KnowBe4 Phishing

SkillSecurity

KnowBe4 phishing simulations: campaign creation and lifecycle, security test management, recipient interaction tracking (sent, opened, clicked, reported), phish-prone percentage calculation, template selection, landing pages, and click tracking.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the KnowBe4 Phishing skill

What this skill tells your AI

The instructions your AI receives, as published by wyre-ai/msp-claude-plugins in msp-claude-plugins/email-security/knowbe4/skills/phishing/SKILL.md and read by ahel’s review.

Overview

KnowBe4 phishing simulations are the core mechanism for testing and improving an organization's resilience to social engineering attacks. Campaigns deliver simulated phishing emails to users and track their interactions -- whether they opened the email, clicked the link, submitted data on the landing page, reported it via the Phish Alert Button, or took no action. The phish-prone percentage is the key metric derived from these campaigns.

Anti-triggers

  • A real phishing email that reached a user — every campaign, click, and "failure" here is a simulation the MSP sent on purpose. Genuine inbound phishing is detected by the mail-security vendor: proofpoint-tap, avanan-threats, or abnormal-security-threats.
  • Finding, releasing, or pulling a message out of a mailbox — KnowBe4 never touches production mail flow. Use proofpoint-quarantine or avanan-quarantine to release, and proofpoint-forensics to remove delivered mail.
  • "Phish Alert Button" reports as a threat-intake queue — this skill counts PAB reports as a pass/fail signal on a simulation; the real user-reported phishing triage queue is ironscales-incidents.
  • Enrolling the users who failed into remedial training — the enrollment side is knowbe4-training.
  • Organization-wide phish-prone percentage or department breakdowns — per-campaign results are here; rolled-up metrics and benchmarks are knowbe4-reporting.

Key Concepts

Campaign Lifecycle

CREATED ──> SCHEDULED ──> IN_PROGRESS ──> COMPLETED
                │                              │
                └──── CANCELLED                └──> ARCHIVED
  • Created: Campaign configured but not yet scheduled
  • Scheduled: Campaign queued for delivery at a specific date/time
  • In Progress: Emails are being sent and interactions tracked
  • Completed: Campaign delivery finished, final results available
  • Cancelled: Campaign aborted before completion
  • Archived: Completed campaign moved to archive

Security Test Types

TypeDescriptionUse Case
PhishingStandard email with link to landing pageMost common, baseline testing
VishingVoice-based social engineering simulationPhone-based attack awareness
SmishingSMS-based phishing simulationMobile threat awareness
USBPhysical USB drop testPhysical security awareness
QR CodeQR code-based phishingEmerging threat vector

Recipient Interaction States

Each recipient in a campaign progresses through trackable states:

StateDescriptionIndicates
DeliveredEmail successfully deliveredBaseline count
OpenedRecipient opened the emailCuriosity/engagement
ClickedRecipient clicked the phishing linkFailed the test
RepliedRecipient replied to the emailFailed the test (data leakage risk)
Attachment OpenedRecipient opened an attachmentFailed the test
Macro EnabledRecipient enabled macros in attachmentCritical failure
Data EnteredRecipient submitted data on landing pageCritical failure
ReportedRecipient reported via Phish Alert ButtonPassed the test
No ActionNo interaction recordedNeutral (may not have seen it)

Phish-Prone Percentage Calculation

The phish-prone percentage (PPP) is the primary metric for organizational risk:

function calculatePhishPronePercentage(campaign) {
  const totalDelivered = campaign.recipients.filter(r => r.delivered).length;
  const totalFailed = campaign.recipients.filter(r =>
    r.clicked || r.replied || r.attachmentOpened || r.macroEnabled || r.dataEntered
  ).length;

  if (totalDelivered === 0) return 0;
  return ((totalFailed / totalDelivered) * 100).toFixed(1);
}

Industry Benchmarks:

PPP RangeRatingContext
0-5%ExcellentWell-trained organization
5-15%GoodRegular training in place
15-30%AverageIndustry baseline for new programs
30-50%PoorNeeds immediate attention
50%+CriticalHigh-risk organization

Field Reference

Campaign Fields

FieldTypeDescription
campaign_idintUnique campaign identifier
namestringCampaign name
statusstringCurrent status (created, scheduled, in_progress, completed)
create_datedatetimeWhen campaign was created
start_datedatetimeScheduled start date
end_datedatetimeCampaign end date
duration_typestringHow long the campaign runs (e.g., one_week, two_weeks)
send_durationstringEmail delivery spread period
track_durationstringHow long to track interactions after delivery
frequency_typestringOne-time, weekly, bi-weekly, monthly
phishing_template_idintTemplate used for the phishing email
landing_page_idintLanding page shown after click
groupsarrayTarget groups for the campaign

Phishing Security Test (PST) Fields

FieldTypeDescription
pst_idintUnique security test identifier
statusstringTest status
started_atdatetimeWhen the test began
categoryobjectTemplate category info
templateobjectEmail template details
landing_pageobjectLanding page details
scheduled_countintRecipients scheduled to receive
delivered_countintEmails successfully delivered
opened_countintEmails opened
clicked_countintLinks clicked
replied_countintReplies sent
attachment_open_countintAttachments opened
macro_enabled_countintMacros enabled
data_entered_countintData entered on landing page
reported_countintReported via PAB
bounced_countintEmails bounced

Recipient Fields

FieldTypeDescription
recipient_idintUnique recipient identifier
pst_idintParent security test
userobjectUser details (name, email, department)
scheduled_atdatetimeWhen email is scheduled
delivered_atdatetimeWhen email was delivered
opened_atdatetimeWhen email was opened
clicked_atdatetimeWhen link was clicked
replied_atdatetimeWhen reply was sent
attachment_opened_atdatetimeWhen attachment was opened
macro_enabled_atdatetimeWhen macro was enabled
data_entered_atdatetimeWhen data was entered
reported_atdatetimeWhen it was reported
bounced_atdatetimeWhen email bounced
ipstringIP address of interaction
browserstringBrowser used for click

MCP Tools

ToolDescriptionParameters (required in bold)
knowbe4_phishing_campaigns_listList all phishing campaignspage, per_page
knowbe4_phishing_campaigns_getGet campaign details, including its associated security testscampaign_id
knowbe4_phishing_campaign_testsList the Phishing Security Tests belonging to one campaigncampaign_id, page, per_page
knowbe4_phishing_security_tests_listList Phishing Security Tests across all campaignspage, per_page
knowbe4_phishing_security_test_getGet detailed results for one PST — PPP, clicked/opened/reported countspst_id
knowbe4_phishing_security_test_recipientsRecipient-level results for one PST: who clicked, opened, reportedpst_id, page, per_page
knowbe4_phishing_security_test_recipientOne recipient's result within one PSTpst_id, recipient_id

There is no campaign-level recipient tool. Recipients hang off a Phishing Security Test, never off a campaign, so "who clicked in this campaign" is two steps: knowbe4_phishing_campaign_tests to get the campaign's PSTs, then knowbe4_phishing_security_test_recipients per PST. A recipient ID is only meaningful alongside the pst_id it came from — knowbe4_phishing_security_test_recipient requires both.

There is no phishing-template tool. Nothing in this plugin lists the template library or reads a single template's content, and no page/ per_page sweep will find one. Template selection is console work. Campaign and PST records name the template that was used, which is enough to compare how templates performed after the fact, but not to browse what is available before a send.

None of the list tools filter by status or date. Narrowing to "completed campaigns since March" means paginating and filtering client-side.

Common Workflows

Review Campaign Results

  1. List campaigns to find the target campaign
  2. Get campaign details for overview metrics
  3. List security tests within the campaign
  4. Get security test results for detailed interaction counts
  5. List recipients to identify who clicked/failed
  6. Calculate PPP from the results

Identify High-Risk Users

  1. List completed campaigns from a date range
  2. Get recipients who clicked or entered data across campaigns
  3. Cross-reference with user profiles for repeat offenders
  4. Generate report of users who failed multiple tests

Compare Campaign Performance Over Time

  1. List all campaigns sorted by date
  2. Get PPP for each campaign
  3. Track trend -- PPP should decrease over time with training
  4. Identify anomalies -- sudden PPP increase may indicate new attack vector or template difficulty

Post-Campaign Remediation

  1. Get failed recipients from completed campaign
  2. Enroll failed users in remedial training
  3. Schedule follow-up test targeting the same users
  4. Compare results to measure improvement

Error Handling

Common API Errors

CodeMessageResolution
400Invalid campaign parametersCheck date formats and required fields
401Invalid API tokenVerify KNOWBE4_API_KEY
403Insufficient permissionsAPI token needs Reporting permissions
404Campaign not foundVerify campaign_id exists
429Rate limit exceededImplement backoff (see api-patterns)

Data Considerations

IssueCauseResolution
Zero delivered countCampaign just startedWait for delivery to complete
High bounce rateInvalid email addressesClean user list before next campaign
No reported countPAB not deployedInstall Phish Alert Button
Opened count higher than deliveredEmail previews/security scannersFilter by user agent if available

Best Practices

  1. Vary templates -- Use different phishing scenarios to avoid pattern recognition
  2. Spread delivery -- Send over days/weeks, not all at once, to avoid "water cooler effect"
  3. Track trends, not individual tests -- Single campaigns can be noisy; look at 3-6 month trends
  4. Combine with training -- Auto-enroll failed users in relevant training modules
  5. Use realistic scenarios -- Match templates to actual threats your clients face
  6. Baseline first -- Run an initial campaign before training to establish baseline PPP
  7. Report to leadership -- Share PPP trends with management to justify security awareness investment
  8. Test all levels -- Include executives and IT staff, not just general users
  9. Respect local regulations -- Some regions have restrictions on simulated phishing
  10. Set proper tracking duration -- Allow 72 hours minimum for accurate click data

Related Skills

Signals

GitHub stars
45
Forks
24
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
knowbe4-phishing
Source
github.com/wyre-ai/msp-claude-plugins