics providing insight into the interaction with awareness training content.

{% hint style="info" %}
The Awareness Website tab will only be displayed in campaigns with awareness training.
{% endhint %}

Metrics at the top indicate the number of awareness emails sent, opened, and the completion rate, along with the average score achieved by recipients.

<figure><img src="/files/ZaY770eHrHF5hB6DTLZl" alt="" width="563"><figcaption></figcaption></figure>

The "Awareness Website Stats" chart shows the number of visits over a selectable time period, offering a view of user engagement over time.

<figure><img src="/files/qgfomsnUM8lBWwMk7VRG" alt="" width="563"><figcaption></figcaption></figure>

"Awareness Website Click Stats" bar graph illustrates the number of clicks versus not clicked, highlighting whether the recipient clicked the link to go to the training content.

<figure><img src="/files/Wyp0WISzDXoCa3QrHGw3" alt="" width="563"><figcaption></figcaption></figure>

The "Quiz Scores Distribution" graph displays user performance across different score ranges, allowing administrators to gauge the overall effectiveness of the training.

<figure><img src="/files/xlinmbJKtBJIjJMMUB8c" alt="" width="563"><figcaption></figcaption></figure>

"Quiz Correct Answers Percent" showcases the percentage of correct responses to each quiz question, indicating areas where recipients may need further education.

<figure><img src="/files/UiwtjnhXohNnLMjUuSO6" alt="" width="563"><figcaption></figcaption></figure>

"Quiz Average Answer Time" presents the time taken to answer each question, providing insight into question difficulty or recipient uncertainty.

<figure><img src="/files/wsmOv6oTJt2Ly4p4NH3q" alt="" width="563"><figcaption></figcaption></figure>

Two additional bar charts detail the average time spent per awareness training and per page, reflecting engagement depth and content complexity.

<figure><img src="/files/XZftpbDOyLp9AL4i41Pd" alt="" width="563"><figcaption></figcaption></figure>
{% endtab %}
{% endtabs %}

***

### Collected Data

Collected data encompasses information gathered from web-based phishing simulations, including credentials entered on a fake login page or data transmitted to LUCY from simulated document macros activated by users.

<figure><img src="/files/qC9yTV3qDCG1wn60s9pQ" alt=""><figcaption></figcaption></figure>

Each entry will be listed below. To view the collected data, select 'Click to View.'

<figure><img src="/files/z1pZh9p4wnP4qXOt1MMa" alt="" width="297"><figcaption></figcaption></figure>

{% hint style="warning" %}
Lucy collects only partial data to comply with data regulations, revealing the first three characters of usernames and passwords.
{% endhint %}

{% tabs %}
{% tab title="Type" %}
This dropdown allows users to filter the displayed data based on the category it falls under.

<figure><img src="/files/Y00isntidfQqroRt8vlh" alt="" width="223"><figcaption></figcaption></figure>

* **All**: Displays all types of collected data without any filters.
* **Raw Data**: Shows unprocessed data exactly as it was captured.
* **Form Data**: Filters to show data entered into forms within Lucy, like registration or feedback forms.
* **Login Data**: Reveals data related to user login credentials, typically restricted to partial information for privacy.
* **File Upload**: Lists data on files uploaded by the [Technical Malware](/guides/attack-simulations/attack-types/technical-malware-test) test.
* **Interactive Session**: Displays data from sessions that involve user interaction, possibly including real-time engagements and their details.
  {% endtab %}

{% tab title="Scenario" %}
The "Scenario" dropdown menu in the "Collected Data" tab allows administrators to filter the collected data based on different scenarios within the campaign.

<figure><img src="/files/OOawWgQg5S7yL83PK1GN" alt="" width="212"><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Export" %}
Exporting the Collected data will provide an administrator with either a csv or xml, specifying the following metrics:

<figure><img src="/files/gLbZYmAhLdvWldcavvhO" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Clear" %}
This option allows an administrator to clear all collected data.

{% hint style="warning" %}
Once data has been cleared, it becomes irretrievable.
{% endhint %}
{% endtab %}
{% endtabs %}

***

### Recipients

The Recipients Statistics page offers administrators a comprehensive overview of individual recipient outcomes, furnishing granular metrics on each participant's engagement with the campaign.

<figure><img src="/files/ZdhglLHTqSjWeuDHUUKd" alt="" width="563"><figcaption></figcaption></figure>

#### Overview of all recipient statistics:

<figure><img src="/files/wLXfasqWU0ie47ERAJr3" alt="" width="563"><figcaption></figcaption></figure>

{% tabs %}
{% tab title="Recipients" %}
The total number of individuals targeted in the campaign.
{% endtab %}

{% tab title="Sent" %}
The total emails that were successfully dispatched to recipients.
{% endtab %}

{% tab title="Opened" %}
Recipients who opened the email.

{% hint style="warning" %}
"Tracked Opened Emails" needs to be enabled on the Scenario Settings.
{% endhint %}

<figure><img src="/files/hiPdjwhXXSVjQofFKHBq" alt="" width="563"><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Clicked" %}
Recipients who clicked on a link within the email.
{% endtab %}

{% tab title="Vulnerable" %}
The number of recipients who are considered to have vulnerabilities in their browser version.

{% hint style="warning" %}
"Advanced Information Gathering" needs to be enabled on the Scenario Settings.
{% endhint %}

<figure><img src="/files/HXEKu1ZXztWJPANImvqh" alt="" width="563"><figcaption></figcaption></figure>
{% endtab %}

{% tab title="File Downloaded" %}
Instances where a recipient downloaded a file.
{% endtab %}

{% tab title="Data Submitted" %}
Cases where recipients entered data on a simulated phishing page.
{% endtab %}
{% endtabs %}

{% tabs %}
{% tab title="Succeeded" %}
Recipients who completed the desired success action of the phishing simulation.

{% hint style="warning" %}
The success action is defined for each scenario on the Scenario Settings of the campaign.
{% endhint %}

<figure><img src="/files/35XhN6enO3CB1c4sJSvr" alt="" width="563"><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Training Succeeded" %}
Recipients who successfully completed the associated training module.
{% endtab %}

{% tab title="Rescheduled" %}
The amount of recipients that opted to reschedule the training.

{% hint style="warning" %}
"Allow Awareness Rescheduling" needs to be enabled on the Base Settings of the campaign.
{% endhint %}

<figure><img src="/files/QB55De0fZ30bfNGXJpao" alt="" width="563"><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Out of Office" %}

Auto-replies indicating the recipient is out of the office.

{% hint style="warning" %}
"Tracked Bounced Emails" needs to be selected on the Base Settings of the campaign.
{% endhint %}

<figure><img src="/files/vyPBrJtdJ8fhgcXi5HEX" alt="" width="563"><figcaption></figcaption></figure>

{% hint style="info" %}
Further behavioral configuration can be done in **Settings -> Submitted Email Settings -> Automated Response Detection**
{% endhint %}
{% endtab %}

{% tab title="Bounced" %}
Emails that failed to deliver.

{% hint style="warning" %}
"Tracked Bounced Emails" needs to be selected on the Base Settings of the campaign.
{% endhint %}

<figure><img src="/files/S9VJhey3mV1booUnfxYA" alt="" width="563"><figcaption></figcaption></figure>

{% hint style="info" %}
Further behavioral configuration can be done in **Settings -> Submitted Email Settings -> Automated Response Detection**
{% endhint %}
{% endtab %}

{% tab title="Responded" %}
Recipients who replied to the email.

{% hint style="info" %}
The system is configured to intercept all emails directed to the sender's email address and associated domain. Thus, the sender's email domain's MX records must be set to this Lucy server, and as a result, no emails from the Lucy Server can be delivered to addresses within that domain if they are listed as recipients.
{% endhint %}
{% endtab %}
{% endtabs %}

#### Detailed Recipient Statistics

In the following section, an administrator can obtain detailed data on each recipient's specific interactions within the campaign.

<details>

<summary>Navigating through recipient statistics</summary>

From the dropdown, an administrator can isolate recipients by Scenarios:

<img src="/files/Ywa8e4B3BnqehZ59aK8B" alt="" data-size="original">

* **Name**: Lists the names of the individuals targeted in the phishing campaign scenario.
* **OS**: Shows the operating system of the recipient's device, including the version and release year.
* **Browser**: Indicates the web browser used by the recipient, along with the version.
* **Plugins**: Lists any browser plugins detected on the recipient's device.
* **Phished**: A checkmark represents whether the recipient was successfully phished.
* **Train**: Indicates whether the recipient has completed the associated cybersecurity training.
* **Actions**: This column includes icons for actions that can be taken for each recipient, such as editing, manually updating the statistics, or deleting a recipient.

</details>

Each recipient has quick actions available, enabling you to download the training certificate, resend the email, edit recipient details, or update the recipient's statistics.

<figure><img src="/files/XWPPhjwJkFPCi0BW1wbu" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Click on the recipient's name to gather detailed statistics.
{% endhint %}

<figure><img src="/files/QWJwQqZZLMbn8AoV83k9" alt="" width="563"><figcaption></figcaption></figure>

<details>

<summary><strong>Recipient Profile</strong></summary>

* **Name**: The recipient's full name.
* **Email**: Their email address.
* **Phone**: The recipient's phone number.
* **User History**: Includes a log of all interactions with the campaigns.

![](/files/tximA6syaAqmc4ztLacY)

</details>

<details>

<summary><strong>Campaign Interaction Details</strong></summary>

* **Lure Sent**: Status of [phishing lure](/guides/attack-simulations/attack-types/lures) sent to the recipient.
* **Message Sent**: Confirmation of the campaign message being sent.
* **Training Sent**: Indicates if the awareness training was sent.
* **Reported:** Status if the recipient had reported the simulated email.
* **Stats Updated**: Timestamp of the last update to the recipient's statistics.

</details>

<details>

<summary><strong>Engagement Metrics</strong></summary>

* **Success Rate**: Percentage of successful phishing attempts.
* **Click Rate**: Percentage of links clicked by the recipient.
* **Successful Attack**: Count of successful phishing attempts.
* **Training Page Visited**: Indicates if the recipient visited the training page.

</details>

<details>

<summary><strong>Reputation Level</strong></summary>

Visual indicator of the recipient's susceptibility to phishing attempts, which can be customized.

</details>


# Reports

### Introduction

Reports provide a holistic analysis of campaigns, encompassing executive summaries, campaign objectives, configuration details, visual aids like screenshots of phishing emails and landing pages, as well as critical training metrics including quiz performance statistics and campaign imagery. These reports are tailored to be a quick and efficient solution to provide an overview of the security appetite of the organization, serving as an informative executive summary.

<figure><img src="/files/Td6uMTiVp3JTi1RFsIVo" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/AVFS1C8hzUHbMrhqtdMB" alt=""><figcaption></figcaption></figure>


# Exports

### Overview

LUCY provides a versatile data export functionality, accessible through the "Export" option within the campaign overview page. Users have the flexibility to export either all monitored data or select specific data for export. This feature supports a range of formats and methodologies, catering to various user needs.

{% hint style="info" %}
Navigate to a **Campaign -> Results -> Exports**
{% endhint %}

<figure><img src="/files/EtywFOwpkq4Yj3tnmw2w" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
All exports are available in either CSV or XML format.
{% endhint %}

***

### Recipient Statistics

<figure><img src="/files/iFNPtnKt33FCpvWt8IJS" alt=""><figcaption></figcaption></figure>

<details>

<summary>Recipient Statistics Descriptions</summary>

* **All**: Exports the entire dataset of campaign recipients without any filters applied.
* **All By Recipient Group**: Allows you to export data for specific groups of recipients.&#x20;
* **Succeeded**: Filters and exports data for recipients who completed the desired action of the attack, indicating they were successfully phished.
* **Not Succeeded**: Selects recipients who did not complete the attack's intended action, meaning the phishing attempt was unsuccessful with them.
* **Clicked**: Focuses on recipients who clicked on the link in the phishing email, message (SMS), or link to Awareness training.
* **Started Training**: Filters recipients who have begun the training modules provided in the campaign.
* **Not Started Training**: Exports data for recipients who have not initiated any training modules linked to the campaign.
* **Completed Training**:  Filters recipients who have gone through and completed the training modules.
* **Downloaded File**: Identifies recipients who have downloaded a file, as part of an attack or malware simulation.
* **Visits**: Exports data on all recipients who visited the campaign's landing pages.
* **Scenario Visits**: Focuses on recipients who visited a specific scenario in the campaign.
* **Awareness Visits**: Filters out data for recipients who visited the awareness pages that are typically set up to educate them post-engagement with the phishing attempt.
* **Quiz Answers**: Exports data specifically related to the recipients' engagement with quizzes, such as answers submitted.
* **Received Training Certificate**: Filters and exports data for recipients who have received a certificate upon completing a training module, signifying their participation and completion.
* **Clicks Data**: Provides detailed data on the interactions of recipients with the phishing links, such as the time of click and frequency.

</details>

***

### Recipient Success Actions

<figure><img src="/files/m3TG8OpNgXpYAU0Kc0Ld" alt=""><figcaption></figcaption></figure>

<details>

<summary>Recipient Success Actions Descriptions</summary>

* **Succeeded to Group**: This option allows you to filter and export data for recipients who have been successfully phished or who have completed the desired success action in the campaign. The recipients who meet this criterion will be grouped together, which can be useful for follow-up actions such as simulating or training again.
* **Not Succeeded to Group**: Contrary to the above, this option will filter out and export data for recipients who did not fall for the phishing attempt or who did not complete the intended success action. These recipients are also grouped, allowing you to target them for more challenging simulations.
* **Clicked to Group**: This selection filters recipients based on whether they clicked on a phishing link or not. It groups the clickers, providing a list of those who showed initial engagement with the phishing content.

</details>

***

### Export recipients within a submitted time range to a new group.

This option exports data for recipients within a specified time range to a new group. This is useful for creating segments of recipients who have been active or participated within a certain period, and facilitating targeted follow-up campaigns or analyses.

<figure><img src="/files/UEkxPmnsT3BO9V0SLdgO" alt="" width="290"><figcaption></figcaption></figure>

***

### Export campaign benchmark results

The Benchmark export provides a snapshot of campaign performance by compiling key metrics like message delivery, open rates, click-throughs, and overall success rates into a comprehensive report.

<figure><img src="/files/MVYoxvWlKmw0tyvE7NlI" alt=""><figcaption></figcaption></figure>

***

### Export collected data

This export option compiles a detailed log of user interactions from the campaign, recording entries like timestamps, participant details, associated scenarios, and specific user-submitted information, exemplified by login credentials.

<figure><img src="/files/ho58dnNKjWe4BvzeIJxX" alt=""><figcaption></figcaption></figure>

***

### Automated Export

Automated Exports is a functionality that allows for the scheduled and recurrent generation of reports based on predefined criteria and intervals.

{% hint style="info" %}
Navigate to a **Campaign -> Results -> Automated Exports**
{% endhint %}

<figure><img src="/files/L1LfZAvHVGorO1VBk6z1" alt=""><figcaption></figcaption></figure>

* **Export Target**: Choose data sets to automate, like All Victims, Not Succeeded, Clicks Data, or Campaign Benchmark.
* **Export Frequency**: Set the frequency for the export—daily, weekly, monthly, or yearly.
* **Export Time**: Decide the specific time of day for the export to run.
* **Export Days**: Specify which days the export should occur, based on the chosen frequency.
* **Export Type**: Select the format of the exported file, such as XML or CSV.

This tool is designed to regularly provide fresh data without manual effort, aiding consistent and timely analysis sent directly to the email address of the campaign creator.

***

### Alternative Export Methods

* **API Integration**: LUCY offers [API access](/application-reference/settings/common-system-settings/api-whitelist) for users preferring automated data retrieval.

***

### All Exportable Columns

Lucy provides many exportable data points, covering aspects from recipient information to interaction metrics, such as:

* Personal and contact information (name, email, phone number)
* Engagement metrics (clicks, submissions, training completion)
* Campaign specifics (scenario name, domain, staff type)
* Technical data (operational system, IP, browser, plugins used)
* Interaction timelines (email submission, click, report times)
* Quiz and training metrics (quiz answers, training completion)
* Security awareness levels

| Collumn name                              | Description                                                                                         | Value Type        |
| ----------------------------------------- | --------------------------------------------------------------------------------------------------- | ----------------- |
| name                                      | Name of the recipient                                                                               | Text              |
| email                                     | Email of the recipient                                                                              | Text              |
| phone                                     | Phone number of the recipient                                                                       | Numeral           |
| gender                                    | Gender of the recipient                                                                             | Male / Female     |
| link                                      | Unique link of the recipient                                                                        | Text              |
| lure\_submitted\_at                       | Time of lure email submission                                                                       | Timestamp         |
| mail\_submitted\_at                       | Time of email submission                                                                            | Timestamp         |
| clicked                                   | Recipient clicked the link in the email                                                             | Yes / No          |
| clicked\_at                               | Time recipient clicked the link in the email                                                        | Timestamp         |
| succeeded                                 | Success action triggered for the recipient                                                          | Yes / No          |
| succeeded\_at                             | Time when success action was triggered                                                              | Timestamp         |
| trained                                   | Recipient has completed the training                                                                | Yes / No          |
| trained\_at                               | Time when recipient has completed the training                                                      | Timestamp         |
| reported                                  | Recipient has reported the message via LUCY Report Plugin                                           | Yes / No          |
| reported\_at                              | Time when recipient has reported the message                                                        | Timestamp         |
| domain                                    | Domain used in the campaign's scenario                                                              | Text              |
| scenario                                  | Name of the scenario on the campaign                                                                | Text              |
| staff\_type                               | Info about recipient's staff category                                                               | Text              |
| location                                  | Info about recipient's location                                                                     | Text              |
| division                                  | Info about recipient's department                                                                   | Text              |
| comment                                   | Additional optional comment about the recipient                                                     | Text              |
| os                                        | Operational System of the workstation that submitted first click                                    | Text              |
| ip                                        | IP of the workstation that submitted first click                                                    | Numeral           |
| proxy\_ip                                 | IP of the proxy                                                                                     | Numeral           |
| browser                                   | Browser of the workstation that submitted first click                                               | Text              |
| plugins                                   | Plugins detected on the workstation that submitted first click                                      | Text              |
| country                                   | Country based on IP                                                                                 | County Code       |
| success\_rate                             | How many times a recipient was successfully attacked, depending on the Success Action               | Numeral           |
| click\_rate                               | How many times a recipient clicked the attack link                                                  | Numeral           |
| scenario\_time                            | Amount of time the victim has spent on the phishing link page                                       | Numeral           |
| awareness\_time                           | Amount of time the victim has spent on the awareness link page                                      | Numeral           |
| email\_subject                            | Subject of the sent email                                                                           | Text              |
| first\_click\_after\_delivery             | Time value in seconds between mail\_submitted\_at and succeeded\_at                                 | Numeral           |
| first\_report\_after\_delivery            | Time value in seconds between mail\_submitted\_at and reported\_at                                  | Numeral           |
| reminder\_click\_submitted\_at            | Time when recipient clicked the reminder link                                                       | Timestamp         |
| reminder\_training\_start\_submitted\_at  | Time when the recipient started the training provided by reminder                                   | Timestamp         |
| reminder\_training\_finish\_submitted\_at | Time when the recipient finished the training provided by reminder                                  | Timestamp         |
| downloaded\_files                         | File-based attack downloaded files by the recipient                                                 | Text              |
| collected\_data                           | The data that has been submitted by the recipient on the landing page                               | Text              |
| out\_of\_office\_at                       | Time of Out of Office autorespond                                                                   | Timestamp         |
| bounced\_at                               | Time of the Bounced response                                                                        | Timestamp         |
| responded\_at                             | Time of the incoming response to the email                                                          | Timestamp         |
| certificate\_received                     | Recipient has received a certificate                                                                | Yes / No          |
| training\_with\_quiz\_passed              | Recipient has passed a training with Quiz mode enabled                                              | Yes / No          |
| training\_with\_quiz\_passed\_at          | Time when recipient has passed a training with Quiz mode enabled                                    | Timestamp         |
| training\_noquiz\_finished                | Recipient has finished a training without Quiz                                                      | Yes / No          |
| training\_noquiz\_finished\_at            | Time when recipient has finished a training without Quiz                                            | Timestamp         |
| security-level                            | Level of awareness security                                                                         | Numeral           |
| answers\_count\_0                         | Quiz answers count                                                                                  | Numeral           |
| answers\_percent\_0                       | Quiz answers percentage (based on total number of questions)                                        | Percentage        |
| correct\_answers\_count\_0                | Number of correct quiz answers                                                                      | Numeral           |
| correct\_answers\_percent\_0              | Correct answers percentage (based on total number of questions)                                     | Percentage        |
| wrong\_answers\_count\_0                  | Number of wrong quiz answers                                                                        | Numeral           |
| wrong\_answers\_percent\_0                | Wrong answers percentage (based on total number of questions)                                       | Percentage        |
| quiz\_time\_spent\_0                      | Time spent for quiz                                                                                 | Minutes / Seconds |
| training\_succeeded\_0                    | Recipient has completed the training with Extended method of tracking the end of the quiz           | Yes / No          |
| training\_succeeded\_at\_0                | Time when recipient has completed the training with Extended method of tracking the end of the quiz | Timestamp         |

###


# Templates


# Attack Templates

Templates -> Attack Templates

### Introduction

Lucy comes with a comprehensive collection of more than 500 attack simulation templates covering various types of attacks. The templates range from straightforward exercises featuring clear spelling mistakes to more intricate simulations involving complex double barrel and file-based attacks. Designed to mimic both real-world scenarios from known brands and hypothetical situations.

***

### Attack Template Variations

{% tabs %}
{% tab title="Hyperlink" %}
This type of simulation targets users' ability to recognize malicious links. It involves crafting emails or messages that include hyperlinks leading to unsafe websites.&#x20;

The goal is to educate users on the dangers of clicking on unknown links and to improve their ability to identify suspicious or malicious hyperlinks.\
\
The attack is deemed successful the moment a user clicks on a hyperlink contained within the simulated email.

<figure><img src="/files/7gMJ39lmL7diseQkqUBH" alt="" width="563"><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Web-Based" %}
This simulation exposes users to scenarios where attackers use compromised or malicious websites to gain access to sensitive information or to infect users' systems with malware. \
\
It teaches users to navigate the web more securely, emphasizing the importance of verifying the legitimacy of websites and the risks of entering personal information into untrusted web pages.\
\
The attack is deemed successful the moment a user enters data on a simulated website landing page.

<figure><img src="/files/XEE1Sd2nDpO9L6GZFNDy" alt="" width="563"><figcaption></figcaption></figure>
{% endtab %}

{% tab title="File-Based" %}
In this attack type, users are presented with files that appear benign but contain malicious payloads. \
\
These files come in various formats, such as Excel/Word Macros, PDFs, SVG or executables, and are typically distributed via email attachments or landing page downloads.\
\
The objective is to train users to be wary of opening or downloading files from unverified sources and to recognize signs of potentially malicious files.\
\
The attack is deemed successful the moment a user either downloads the file or executes the payload.

<figure><img src="/files/mWmxwUK3CW1ldaNQP0Qd" alt="" width="563"><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Mixed" %}
Mixed attacks involve a sequence where an email prompts a user to log into a fake portal for credential harvesting.&#x20;

The user then downloads and executes a file, often containing ransomware, as the final success phase of the attack. This simulation trains users to recognize and mitigate multi-step cyber threats, emphasizing the critical need for cautious interaction with emails and websites, and the importance of verifying sources before downloading and executing files.&#x20;

The attack is considered successful when the user executes the ransomware payload.
{% endtab %}

{% tab title="Portable Media" %}
This attack type involves the use of physical media devices, such as USB drives or [Rubber Ducky's](https://shop.hak5.org/products/usb-rubber-ducky), that are infected with malware. \
\
It aims to educate users about the risks associated with connecting unknown or unsolicited portable media to their devices.&#x20;

The focus is on raising awareness of the potential for these devices to bypass network security measures and directly introduce malware into systems.\
\
The attack is deemed successful the moment a user either runs an executable from a USB or inserts a Rubber Ducky with the potential to act as a keylogger.
{% endtab %}
{% endtabs %}

***

### Attack Template Directory Navigation

Accessing **Templates -> Attack Templates** displays all the attack templates available on your current server. You can view your **installed** templates as well as browse for templates to **download**.

<figure><img src="/files/ea2Ja0dmp1jfpC2Obqb4" alt=""><figcaption></figcaption></figure>

***

### **Filtering**

With Lucy's extensive template repository, using filters is advantageous to identify which templates are automatically translated into your preferred languages, relevance to your target audiences, category, or difficulty level.

{% tabs %}
{% tab title="Language" %}
The language filter displays all templates available in the chosen languages. Initially, only a subset of 10 languages is shown by default.

<figure><img src="/files/xgIuz5IZPG4PNmHybA0U" alt="" width="204"><figcaption></figcaption></figure>

To locate languages not listed, utilize the language search bar.

<figure><img src="/files/rRbrHWpq2KVdQElbSnTI" alt="" width="201"><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Type" %}
The type filter enables you to categorize and view all attacks by their predefined attack type. For instance, selecting the filter for Hyperlink attacks will display all the templates associated with this specific type of attack.<br>

<figure><img src="/files/qr0XTn7dlvzuJn6tcrST" alt="" width="301"><figcaption></figcaption></figure>

{% hint style="info" %}
For comprehensive instructions on Attack Types, please refer to our guide titled "[Attack Types](/guides/attack-simulations/attack-types)"
{% endhint %}
{% endtab %}

{% tab title="Target Audience" %}
The target audience filter helps you find all attack templates relevant to the specific group within your organization you are aiming to train or evaluate. Some attacks are tailor-made for technical staff like developers or system administrators, while others are suited for corporate users, including C-level executives.

<figure><img src="/files/09sFRs42AtiulZwBlrVW" alt="" width="302"><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Category" %}
The category filter helps you refine your search to attack templates based on their fundamental attack objective. For instance, choosing Social Media as a category will show all templates related to platforms such as Facebook, Twitter, WhatsApp, and others.

<figure><img src="/files/qXVzWOHsekcKsC2NgqEP" alt="" width="296"><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Difficulty Level" %}
The difficulty filter organizes attack templates by their perceived complexity. For instance, templates featuring intentional spelling mistakes and minor branding alterations might be classified as "Low Level," indicating they are easier to identify by the end user. Conversely, templates that include nearly identical landing pages designed to mimic legitimate entities, such as Microsoft, are categorized as "High Level," reflecting their greater challenge in detection.

<figure><img src="/files/DdGJf7h1PHgnHVaZkj8y" alt="" width="296"><figcaption></figcaption></figure>

{% hint style="info" %}
By default, templates are not assigned a Difficulty level since this classification can be subjective and dependent on the security posture of the organization in question. Manual classification is required during the template editing process to reflect an organization's specific security considerations.
{% endhint %}
{% endtab %}
{% endtabs %}

***

### **Search, Actions, and Sorting**

The upper bar in the template directory offers functionalities such as search, the ability to perform actions specific to templates, and options to sort the displayed results.

<figure><img src="/files/vRa8anYrXhPsVRjDvdMd" alt=""><figcaption></figcaption></figure>

{% tabs %}
{% tab title="Search" %}
The Search bar functions as a global search tool, allowing you to retrieve all templates that match your specified keywords.

<figure><img src="/files/Gqooot5TbJxiTNh1pLEW" alt="" width="563"><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Actions" %}

* **Copy**: Duplicate the selected template within the directory.
* **Restore**: Import a previous Backup template.
* **Backup**: Create a save point for the selected template to preserve its current state as a downloadable backup.
* **Delete**: Permanently remove the selected template from the directory.

<figure><img src="/files/yuOntH6KxtcLUGzW3eHu" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Sort" %}
By default, templates are sorted from newest to oldest. However, you can choose to sort them alphabetically, by the date they were added, or by the date they were last customized.

<figure><img src="/files/IKOyWDZeHtkDHd5GxCE1" alt="" width="243"><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Tab / List View" %}
This display toggle allows you to switch between viewing the template results as tiles or in a list format.

<figure><img src="/files/SofN51X73wOtius0vTLg" alt="" width="107"><figcaption></figcaption></figure>

Tiles:

<figure><img src="/files/sQlKbv52gYt1Cxzn86BR" alt="" width="563"><figcaption></figcaption></figure>

List:

<figure><img src="/files/TsDRlh1mIWqSsmBxOGYQ" alt="" width="563"><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Favorites" %}
Starting in Lucy version 5.1 you may select your favorite templates and use the "Starred" filter option to view them:

<figure><img src="/files/QyhdFRQaPVDhwanBJ6t6" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Click the :star: icon on any template to favorite or unfavorite it.
{% endhint %}
{% endtab %}
{% endtabs %}

***

{% hint style="success" %}
Ready to edit a template? See our guide to [customize an attack template](/guides/attack-simulations/attack-template-customization).
{% endhint %}

***


# Awareness Templates

### Introduction

Awareness training through LUCY helps reduce susceptibility to phishing and malware by educating users about their risks. The platform offers:

* Computer-based training accessible from any location.
* Short, modular, customizable videos suitable for multi-session completion.
* Tailored training topics and layouts for specific audiences.
* Supplementary materials to reinforce training.
* Multi-language support to ensure consistency across geographies.
* Quizzes to assess learner comprehension.
* Completion reports for compliance tracking.

{% hint style="warning" %}
Awareness training may use cookies for progress tracking.
{% endhint %}

***

{% hint style="info" %}
Navigate to **Templates -> Awareness Templates**
{% endhint %}

### Awareness Template Variations

LUCY provides a variety of ready-to-use e-learning templates, which are continually updated.  These templates include rich media options like videos and interactive elements to enhance engagement.

{% tabs %}
{% tab title="Games" %}
Gamification in cybersecurity awareness training incorporates interactive challenges and rewards to engage participants, making learning about security protocols both fun and memorable.

For example, search for **Who Wants to Be a Millionaire: Test your phishing know-how!**

<figure><img src="/files/5A1OMqIGg5NifWMXYtQZ" alt="" width="563"><figcaption></figcaption></figure>
{% endtab %}

{% tab title="1 Pagers" %}
1 Pager templates in LUCY serve as immediate feedback mechanisms for users who have been deceived by a phishing simulation. These templates are designed to:

* Quickly inform users of their mistake without causing panic.
* Provide a brief, clear warning that explains the simulation's intent.
* Encourage users to remain vigilant against real phishing attempts.
* Suggest further training to improve their cybersecurity awareness.

For example, search for **One Pager: Customizable template**

<figure><img src="/files/xfHyVc68OxjYzvqVgXvq" alt="" width="375"><figcaption></figcaption></figure>

These templates are fully customizable, allowing for the addition of pointers about the recent phishing simulation and the ability to upload custom images.
{% endtab %}

{% tab title="Micro Learning" %}
Microlearning in security awareness training uses short, focused modules to teach specific security practices, enhancing retention and fitting easily into busy schedules.

For example, search for **Microlearning-Google sign in**

<figure><img src="/files/lcnqxZT5Zdb9rFRV1iZG" alt="" width="563"><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Advanced Learning" %}
Advanced Learning templates incorporate multiple quizzes, a final exam, and interactive tasks and videos to deeply engage learners and reinforce complex security topics.

For example, search for **Information Security in Ai**

<figure><img src="/files/lmypAH8NkB2ovPEmLG4H" alt="" width="563"><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Exams Only" %}
Exam-only templates focus solely on delivering assessments to end users, testing their knowledge and understanding of security practices without preceding instructional content.

For example, search for **Exam-Information Security in AI Exam**

<figure><img src="/files/ZXDl43B36PRibULBh4v3" alt="" width="563"><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Videos" %}
Video-only templates feature thematic characters and include interactive options, engaging users through narrative-driven content that illustrates security concepts and practices in an immersive format.

Click [here](/guides/awareness-training/awareness-template-customization#custom-video-content) for our guide on using custom videos in Lucy templates.
{% endtab %}
{% endtabs %}

***

### Awareness Template Directory Navigation

Accessing **Templates -> Awareness Templates** displays all the awareness templates available on your current server. You can view your **installed** templates as well as browse for templates to **download**.

<figure><img src="/files/TKMmsD64368vN0g8EmiK" alt=""><figcaption></figcaption></figure>

***

### Filtering

With Lucy's extensive template repository, using filters is advantageous to identify which templates are automatically translated into your preferred languages, relevance to your target audiences, category, or difficulty level.

{% tabs %}
{% tab title="Language" %}
The language filter displays all templates available in the chosen languages. Initially, only a subset of 10 languages is shown by default.

<figure><img src="/files/xgIuz5IZPG4PNmHybA0U" alt="" width="204"><figcaption></figcaption></figure>

To locate languages not listed, utilize the language search bar.

<figure><img src="/files/rRbrHWpq2KVdQElbSnTI" alt="" width="201"><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Type" %}
The type section classifies the format of the content within the awareness templates. This helps in selecting a delivery method that will most effectively engage the target audience and reinforce learning.

<figure><img src="/files/NrUR4n9SHkOdiHuqqb4a" alt="" width="296"><figcaption></figcaption></figure>

**Video**:

* Multimedia presentations often incorporating visual and auditory elements to illustrate security concepts.

**Quiz**:

* Interactive assessments designed to test the audience's understanding of the security material covered.

**Game**:

* Engaging, often interactive activities aimed at educating through play, enhancing retention of security principles.

**Static**:

* Traditional, non-interactive content such as PDFs, images, or text documents providing information without user engagement.

**Mixed**:

* A combination of various formats to cater to different learning styles and preferences within the audience.

**Test**:

* Structured evaluations used to measure the audience’s knowledge and awareness of specific security topics.

**Poster**:

* Visual content designed for print or electronic display, highlighting key security messages or practices.

**Implementation**

* When editing an awareness template, use the Type dropdown to define the template's type.

<figure><img src="/files/rM4Sz7obPAGrPqrEQ9T3" alt="" width="563"><figcaption></figcaption></figure>

This allows administrators to filter templates based on the mode of information delivery that best suits their campaign's objectives.
{% endtab %}

{% tab title="Target Audience" %}
The target audience filter helps you find all awareness templates relevant to the specific group within your organization you are aiming to train or evaluate. Some awareness templates are tailor-made for technical staff like developers or system administrators, while others are suited for corporate users, including C-level executives.

<figure><img src="/files/vCXWKYNiLXSRVcSBIgu5" alt=""><figcaption></figcaption></figure>

**End-user**:

* Content is intended for the general workforce or individuals who use IT systems and services.
* Focuses on common security practices, phishing awareness, and safe internet habits.

**IT Expert**:

* Tailored for professionals with technical roles in information technology.
* Covers in-depth security protocols, advanced threat detection, and system-specific security measures.

**Management**:

* Designed for executives and department heads.
* Emphasizes strategic security planning, risk management, and policy enforcement.

**Implementation**

* Select the target audience that corresponds with the group for which the awareness template is being developed.

<figure><img src="/files/fgq54JtRbjDNxVezTAwN" alt=""><figcaption></figcaption></figure>

This targeting ensures that the material is relevant and the language used is appropriate for the audience's role and level of expertise.
{% endtab %}

{% tab title="Difficulty Level" %}
The Difficulty Level categorizes awareness templates based on the level of complexity and the knowledge required to understand the content. This classification aids in selecting the appropriate template that matches the intended audience's expertise.

<figure><img src="/files/1rF45XIaxQ2naRzDax7V" alt="" width="307"><figcaption></figcaption></figure>

**Low Level**:

* Suitable for a broad audience, including individuals with minimal to no prior knowledge of security awareness topics.
* The content is straightforward and uses basic language to ensure comprehension.

**Medium Level**:

* Targeted at users with a moderate understanding of security concepts.
* Templates include more detailed information and may introduce more complex terms, requiring a foundational level of security awareness.

**High Level**:

* Designed for an audience with advanced knowledge of security awareness.
* Complex concepts and industry-specific jargon are prevalent, necessitating a high degree of familiarity with the subject matter.

**Implementation**

* When creating or editing awareness templates, select the appropriate difficulty level that best matches the complexity of the material and the intended audience's expertise level.

<figure><img src="/files/9YkdDbtUzJVS49dwsik0" alt="" width="563"><figcaption></figcaption></figure>

This categorization helps administrators to filter and choose templates that align with their educational goals and the knowledge level of their audience.
{% endtab %}

{% tab title="Duration" %}
The duration section specifies the length of time required to complete an awareness activity or consume content. This information helps in planning and allocating appropriate time slots for security training sessions.

<figure><img src="/files/NmUuuAsGIOMTQYfwDzES" alt="" width="299"><figcaption></figcaption></figure>

Specify the estimated time required to complete the template when editing a template.

<figure><img src="/files/cAN5BW8oa6arlkh23sFO" alt="" width="563"><figcaption></figcaption></figure>
{% endtab %}
{% endtabs %}

***

### **Search, Actions, and Sorting**

The upper bar in the template directory offers functionalities such as search, the ability to perform actions specific to templates, and options to sort the displayed results.

<figure><img src="/files/JTnLyLwO9FJcFsHvV6NZ" alt=""><figcaption></figcaption></figure>

{% tabs %}
{% tab title="Search" %}
The Search bar functions as a global search tool, allowing you to retrieve all templates that match your specified keywords.

<figure><img src="/files/yJTaIpUq60RLNsbjaZxJ" alt="" width="563"><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Actions" %}

* **Copy**: Duplicate the selected template within the directory.
* **Restore**: Import a previous Backup template.
* **Backup**: Create a save point for the selected template to preserve its current state as a downloadable backup.
* **Delete**: Permanently remove the selected template from the directory.

<figure><img src="/files/1Ej7BdSlfIVN6OxR5omu" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Sort" %}
By default, templates are sorted from newest to oldest. However, you can choose to sort them alphabetically, by the date they were added, or by the date they were last customized.

<figure><img src="/files/2cNjqZPd9gMYoj6ZmHJY" alt="" width="223"><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Tab / List View" %}
This display toggle allows you to switch between viewing the template results as tiles or in a list format.

<figure><img src="/files/n9mX9GaIoM5oUz9xlAqQ" alt="" width="104"><figcaption></figcaption></figure>

Tiles:

<figure><img src="/files/ephsF16Wg2wrSHYTVlzn" alt="" width="563"><figcaption></figcaption></figure>

List:

<figure><img src="/files/mpQuc3rxIMQWtv7Y9blf" alt="" width="563"><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Favorites" %}
Starting in Lucy version 5.1 you may select your favorite templates and use the "Starred" filter option to view them:

<figure><img src="/files/dR8HIWHLrHKGjb8Oy2yz" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Click the :star: icon on any template to favorite or unfavorite it.
{% endhint %}
{% endtab %}
{% endtabs %}

***

### Dynamically preview an Awareness template

Lucy enables administrators to dynamically preview any template, allowing them to understand the construction, flow, and logic of both the email and landing pages.

<figure><img src="/files/rt3CMp9moV3vRUL4LFwJ" alt=""><figcaption></figcaption></figure>

***

{% hint style="success" %}
Ready to edit a template? See our guide to[ customize an awareness template](/guides/awareness-training/awareness-template-customization).
{% endhint %}

***




---

[Next Page](/llms-full.txt/1)

