Skip to main content
TrustRadius
KnowBe4 PhishER/PhishER Plus

KnowBe4 PhishER/PhishER Plus

Overview

What is KnowBe4 PhishER/PhishER Plus?

PhishER is presented as a lightweight Security Orchestration, Automation and Response (SOAR) platform to orchestrate threat response and manage the high volume of potentially malicious email messages reported by users. And, with automatic prioritization of emails, PhishER helps InfoSec and…

Read more
Recent Reviews

Phishing Hero!

10 out of 10
March 13, 2024
Incentivized
We use KnowBe4 PhishER with our KMSAT. KnowBe4 PhishER is basically helping us to resolve our biggest security problem and that is …
Continue reading
Read all reviews

Awards

Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards

Popular Features

View all 5 features
  • Company-wide Incident Reporting (52)
    7.8
    78%
  • Live Response for Rapid Remediation (55)
    7.8
    78%
  • Centralized Dashboard (62)
    7.8
    78%
  • Machine Learning to Prevent Incidents (54)
    7.7
    77%

Reviewer Pros & Cons

View all pros & cons
Return to navigation

Pricing

View all pricing

3001-5000 Monthly Pricing Per Seat

$0.50

Cloud
per month (billed annually) per seat

2001-3000 Monthly Pricing Per Seat

$0.55

Cloud
per month (billed annually) per seat

1001-2000 Monthly Pricing Per Seat

$0.65

Cloud
per month (billed annually) per seat

Entry-level set up fee?

  • Setup fee optional
For the latest information on pricing, visithttps://www.knowbe4.com/pricing-phisher

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services
Return to navigation

Features

Incident Response Platforms

Incident response (IR) platforms guide countermeasures against a security breach and deploy preplanned, automated threat responses

7.6
Avg 8.5
Return to navigation

Product Details

What is KnowBe4 PhishER/PhishER Plus?

PhishER is a platform for managing the high volume of potentially malicious email messages reported by users. With automatic prioritization of emails, PhishER aims to help InfoSec and Security Operations team cut through the inbox noise and respond to the most dangerous threats more quickly.

PhishER is a web-based platform with critical worksteam functionality that serves as a phishing emergency room to identify and respond to user-reported messages. With PhishER, users are able to automate the workstream of 90% of reported emails that are not threats, freeing up incident response resources.

PhishER is available as a stand-alone product or as an optional add-on for KnowBe4 customers that want to automatically prioritize and manage potentially malicious messages that were reported through the KnowBe4 Phish Alert Button. PhishER Plus is an upgraded subscription level that includes all of the features from PhishER with additional enhancements and AI-validated crowdsourced data. PhishER Plus was developed to help supercharge an organization’s email security defenses. It does this by automatically blocking phishing attacks that traditional Security Email Gateways (SEGs) miss and removes these missed threats from users’ inboxes.

KnowBe4 PhishER/PhishER Plus Features

Incident Response Platforms Features

  • Supported: Company-wide Incident Reporting
  • Supported: Integration with Other Security Systems
  • Supported: Centralized Dashboard
  • Supported: Machine Learning to Prevent Incidents
  • Supported: Live Response for Rapid Remediation

Additional Features

  • Supported: Automatic Message Prioritization

KnowBe4 PhishER/PhishER Plus Screenshots

Screenshot of This is a diagram of the PhishER workflow. Reviewing the PhishER workflow before getting started will provide an understanding of how PhishER, PhishRIP and PhishFlip work.Screenshot of The Reports screen will display five different dashboards of information.Screenshot of When entering the PhishER platform, the first screen that appears is the Dashboard. Here, a quick overview of the PhishER platform will appear.

KnowBe4 PhishER/PhishER Plus Video

Introduction to PhishER

KnowBe4 PhishER/PhishER Plus Competitors

KnowBe4 PhishER/PhishER Plus Technical Details

Deployment TypesSoftware as a Service (SaaS), Cloud, or Web-Based
Operating SystemsUnspecified
Mobile ApplicationNo
Supported CountriesGlobal

KnowBe4 PhishER/PhishER Plus Downloadables

Frequently Asked Questions

PhishER is presented as a lightweight Security Orchestration, Automation and Response (SOAR) platform to orchestrate threat response and manage the high volume of potentially malicious email messages reported by users. And, with automatic prioritization of emails, PhishER helps InfoSec and Security Operations team cut through the inbox noise and respond to the most dangerous threats more quickly.

Cofense Triage, Infosec IQ, and Proofpoint Threat Response Auto-Pull are common alternatives for KnowBe4 PhishER/PhishER Plus.

Reviewers rate Company-wide Incident Reporting and Centralized Dashboard and Live Response for Rapid Remediation highest, with a score of 7.8.

The most common users of KnowBe4 PhishER/PhishER Plus are from Mid-sized Companies (51-1,000 employees).
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(160)

Attribute Ratings

Reviews

(1-5 of 5)
Companies can't remove reviews or game the system. Here's why
Score 10 out of 10
Vetted Review
Verified User
Incentivized
We love PhishER because it works to combat our phishing email issue. I think the most notable feature of the product is that it actually takes the phishing and malware emails we receive and pulls them out of users inbox. It is very beneficial. The other feature I find extremely beneficial is the Virus Total score to decide whether an email is malicious or not.
  • Identifies the difference between Clean and Threat emails.
  • Pulls out emails from other users mailboxes that contain the same info as phishing email.
  • Enables you to customize the platform to closely relate to your company.
  • Honestly I can't think of anything!
KnowBe4 PhishER is great at detecting threats before they even reach our users mailboxes. Since human error is so prevalent, this is a huge help. The tool also does a great job of setting to the side the ones it is unsure about. I like this because it does not pull out emails from our users unless it is extremely sure it contains a threat.
Incident Response Platforms (5)
100%
10.0
Company-wide Incident Reporting
100%
10.0
Integration with Other Security Systems
100%
10.0
Centralized Dashboard
100%
10.0
Machine Learning to Prevent Incidents
100%
10.0
Live Response for Rapid Remediation
100%
10.0
  • Isolating email threats
  • Seizing phishing emails before they become an attack
  • Leaving more time open on our team to work on other tasks
KnowBe4 PhishER has saved my organization time and money by reducing/eliminating the amount of threats that enter our user's mailboxes. It is a sad truth, but if all the threat emails would have actually gotten sent out, our users would have clicked on them.
We have implemented Phish ML, PhishRIP, and Phish ER Blocklist.
These features have impacted my organization by working together to create a perfect offensive tool. Most tools these days are defensive, but i feel like this one does so much better at preventing the problems to begin with.
None.
I feel the configurability is just right for this type of product! The tool was working great without configuring small details, however, it works even better now. I am able to create the email responses from scratch for THREAT, SPAM and CLEAN sent to end users after they report phishing email. These emails can be set to be coming from whatever sender you’d like (my company uses IT Services). Another feature is the Blocklist where i can add a malicious sender’s email address, a URL, or a File Hash. You can then configure to sync with Microsoft 365 mailboxes. I also like that I can use the pre-determined tags and/or create my own to apply to the messages. Not only can you create the tags, but you can also use those tags to define the classification (THREAT, SPAM or CLEAN) each email receives!
My recommendation would be to take the time to carefully configure the tool based on your company’s preferences. Doing so will result in a very accurate data presentation.
Some - we have done small customizations to the interface
Some - we have added small pieces of custom code
I have not added custom code myself yet.
Score 10 out of 10
Vetted Review
Verified User
We have a high rate of items reported via Phish ER (approximately 1000 a month) for a department of 2 people.
We setup rules in Phish Alert to respond to the most common items reported.
We have also setup rules to all the InfoSec team to focus on those emails that have not been responded to and/or actual threats.
By utilizing Phish ER we have been able to take reduce the amount of time spent addressing items report from 2 hours a day down to < 20 minutes.
Additionally with the recent update to allow us to push blocks to M365 we are seeing a large reduction in the number of spam and scam emails.
  • Minimal false positives
  • Ease of use in defining and designing flows
  • Ease of use in defining and designing response templates
  • Reporting - the reports in place are useful but allowing for more details would be helpful
  • More Quick Actions
Ease of implementation.
Time savings.
Use in identifying trends.
Incident Response Platforms (5)
94%
9.4
Company-wide Incident Reporting
80%
8.0
Integration with Other Security Systems
100%
10.0
Centralized Dashboard
90%
9.0
Machine Learning to Prevent Incidents
100%
10.0
Live Response for Rapid Remediation
100%
10.0
  • Time saved has allowed for concentration in other areas.
  • Response time to users has increased InfoSec profile in the company, making it easier to sell other initiatives. Also, this makes users more likely to report things
  • The ability to see threats in 1 area allows for better recognition of trends or large scale attacks.
The automated responses with low cases of false positives has allowed my team to focus on the actual threats and/or unknowns. This has promoted users to be more willing to report things.

We have implemented - PhishER Blocklist.
This has helped reduce the amount of spam/scams that are getting to users.Very valuable.
In looking at other products I didn't find any that were as integrated with our email process.
We did implement Tessian as an email filtering/security product but I feel PhishER provides functionality that other email security tools cannot provide.
Just right.
Easy to get up and running quickly
Turn on Phish ER but wait to setup the automation tasks until you have reviewed your data to group and rollout types of emails.

No - we have not done any customization to the interface
No - we have not done any custom code
None - the available features met our needs
3
Information Security
Information Technology


2
Members of the InfoSec team with experience in email security.
  • Ability to automate responses to users that report emails.
  • Reporting and classification of reported emails.
  • Integration with M365 to allow for adding emails, attachments, etc. to block list.
  • Training users on legitimate emails and proper communications.
  • Finding large scale phishing attacks.
  • Understanding and reporting on most common scams/phish being seen by users.
  • Use the data gathered to recognize frequent reporters.
  • Use data gathered to understand common domains, etc. for DMARC and SPF implementation
Phish ER has reduced the time my team and I spend on reported emails by over 80%. With the volume of emails reported and a small team this is a must have.
No
  • Integration with Other Systems
  • Ease of Use
We have made reporting emails via Phish Alert a cornerstone message in our Awareness program, so anything we implemented had to work with the Phish Alert button.
I wouldn't change anything. The evaluation was straight forward and we chose to move forward with the best product.
Responses to questions were answered quickly and accurately.
I'm not sure if we purchased a premium support option. I don't think so.
No
I've had multiple support cases opened that I not only received an answer to the problem in question but also details on best practices that improved the underlying process.
The product is easy to setup, use and maintain. The product is stable and performs as expected
  • The rules are easy to define and implement.
  • The actions provided a way to create the email flows that I wanted.
  • The templates are easy to design and allow for all the content that I wanted.
  • None
Score 9 out of 10
Vetted Review
Verified User
Incentivized
We use KnowBe4 PhishER as part of our email analysis when users report emails to the team and also have some visibility what users report and how often. Some business problems this product addresses is the need to free up team resources to review emails on a daily basis. Another problem this product addresses is that it creates additional flexibility within the overall workflow. For example, when a ticket needs to get created internally for review, it's just one click of a button. This product helps automate some of our tasks that would normally be a manual effort.
  • Provides high level reporting
  • Integration with ticketing system such as Jira
  • The flexibility of creating rules that align with various workflows
  • Easy to use interface
  • The number of action items could be expanded to include more functionality
  • The option to schedule reports and send to various team members to eliminate the need to go into the console on a weekly or monthly basis
  • Additional widgets to expand the dashboard functionality
The KnowBe4 PhishER is a great product that integrates well with the KnowBe4 security education platform and Jira service desk. Those two integrations make the general workflow effortless for someone who is in the product on a daily basis. This reduces manual work and allows our team to be productive and work on other projects.

This product also gives the team visibility on what is being reported and help determine if the email reported is localized or widespread throughout the organization. Meaning, depending on how many people report an email based on location and job roles.

This solution is well suited for an organization or team who would like to automate the guess work of determining if a email is a phish, spam, or safe. Additionally, have that one click response to the user who reported to get additional insight on if they did respond to the email or clicked on that was determined to be a real phishing email.

Incident Response Platforms (5)
78%
7.8
Company-wide Incident Reporting
70%
7.0
Integration with Other Security Systems
80%
8.0
Centralized Dashboard
60%
6.0
Machine Learning to Prevent Incidents
90%
9.0
Live Response for Rapid Remediation
90%
9.0
  • Freed up team resources with automation
  • Real time data on email reporting
  • Resolve incidents in a timely manner
  • Response and communication capabilities
PhishER has definitely saved our team and organization by utilizing the machine learning functionality within the solution. What use to take 30 minutes or more now takes less than 5 minutes. The benefits that it brings to our organization is freed up team resources, increased our confidence levels to determine real threats, and overall security posture throughout the organization. As this works alongside the security education platform, we are able to use phish-flip to turn active phishing attacks into safe templates into a learning opportunity.
Our organization has implemented PhishML, PhishRIP, PhishFLIP to help automate remediation of known threats from our users' mailboxes. We found these capabilities to very useful and help with our education and remedial efforts. Having used this capabilities allows the team to have a good insight on what emails are being reported as well as get another review on them as well.
Having reviewed and currently using these capabilities has spread general awareness not only to our team but our entire organization. We have noticed increased communication from our users and everyone wants to help report suspicious emails and let this solution further help with the analysis. We have found that our overall phish-prone percentages have gone down since the implementation of PhishFlip. Additionally, this reduces some of the risk that the organization once had.
PhishER is my opinion is an industry leader when it comes to a tool for email analysis and remediation. This solution has a solid interface to use and understand its functionality. Additionally it has easy integrations with other security products that make this appealing for organizations in most industries. Overall, we are pleased with PhishER and complements the security education platform very well to have nearly that all in one solution.
I believe the configurability for this product is somewhat limited as it related to the number of actions that can be configured. At the time of this writing, the total number of configurable actions allowed is eight.

There are times when I am reviewing emails and don't have the correct action available. Having additional action buttons would help the automation process. This is something that has great potential and I find it very useful and reduces time for my team.
When configuring KnowBe4 PhishER in your environment it is often considered best practice to evaluate your current environment and understand how this would fit into your current security stack. One of many benefits of having PhishER is the opportunity to automate repetitive tasks saving you and the team countless hours of reviewing emails.

Some - we have done small customizations to the interface
We have made some small customizations to the interface that helps us automate repetitive tasks and free up team resources to work on other project. For the most part, it was straight forward and easy to do with minimal effort.

Some examples are creating custom email workflow rules, enabling additional actions for communication purposes, add additional tags for certain emails.
No - we have not done any custom code
PhishER is customizable to fit into most environments and can be a huge time saver for the responsible team(s). Having PhishER is another great tool that can give an "Eyes on Glass" approach to email monitoring and see how your users respond to emails. Having creating the different emails tags does help with reporting and give you a good overall visual on emails within your environment.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
Use KnowBe4 PhishER for users to submit tickets to our helpdesk team. We have automation setup to process findings and pass the emails to the correct tech's for investigation.
  • Custom Rules for Phishing Emails
  • Custom Reports for IT and Exec
  • Integrate with other Phishing providers
  • More control on their rules or be able to script more
  • Allow to remove emails from exchange server if they are phishing emails
Allowed us to automate our phish reporting for users and to catch the emails quicker with out a lot of time reviewing emails.
Incident Response Platforms (5)
88%
8.8
Company-wide Incident Reporting
80%
8.0
Integration with Other Security Systems
80%
8.0
Centralized Dashboard
100%
10.0
Machine Learning to Prevent Incidents
90%
9.0
Live Response for Rapid Remediation
90%
9.0
  • Helped to reduce the time to respond to emails for tech's
  • allows helpdesk to work with users and not take away from Exchange Admin's
Being able to setup rules for emails that come in and deal with quickly has been a major help for us. To get the first email triage it and then take care of any of the other emails like this comes in to automate the process.
We have implemented KnowBe4 PhishER Blocklist so far and will be testing ML and Flip shortly.
Saved us time and money with reducing labor of repeated incoming emails.
KnowBe4 has a lot of features and easy to configure for admin's. Adding the report button was the toughest part because there were so many different ways to deploy it to everyone. Once we figured out the direction the company wanted to go we hit the ground running and got the buttons installed in 30 minutes.
Make sure that you know what types of products you want to install button. It makes the installations easier. PhishER is great and has help cut down time with rules that process emails that are submitted with out our admin's having to touch each email that comes in.
Some - we have done small customizations to the interface
Once we had a little tour of PhishER we saw what we could do with the rules and customizations to make our lives easier. Start small and add as you go. We still need to tweak the customizations every couple of months because things change.
No - we have not done any custom code
Being able to customize some of the rules and action are great for us. Not just an out of the box piece of software that you can't fit to your business.
10
Server, Network, HelpDesk and Management use this product.
5
Users in the Server and HelpDesk teams use PhishER and need to know some basic email and filtering rules.
  • Reporting emails from Outlook
  • Rules to automatically take care of emails that come in regularly
  • Rules to let the user know what is going on and not have a black hole that these email end up in.
  • Lets us know when our Health Provider starts sending out emails to user, so we can notify users of this email and that its not spam.
  • Helps us reward users that report emails that most to help protect our company
  • Looking in some custom coding to send scams and virus email to other vendors for deep inspections
  • Notify supervisors about their users and who clicks on everything for safety training.
We really like the cost and the coverage that PhishER brings to the company and being able to over lap with our email provider and spam filtering vendors has been a huge help.
No
  • Scalability
  • Integration with Other Systems
  • Other
Being able to report emails and create rules to automate these was the biggest factor.
Being able to do so much with PhishER has made us question other vendors and why they aren't already doing what PhishER already does. That we use PhishER on top of what other vendors do because it's more customizable.
Work with support or rep for some basic steps, the rest is pretty straight foward.
  • Implemented in-house
No
Change management was minimal
  • Yara Rule Editor was the only issue we encountered
Support has been easy to get along with and easy to understand.
We didn't purchase premium support because the product is very easy to use.
No
Doing some customizing on our rules, support was able to listen to our needs and send us an example of what we needed promptly. Then they followed up with some suggestions to add to it like some other companies had already done.
Very easy to use and able to customize it to our companies needs and changing needs monthly.
  • Phish button is the best thing we have used
  • Rules are setup and changed around all the time depending on our environment
  • Yara Rule Editor was a little tough to understand but it didn't take long.
  • iPhone users button to be able to
Yes
It works well, iPhones have a little issue with interface but it's manageable.
PhishER is easy to intergrate with other providers but some of the other vendors don't play nice with PhishER
  • Proofpoint
  • Microsoft Exchange Online
Getting the systems to talk to each other was the toughest part, after that it was easy to update and exchange information.
  • Exchange 2019
  • Other Email Vendors
  • Mail Relay
Some vendors support integration and some your have to manipulate it to work with powershell or coding.
  • File import/export
  • API (e.g. SOAP or REST)
  • AppExchange or similar marketplace
Powershell
Know your vendors and talk to them about integration before you try to integrate PhishER.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
With today's growing phishing attack surface, the need for a reporting and management system is inevitable. Manually managing phishing responses is cumbersome and downright unsafe. KnowBe4 PhishER allows us to quickly and safely manage our phishing reports.
  • Detailed Phishing Indicators
  • Automatic Categorization of Phishing Emails
  • Multi-Admin Workflow
  • Automated Responses
  • Setup a bit tricky out of the box. I prefer self-service setups that are easy to use, but KnowBe4 PhishER does offer great service for their products.
KnowBe4 PhishER is suited for any decently sized organization. No matter the business, phishing is a severe threat today.
Incident Response Platforms (5)
60%
6.0
Company-wide Incident Reporting
N/A
N/A
Integration with Other Security Systems
100%
10.0
Centralized Dashboard
100%
10.0
Machine Learning to Prevent Incidents
N/A
N/A
Live Response for Rapid Remediation
100%
10.0
  • Less time coordinating phishing response
  • Less time investigating reports
  • Mitigating phishing risk more effectively
The PhishER identification tags are vital to our response team. The tags help us prioritize threats over spam or false positive reports.
PhishML, PhishRIP, and PhishER blocklist
All capabilities allow us to centrally manage our phishing response. Before we would have to manually track down emails in Microsoft's Security console, wasting a lot of time. All capabilities allow us to easily manage our phishing threats.
KnowBe4 PhishER is flexible. The configuration can be as simple or complex as you like. They also offers support for configuring the instance to your organization's specific needs.
Talk with your rep to ensure you are using the software to its fullest potential.
Some - we have done small customizations to the interface
Setting up workflows for your team is important. Having specific workflows for our criteria is helpful. Configuring quick actions also saves us a lot of time.
No - we have not done any custom code
N/a
160
Information technology (reviewers) and end users (reporters)
1
Information Technology with a focus on security
  • Security
  • Ransomware Mitigation
  • Malicious email tracking
  • Automated workflows
  • Automated responses
  • Machine learning
KnowBe4 PhishER fits nicely into their product suite. It is both affordable and useful.
No
  • Cloud Solutions
  • Integration with Other Systems
  • Ease of Use
Ease of use is important for small businesses that don't have many resources to dedicate to a complicated solution.
I wouldn't change anything
KnowBe4 support is attentive to our needs. Our requests and concerns are always processed quickly.
No, the support is included in our current contract
No
They assisted us with setting up the more handy features, like quick actions.
The configuration is a bit complicated, but easy once you get the hang of it. Once configured, it is easy to manage our malicious emails that are reported by our staff.
  • Quick actions
  • Link tracking
  • Initial setup
Return to navigation