Skip to main content
TrustRadius
KnowBe4 PhishER/PhishER Plus

KnowBe4 PhishER/PhishER Plus

Overview

What is KnowBe4 PhishER/PhishER Plus?

PhishER is presented as a lightweight Security Orchestration, Automation and Response (SOAR) platform to orchestrate threat response and manage the high volume of potentially malicious email messages reported by users. And, with automatic prioritization of emails, PhishER helps InfoSec and…

Read more
Recent Reviews

Phishing Hero!

10 out of 10
March 13, 2024
Incentivized
We use KnowBe4 PhishER with our KMSAT. KnowBe4 PhishER is basically helping us to resolve our biggest security problem and that is …
Continue reading
Read all reviews

Awards

Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards

Popular Features

View all 5 features
  • Company-wide Incident Reporting (52)
    7.8
    78%
  • Live Response for Rapid Remediation (55)
    7.8
    78%
  • Centralized Dashboard (62)
    7.8
    78%
  • Machine Learning to Prevent Incidents (54)
    7.7
    77%

Reviewer Pros & Cons

View all pros & cons
Return to navigation

Pricing

View all pricing

3001-5000 Monthly Pricing Per Seat

$0.50

Cloud
per month (billed annually) per seat

2001-3000 Monthly Pricing Per Seat

$0.55

Cloud
per month (billed annually) per seat

1001-2000 Monthly Pricing Per Seat

$0.65

Cloud
per month (billed annually) per seat

Entry-level set up fee?

  • Setup fee optional
For the latest information on pricing, visithttps://www.knowbe4.com/pricing-phisher

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services
Return to navigation

Features

Incident Response Platforms

Incident response (IR) platforms guide countermeasures against a security breach and deploy preplanned, automated threat responses

7.6
Avg 8.5
Return to navigation

Product Details

What is KnowBe4 PhishER/PhishER Plus?

PhishER is a platform for managing the high volume of potentially malicious email messages reported by users. With automatic prioritization of emails, PhishER aims to help InfoSec and Security Operations team cut through the inbox noise and respond to the most dangerous threats more quickly.

PhishER is a web-based platform with critical worksteam functionality that serves as a phishing emergency room to identify and respond to user-reported messages. With PhishER, users are able to automate the workstream of 90% of reported emails that are not threats, freeing up incident response resources.

PhishER is available as a stand-alone product or as an optional add-on for KnowBe4 customers that want to automatically prioritize and manage potentially malicious messages that were reported through the KnowBe4 Phish Alert Button. PhishER Plus is an upgraded subscription level that includes all of the features from PhishER with additional enhancements and AI-validated crowdsourced data. PhishER Plus was developed to help supercharge an organization’s email security defenses. It does this by automatically blocking phishing attacks that traditional Security Email Gateways (SEGs) miss and removes these missed threats from users’ inboxes.

KnowBe4 PhishER/PhishER Plus Features

Incident Response Platforms Features

  • Supported: Company-wide Incident Reporting
  • Supported: Integration with Other Security Systems
  • Supported: Centralized Dashboard
  • Supported: Machine Learning to Prevent Incidents
  • Supported: Live Response for Rapid Remediation

Additional Features

  • Supported: Automatic Message Prioritization

KnowBe4 PhishER/PhishER Plus Screenshots

Screenshot of This is a diagram of the PhishER workflow. Reviewing the PhishER workflow before getting started will provide an understanding of how PhishER, PhishRIP and PhishFlip work.Screenshot of The Reports screen will display five different dashboards of information.Screenshot of When entering the PhishER platform, the first screen that appears is the Dashboard. Here, a quick overview of the PhishER platform will appear.

KnowBe4 PhishER/PhishER Plus Video

Introduction to PhishER

KnowBe4 PhishER/PhishER Plus Competitors

KnowBe4 PhishER/PhishER Plus Technical Details

Deployment TypesSoftware as a Service (SaaS), Cloud, or Web-Based
Operating SystemsUnspecified
Mobile ApplicationNo
Supported CountriesGlobal

KnowBe4 PhishER/PhishER Plus Downloadables

Frequently Asked Questions

PhishER is presented as a lightweight Security Orchestration, Automation and Response (SOAR) platform to orchestrate threat response and manage the high volume of potentially malicious email messages reported by users. And, with automatic prioritization of emails, PhishER helps InfoSec and Security Operations team cut through the inbox noise and respond to the most dangerous threats more quickly.

Cofense Triage, Infosec IQ, and Proofpoint Threat Response Auto-Pull are common alternatives for KnowBe4 PhishER/PhishER Plus.

Reviewers rate Company-wide Incident Reporting and Centralized Dashboard and Live Response for Rapid Remediation highest, with a score of 7.8.

The most common users of KnowBe4 PhishER/PhishER Plus are from Mid-sized Companies (51-1,000 employees).
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(160)

Attribute Ratings

Reviews

(1-17 of 17)
Companies can't remove reviews or game the system. Here's why
Score 9 out of 10
Vetted Review
Verified User
Incentivized
KnowBe4 PhishER has taken the place of our IT security and best practices training, as well as our phishing testing. The huge library of training material gives us a lot of flexibility with what we are training on and allows more focused targeted training efforts. There is also a huge library of phishing simulation templates ranging from all types of difficulties. This customization gives me the ability to hone in on things my team might actually see in the real world, and I can create or customize my own templates to be even more targeted.
  • Huge library of media
  • Real world examples and frequent updates
  • Communicative account managers
  • It can be a bit tedious to see specific results of phishing test (per user results)
KnowBe4 PhishER is best used by companies who aren't able or do not have the resources to create or customize their own internal training and learning material. KnowBe4 PhishER offers a lot of flexibility within their own system, and allows for admins to narrow the training and testing focus to very specific industries, tools, and needs. If you are able to create hyper customized material or just need extremely basic training, it may not be the best option, but should definitely be considered.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
I use KnowBe4 PhishER as a Security Orchestration, Automation and Response (SOAR) to manage, analyse, respond to the very high volume of emails potentially dangerous reported by my company users with the "Phish alert button." Thanks to this platform I was able to automate 90% of the workstream linked to the reported emails by end users, as the platform automatically analyse the message and classify it as a threats, spam or clean. Based on this classification and based also on tags assigned I'm able to identify the dangerous emails and react to prevent threats. Very useful is the ability to create rules and actions, so I can give an immediate response to the user that report the email as suspicious and confirm if is a threats, spam or not dangerous, in this way I improve also the ability of the users to recognise a phishing and spot it. I use this platform every day and few times a day to monitoring email reported to identify spear phishing, massive spam or massive phishing email, this allow me to take action to prevent threats and avoid that others users that receive similar r email click on dangerous link or enter credential. The platform is easy to implement and can be integrated with other service providers like Microsoft for example the possibility to activate the PhishRIP allow the deletion of dangerous email in the user recipient for example before they read it and take an action that can be dangerous if is not able to spot that is a threat.
  • Analysis and classification of phishing emails using machine learning
  • Response to reporting users with personalised emails template
  • Automatic response and actions using integration with Microsoft
  • Good dashboard with reporting and KPI
  • Integration with others product to improve scan and analysis
  • It improves users' security awareness and behavior as receiving an immediate response with the analysis result improves the ability to recognize a phishing email
  • The lack of recognising email dangerous with QR code
  • Improve the alert/notification system to automatically advise the platform administrator in case of massive threats.
  • Decrease in uncategorized emails
KnowBe4 PhishER is very efficient and fast in detecting malicious emails, machine learning allows you to constantly improve the analysis of messages so in the event of receiving numerous malicious emails you can easily manage the incident response automatically, reducing the risk of expansion of the threat, blocking senders and deleting messages before they are read by other users.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
The PhishER platform is an invaluable tool for our organization as it gives us real time insight when we are 'under attack' by a bad actor (or actors). We are able to identify trends, targeted users and methods used by the bad actors in trying to gain access or steal information. On top of this, the PhishRIP feature integrates with our GSuite and scans/quarantines other instances of reported emails that are deemed malicious.
  • The machine based learning does a great job of correctly identifying safe vs. malicious emails.
  • PhishRIP does an excellent job of finding and quarantining similar emails from other users accounts.
  • The reports give us a real time insight into trends and campaigns launched by bad actors.
  • Somtimes the PAB (or Phish Hook) has to have its permissions revalidated. This is a quick fix, but takes some knowledge.
  • I honestly can't think of any other shortcomings at this time.
  • See #1
I can't say enough good things about PhishER. While Google Mail does have the ability to report spam and malicious content, the reporting isn't as user friendly. Having PhishER gives us insight into the email landscape of our end users, and even affords us the ability to retroactively learn some of the techniques used by bad actors so that we can further educate our end users.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
We use it to facilitate in the review of reported suspected phishing emails. It provides ease of review as all necessary information needed to determine a suspected email as phishing is readily available. It also provides automation for known false positives.
  • automation tasks for known false positives
  • providing information for phishing email determination
  • informative dashboard
  • setting up automated tasks
  • rooms is not really understood
  • customizable reports
best for managing phishing email reporting
Score 9 out of 10
Vetted Review
Verified User
Incentivized
KnowBe4 PhishER perfectly solved our issues with responding to phishing emails. Previously, responding to malicious emails was a completely manual process, and we could not respond nearly as quickly or efficiently as we wanted to.
With KnowBe4 PhishER, the process is now highly automated, and we can remove phishing emails from dozens of inboxes in just a few clicks.
Our users appreciate it because they receive much quicker feedback on clean emails.
IT appreciates it because it makes our job a breeze and lets us focus on the important elements of incident response.
Management appreciates it because it helps keep our institution safer and gives them excellent reporting metrics.
  • Quick phishing email review
  • Automated analysis and tagging
  • Immediate quarantine and removal
  • Quicker / more efficient PhishRIP
  • Improved "Find Similar Messages" filtering options
  • Improved notification options
KnowBe4 PhishER is highly efficient and cost effective, making it a great fit for small to medium businesses that are considered about phishing attacks. KnowBe4 PhishER helps small teams respond to phishing emails with the resources and efficiency of larger teams. It fits well with existing KnowBe4 clients, as the Phish Alert button is already in use and training modules for coworkers are available to instruct how to use the button.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
PhishER is used to automate the detection, response, and remediation of phishing emails as well as triage messages in general. It automates the process of breaking down the email headers and makes a MUCH faster and simpler response for a small IT department.<br><br>PhishRIP and PhishFlip are superb addons that allow us to scan our entire Exchange 365 environment for other copies of phishing mail and instantly purge them from other user's mailboxes that haven't reported them yet - and then turn around and use that very message as a training template with KnowBe4 to test users.<br><br>We can automate processes, scanning, detection, message flagging, and alerting from PhishER - it takes a bit to get set up well, but then it's cheaper than an FTE being hired on to help manage it all!
  • automated message header decoding
  • remote removal/deletion of phishing mails from entire mail environment
  • fast and easy false positive/clean identification
  • easier customization of automation rules
  • better end-user feedback to message submitter of submission status
Small IT department use is great as it can be quite set-and-forget and saves money versus hiring.

Anything less than 10 users submitting messages to PhishER, and it's probably not worth the cost of the subscription in comparison to 1:1 communication.

If you have an email system that it doesn't tie well with, it'll be more difficult to get the really really nice integrations working in a way that truly saves time/effort/money.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
We have the Phish Alert Button as part of our subscription. My team was overwhelmed by the alerts sent by users. PhishER, uses automation to cut down on the amount of alerts we need to handle, leaving us with only the high priority or outliers.

The ROI is rapid and your security team will be able to focus on higher value tasks. It is worth the time to work with a KnowBe4 engineer to fine tune the policies for your environment.

Looking forward to seeing how KnowBe4 can integrate AI into this product for even more automation.

  • Reduces the noise vs signal ratio
  • Saves your team time
  • Encourages users to report phishing emails
  • Automates a task that your team hates doing
  • Improve AI for greater filtering
  • Better explanations of the policy settings and rules and how to tweak them for increased results
  • Automated gamification/rewards for end users to encourage reporting actual phishing
  • Automate sending executive level reports to maintain c-suite support and show ROI
Saves your cyber team time. Eliminates something that your team doesn't like doing and will put off.

If you have the PAB for users to report phishing, then you need PhishER.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
We were looking for a way to ensure all employees are up to date in all of the security trainings to help keep our competitive advantage. KnowBe4 PhishER has enabled us to keep automated track of who has taken what training seamlessly and efficiently. We really enjoy the content of the courses and the flexibility of training.
  • Training content is well crafted and professional
  • Reporting is quick and easy
  • They make learning fun and entertaining
  • Too many videos/training videos are released at once
  • Inside Man has been going on tooooooooo long
KnowBe4 PhishER is great for all sized companies and is very easy to use. We are a smaller company and it works very well here. I can see this fitting into any sized company and adding immense value to their organization
September 15, 2023

Great product

Score 10 out of 10
Vetted Review
Verified User
Incentivized
We use PhishER to remove phishing emails from users inboxes. We also use it to block senders from sending malicious emails.
  • Removing malicious emails from users inbox
  • Blocking emails from malicious senders
  • Identifying if emails have malicious attachments or links.
  • One issue is when an email has large attachments, PhishER does not work correctly.
PhishER is great for removing emails from users inbox and for identifying if emails have malicious attachments or links.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
KnowBe4 PhishER helps to address the constant influx of reported phishing emails that our end-users are exposed to. KnowBe4 PhishER allows for our technicians to rapidly respond to these reports to investigate and automate actions to help protect our end users from malicious emails.
  • Automation
  • Email details
  • Integration with other APIs
  • Further customization of auto-actions would be beneficial
I think KnowBe4 PhishER is a perfect soluation for organizations that receive a great deal of phishing emails but do not have the manpower to address all of the reports coming in from end users.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
We primarily use KnowBe4 PhishER to perform remediation and forensics on phishing emails in our organization. KnowBe4 PhishER gives us the ability to easily analyze emails, headers, and also strip the malicious content from emails as well as remove similar emails from our entire org's email servers. Automated remediation is our biggest use case.
  • Email forensics
  • Automated remediation
  • Converting real phishing emails into test emails
  • Navigation and UI can be a little clunky to use
  • Better training on usage
I think KnowBe4 PhishER is good for smaller teams that want an easy way to analyze and remediate phishing emails in an organization. It is plenty capable and the machine learning is mostly accurate. There is no active scanning of emails since users need to report these emails, so it will not replace an email protection service. But it is nice to be able to flip real phishing emails and be able to use them as phishing test emails.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
We implement it on 365, and encourage our users to report any suspicious emails. This encourages awareness, and prevents users from getting caught by a malicious email. The functionality of then removing other similar emails once the threat has been identified is fantastic, and being able to phish rip the email to reintroduce it as a test really ups the game for learning and being prepared for other malicious emails.
  • Increases awareness by giving an option when a user is unsure.
  • Prevents widespread hacks by removing an email from all affected users once it is reported.
  • provides learning opportunities by cloning emails for simulation
  • The quarantine function is lacking. Further integration with the existing 365 quarantine could really make a difference.
  • The UI is a little bit feature heavy and clunky. There is a lack of clarity on how to properly set up certain things including remedial training on a failed simulation.
PhishER is a product which is really built to function in any situation. Anywhere a corporate email account is used, its a valuable tool. The only downside is that it does require a structure, such as an admin, so a company should have a minimum number of employees to truly make it effective.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
Currently KnowBe4 PhishER is being used across all departments within the organization. This has addressed the business problem of suspected phishing remediation. Through machine learning, integrations with VirusTotal, the PhishAlert button, and the ability to automatically respond to messages, we have drastically slashed the amount of time that analysts and end-users spend in phishing responses.
  • Machine learning evaluation
  • Automation of response
  • Setting custom thresholds
  • Quarantining messages before end-users read them
  • Search inboxes for similar messages
  • Custom rules can be bothersome to create
  • Inability to log directly into PhishER, must go through main console first
  • PhishRIP can require too much information when searching for similar messages
PhishER works wonderfully for organizations in which end-users are prone to reporting all messages. By having automated responses it allows for non-malicious messages to be responded to without requiring analyst intervention. The PhishRIP functionality can be less useful because it requires a minimum of two fields to be selected for searching. This can result in issues where a threat actor has modified the body or subject to add a more personal touch to the malicious email.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
We use KnowBe4 PhishER as part of our email analysis when users report emails to the team and also have some visibility what users report and how often. Some business problems this product addresses is the need to free up team resources to review emails on a daily basis. Another problem this product addresses is that it creates additional flexibility within the overall workflow. For example, when a ticket needs to get created internally for review, it's just one click of a button. This product helps automate some of our tasks that would normally be a manual effort.
  • Provides high level reporting
  • Integration with ticketing system such as Jira
  • The flexibility of creating rules that align with various workflows
  • Easy to use interface
  • The number of action items could be expanded to include more functionality
  • The option to schedule reports and send to various team members to eliminate the need to go into the console on a weekly or monthly basis
  • Additional widgets to expand the dashboard functionality
The KnowBe4 PhishER is a great product that integrates well with the KnowBe4 security education platform and Jira service desk. Those two integrations make the general workflow effortless for someone who is in the product on a daily basis. This reduces manual work and allows our team to be productive and work on other projects.

This product also gives the team visibility on what is being reported and help determine if the email reported is localized or widespread throughout the organization. Meaning, depending on how many people report an email based on location and job roles.

This solution is well suited for an organization or team who would like to automate the guess work of determining if a email is a phish, spam, or safe. Additionally, have that one click response to the user who reported to get additional insight on if they did respond to the email or clicked on that was determined to be a real phishing email.

Score 10 out of 10
Vetted Review
Verified User
Incentivized
With today's growing phishing attack surface, the need for a reporting and management system is inevitable. Manually managing phishing responses is cumbersome and downright unsafe. KnowBe4 PhishER allows us to quickly and safely manage our phishing reports.
  • Detailed Phishing Indicators
  • Automatic Categorization of Phishing Emails
  • Multi-Admin Workflow
  • Automated Responses
  • Setup a bit tricky out of the box. I prefer self-service setups that are easy to use, but KnowBe4 PhishER does offer great service for their products.
KnowBe4 PhishER is suited for any decently sized organization. No matter the business, phishing is a severe threat today.
August 11, 2021

Time saver!

Score 9 out of 10
Vetted Review
Verified User
Incentivized
KnowBe4 is currently used throughout the organization. It helps us categorize and quarantine all threats that arrive in our users' email inboxes. By integrating KnowBe4 into our security infrastructure, we have found that it has saved us time and money. It helps us save time and allows us to focus on more important issues and projects.
  • Machine learning
  • Automating threat management
  • Alert configuration
  • Better integration to outlook
  • Better explanations on email structure presentation
  • More training available regarding email threat analysis
This is a necessity if you don't want to find yourself dealing with all the reported threats one by one.
You will see the benefits from day one and the more the machine learning algorithm is fed, the better it gets.
An example scenario is when an employee reports a threat through the add-in installed and deployed on all Outlook clients. The threat is then sent to the PhishER platform, where the administrator inspects it, analyzes it and takes action based on the results.
If it is a threat, it is retained and used as an example to feed the machine learning algorithm, if not, the email is released and sent back to the user with a comment telling the user it's a safe email.
March 14, 2021

Added Security

Score 9 out of 10
Vetted Review
Verified User
Incentivized
KnowBe4 PhishER is that extra layer of protection for email threats. You are able to set up custom rules and actions to automatically sort out phishing attempts as well as set them to spam or clean. Being in an industry not known for tech savyness, this system has added that security blanket for us with phishing attempts.
  • Automation.
  • Easy of Use.
  • Extra Security.
  • Difficult to get set-up originally.
It has been such a great addition to our systems and is really good with tracking CEO spoof and other common threats. Most everything users report is actually just spam, but I can create rules to automatically filter those and only show me the bigger potential issues that we may see.
Return to navigation