Skip to main content
TrustRadius
KnowBe4 PhishER/PhishER Plus

KnowBe4 PhishER/PhishER Plus

Overview

What is KnowBe4 PhishER/PhishER Plus?

PhishER is presented as a lightweight Security Orchestration, Automation and Response (SOAR) platform to orchestrate threat response and manage the high volume of potentially malicious email messages reported by users. And, with automatic prioritization of emails, PhishER helps InfoSec and…

Read more
Recent Reviews

Phishing Hero!

10 out of 10
March 13, 2024
Incentivized
We use KnowBe4 PhishER with our KMSAT. KnowBe4 PhishER is basically helping us to resolve our biggest security problem and that is …
Continue reading
Read all reviews

Awards

Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards

Popular Features

View all 5 features
  • Company-wide Incident Reporting (52)
    7.8
    78%
  • Live Response for Rapid Remediation (55)
    7.8
    78%
  • Centralized Dashboard (62)
    7.8
    78%
  • Machine Learning to Prevent Incidents (54)
    7.7
    77%

Reviewer Pros & Cons

View all pros & cons
Return to navigation

Pricing

View all pricing

3001-5000 Monthly Pricing Per Seat

$0.50

Cloud
per month (billed annually) per seat

2001-3000 Monthly Pricing Per Seat

$0.55

Cloud
per month (billed annually) per seat

1001-2000 Monthly Pricing Per Seat

$0.65

Cloud
per month (billed annually) per seat

Entry-level set up fee?

  • Setup fee optional
For the latest information on pricing, visithttps://www.knowbe4.com/pricing-phisher

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services
Return to navigation

Features

Incident Response Platforms

Incident response (IR) platforms guide countermeasures against a security breach and deploy preplanned, automated threat responses

7.6
Avg 8.5
Return to navigation

Product Details

What is KnowBe4 PhishER/PhishER Plus?

PhishER is a platform for managing the high volume of potentially malicious email messages reported by users. With automatic prioritization of emails, PhishER aims to help InfoSec and Security Operations team cut through the inbox noise and respond to the most dangerous threats more quickly.

PhishER is a web-based platform with critical worksteam functionality that serves as a phishing emergency room to identify and respond to user-reported messages. With PhishER, users are able to automate the workstream of 90% of reported emails that are not threats, freeing up incident response resources.

PhishER is available as a stand-alone product or as an optional add-on for KnowBe4 customers that want to automatically prioritize and manage potentially malicious messages that were reported through the KnowBe4 Phish Alert Button. PhishER Plus is an upgraded subscription level that includes all of the features from PhishER with additional enhancements and AI-validated crowdsourced data. PhishER Plus was developed to help supercharge an organization’s email security defenses. It does this by automatically blocking phishing attacks that traditional Security Email Gateways (SEGs) miss and removes these missed threats from users’ inboxes.

KnowBe4 PhishER/PhishER Plus Features

Incident Response Platforms Features

  • Supported: Company-wide Incident Reporting
  • Supported: Integration with Other Security Systems
  • Supported: Centralized Dashboard
  • Supported: Machine Learning to Prevent Incidents
  • Supported: Live Response for Rapid Remediation

Additional Features

  • Supported: Automatic Message Prioritization

KnowBe4 PhishER/PhishER Plus Screenshots

Screenshot of This is a diagram of the PhishER workflow. Reviewing the PhishER workflow before getting started will provide an understanding of how PhishER, PhishRIP and PhishFlip work.Screenshot of The Reports screen will display five different dashboards of information.Screenshot of When entering the PhishER platform, the first screen that appears is the Dashboard. Here, a quick overview of the PhishER platform will appear.

KnowBe4 PhishER/PhishER Plus Video

Introduction to PhishER

KnowBe4 PhishER/PhishER Plus Competitors

KnowBe4 PhishER/PhishER Plus Technical Details

Deployment TypesSoftware as a Service (SaaS), Cloud, or Web-Based
Operating SystemsUnspecified
Mobile ApplicationNo
Supported CountriesGlobal

KnowBe4 PhishER/PhishER Plus Downloadables

Frequently Asked Questions

PhishER is presented as a lightweight Security Orchestration, Automation and Response (SOAR) platform to orchestrate threat response and manage the high volume of potentially malicious email messages reported by users. And, with automatic prioritization of emails, PhishER helps InfoSec and Security Operations team cut through the inbox noise and respond to the most dangerous threats more quickly.

Cofense Triage, Infosec IQ, and Proofpoint Threat Response Auto-Pull are common alternatives for KnowBe4 PhishER/PhishER Plus.

Reviewers rate Company-wide Incident Reporting and Centralized Dashboard and Live Response for Rapid Remediation highest, with a score of 7.8.

The most common users of KnowBe4 PhishER/PhishER Plus are from Mid-sized Companies (51-1,000 employees).
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(160)

Attribute Ratings

Reviews

(1-8 of 8)
Companies can't remove reviews or game the system. Here's why
Score 10 out of 10
Vetted Review
Verified User
Incentivized
I use KnowBe4 PhishER as a Security Orchestration, Automation and Response (SOAR) to manage, analyse, respond to the very high volume of emails potentially dangerous reported by my company users with the "Phish alert button." Thanks to this platform I was able to automate 90% of the workstream linked to the reported emails by end users, as the platform automatically analyse the message and classify it as a threats, spam or clean. Based on this classification and based also on tags assigned I'm able to identify the dangerous emails and react to prevent threats. Very useful is the ability to create rules and actions, so I can give an immediate response to the user that report the email as suspicious and confirm if is a threats, spam or not dangerous, in this way I improve also the ability of the users to recognise a phishing and spot it. I use this platform every day and few times a day to monitoring email reported to identify spear phishing, massive spam or massive phishing email, this allow me to take action to prevent threats and avoid that others users that receive similar r email click on dangerous link or enter credential. The platform is easy to implement and can be integrated with other service providers like Microsoft for example the possibility to activate the PhishRIP allow the deletion of dangerous email in the user recipient for example before they read it and take an action that can be dangerous if is not able to spot that is a threat.
  • Analysis and classification of phishing emails using machine learning
  • Response to reporting users with personalised emails template
  • Automatic response and actions using integration with Microsoft
  • Good dashboard with reporting and KPI
  • Integration with others product to improve scan and analysis
  • It improves users' security awareness and behavior as receiving an immediate response with the analysis result improves the ability to recognize a phishing email
  • The lack of recognising email dangerous with QR code
  • Improve the alert/notification system to automatically advise the platform administrator in case of massive threats.
  • Decrease in uncategorized emails
KnowBe4 PhishER is very efficient and fast in detecting malicious emails, machine learning allows you to constantly improve the analysis of messages so in the event of receiving numerous malicious emails you can easily manage the incident response automatically, reducing the risk of expansion of the threat, blocking senders and deleting messages before they are read by other users.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
The school has implemented the PhishER add-on for easily reporting suspicious emails. PhishER’s tools analyze these reports, reducing the workload on IT staff. PhishER streamlines the process of identifying, reporting, and responding to phishing attempts, thus saving valuable IT resources. PhishER is integrated into the school’s Gmail and IT security systems to prevent attacks through end user awareness and reporting.
  • The platform offers a simple, one-click reporting button for end-users.
  • Allows teachers to report suspicious emails without needing technical expertise.
  • The IT department is able to review all suspicious email in one dashboard.
  • Enhancing the automated response capabilities, such as directly initiating remediation processes or integrating with other cybersecurity tools, could further streamline the threat management process.
  • Implementing a feedback system where users can be informed about the outcome of their reported emails might encourage more proactive engagement.
  • the reporting tool is not as streamlined on mobile devices as it is on desktops. Enhancing mobile functionality would be beneficial
With a mix of staff, teachers, and potentially older students handling sensitive information, PhishER’s reporting tools are ideal for creating a safer email environment. The platform’s ease of access and user-friendly reporting mechanism is particularly beneficial for dispersed workforces.
Richard Fantozzi, Jr | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
Incentivized
We use it to automate the response and quarantine of phishing emails in conjunction with Office 365. This has greatly reduced the workload and response time of our security team. This has also helped improve the response to phishing emails to users to improve their awareness of what is and what is not a phishing email. One other use is the integration of webhooks to Microsoft Sentinel allow us to investigate incidents from Email
  • Identify clean, spam or bad emails
  • Speed of identification and response
  • Automation of reporting to integrated systems
  • Provdining supporting evidence for bad emails
  • Initial setup possible with a default setup that utilizes all functionality that could be turned off/on and modified per customers needs
  • Supporting multiple actions per foiund email instead of multiple rules needed to fire an email and a webhook
Less than a half hour of setup and we where ready to go with way more automatation that we had before which has proven to be highly effective especially when there are emails that make it through like in BEC scenerios with trusted 3rd parties.
Adam Kuhn | TrustRadius Reviewer
Score 2 out of 10
Vetted Review
Verified User
Incentivized
My goal was tight integration with Microsoft 365 and quick blocking of phishing campaigns. Previously, blocking was a manual process, but with KnowBe4 PhishER - I wanted reporting of real threats to trigger protective action.
  • Integrate with M365
  • Integrate with KnowBe4 Phish Reporting
  • Provide feedback to staff
  • Setup of rules and actions is still a little confusing.
  • I don't want to create too much traffic for the end user - need to tweak.
  • I still want to see what users are submitting - a little tricky to figure out, but getting help.
I've unfortunately had to downgrade my recommendation. I think the product hasn't been refined yet. By crowdsourcing anti-spam services, you end up with a system that flags legitimate email as high-confidence phishing messages. Defender users are no longer allowed to release their own quarantine items. Thus, the end result is a huge burden on IT to release legit messages.
Keith Smith | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
Incentivized
Phishing is a constant battle. PhishER helps augment our security team by giving us the ability to automate tasks. We're able to use the built-in AI and ML to review reported or suspected phishing messages and take action on them without the need for a Security Analyst to review each report individually.
  • Automation
  • Reporting
  • Security
  • Blacklist integration
PhishER is a great tool for offloading tasks that would normally be handled by Security Analysts. When integrated with M365, it can automatically remove messages from the mailboxes of all users who received and reported a suspected message. This happens almost instantly with no need for someone to review and triage the report. And, since it can be based on confidence level, we don't worry about accidentally removing legitimate messages.
Score 10 out of 10
Vetted Review
Verified User
We have a high rate of items reported via Phish ER (approximately 1000 a month) for a department of 2 people.
We setup rules in Phish Alert to respond to the most common items reported.
We have also setup rules to all the InfoSec team to focus on those emails that have not been responded to and/or actual threats.
By utilizing Phish ER we have been able to take reduce the amount of time spent addressing items report from 2 hours a day down to < 20 minutes.
Additionally with the recent update to allow us to push blocks to M365 we are seeing a large reduction in the number of spam and scam emails.
  • Minimal false positives
  • Ease of use in defining and designing flows
  • Ease of use in defining and designing response templates
  • Reporting - the reports in place are useful but allowing for more details would be helpful
  • More Quick Actions
Ease of implementation.
Time savings.
Use in identifying trends.
February 02, 2023

Great Product Suite

Score 9 out of 10
Vetted Review
Verified User
Incentivized
Our organization utilizes PhishER in several ways. We utilize PhishML to assist with our research of messages and our prioritization of the messages we deem as "Vaild". We utilize PhishRIP to assist our O365 quarantining of new incoming messages so that our users experience less spam. We have integrated the Phish Alert button across all our Office 2016 users as well as into our Office 365 users so that they can reported suspected phishing emails to our team. We have also started using PhishFLIP to replace active Phishing attempts into simulated spoofs to test user responses.
  • Phish Alert button is a simple way for users to report phishing attempts.
  • PhishFLIP really increases the look and feel of simulated attempts that we test our users with.
  • PhishRIP cut down on our average email/user counts and have increased our quarantining abilities.
  • Scheduling of simulated emails.
  • Setup of the rules to categorize messages
KnowBe4 is an amazing company and has several products that can really increase your Situational Awareness training program. PhishER is just a suite of programs that assist in user knowledge for phishing attempts, and the filtering, analyzing and quarantining of theose Real Phishing attempts. It's an amazing product that should be in all IT Team's arsenal.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
We had a fairly serious phishing problem and needed to combine some awareness training along with simulated phishing and quarantine capability and PhishER from KnowBe4 checked all the boxes.
  • PhishER's connection to our O365 environment is good, it allows users to click the Phish Alert button to report a phish and this kicks off a back-end action that scans all users' inboxes and quarantines similar phishing emails it finds.
  • The KnowBe4 security awareness training, the Phish Alert Button, and simulated phishing are all tightly integrated, it's a "system" rather than ad hoc solutions.
  • #1 thing KnowBe4 needs to improve is using their PhishML to proactively find and quarantine phishing emails rather than only relying on the reactive click by a user. There's still a huge risk hole they are not filled by not providing this functionality.
I think KnowBe4's customer service is outstanding, we have a "Customer Success Manager" who is very helpful and proactive and support was also very helpful during our implementation.
Return to navigation