Skip to main content
TrustRadius
KnowBe4 PhishER

KnowBe4 PhishER

Overview

What is KnowBe4 PhishER?

PhishER is presented as a lightweight Security Orchestration, Automation and Response (SOAR) platform to orchestrate threat response and manage the high volume of potentially malicious email messages reported by users. And, with automatic prioritization of emails, PhishER helps InfoSec and…

Read more
Recent Reviews

Phishing Hero!

10 out of 10
March 13, 2024
Incentivized
We use KnowBe4 PhishER with our KMSAT. KnowBe4 PhishER is basically helping us to resolve our biggest security problem and that is …
Continue reading
Read all reviews

Awards

Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards

Popular Features

View all 5 features
  • Live Response for Rapid Remediation (55)
    7.8
    78%
  • Company-wide Incident Reporting (52)
    7.8
    78%
  • Centralized Dashboard (62)
    7.8
    78%
  • Machine Learning to Prevent Incidents (54)
    7.7
    77%

Reviewer Pros & Cons

View all pros & cons
Return to navigation

Pricing

View all pricing

3001-5000 Monthly Pricing Per Seat

$0.50

Cloud
per month per seat

2001-3000 Monthly Pricing Per Seat

$0.55

Cloud
per month per seat

1001-2000 Monthly Pricing Per Seat

$0.65

Cloud
per month per seat

Entry-level set up fee?

  • Setup fee optional
For the latest information on pricing, visithttps://www.knowbe4.com/pricing-phisher

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services
Return to navigation

Features

Incident Response Platforms

Incident response (IR) platforms guide countermeasures against a security breach and deploy preplanned, automated threat responses

7.6
Avg 8.5
Return to navigation

Product Details

What is KnowBe4 PhishER?

PhishER is a platform for managing the high volume of potentially malicious email messages reported by users. With automatic prioritization of emails, PhishER aims to help InfoSec and Security Operations team cut through the inbox noise and respond to the most dangerous threats more quickly.

PhishER is a web-based platform with critical worksteam functionality that serves as a phishing emergency room to identify and respond to user-reported messages. With PhishER, users are able to automate the workstream of 90% of reported emails that are not threats, freeing up incident response resources.

PhishER is available as a stand-alone product or as an optional add-on for KnowBe4 customers that want to automatically prioritize and manage potentially malicious messages that were reported through the KnowBe4 Phish Alert Button. PhishER Plus is an upgraded subscription level that includes all of the features from PhishER with additional enhancements and AI-validated crowdsourced data. PhishER Plus was developed to help supercharge an organization’s email security defenses. It does this by automatically blocking phishing attacks that traditional Security Email Gateways (SEGs) miss and removes these missed threats from users’ inboxes.

KnowBe4 PhishER Features

Incident Response Platforms Features

  • Supported: Company-wide Incident Reporting
  • Supported: Integration with Other Security Systems
  • Supported: Centralized Dashboard
  • Supported: Machine Learning to Prevent Incidents
  • Supported: Live Response for Rapid Remediation

Additional Features

  • Supported: Automatic Message Prioritization

KnowBe4 PhishER Screenshots

Screenshot of This is a diagram of the PhishER workflow. Reviewing the PhishER workflow before getting started will provide an understanding of how PhishER, PhishRIP and PhishFlip work.Screenshot of The Reports screen will display five different dashboards of information.Screenshot of When entering the PhishER platform, the first screen that appears is the Dashboard. Here, a quick overview of the PhishER platform will appear.

KnowBe4 PhishER Video

Introduction to PhishER

KnowBe4 PhishER Technical Details

Deployment TypesSoftware as a Service (SaaS), Cloud, or Web-Based
Operating SystemsUnspecified
Mobile ApplicationNo
Supported CountriesGlobal

KnowBe4 PhishER Downloadables

Frequently Asked Questions

PhishER is presented as a lightweight Security Orchestration, Automation and Response (SOAR) platform to orchestrate threat response and manage the high volume of potentially malicious email messages reported by users. And, with automatic prioritization of emails, PhishER helps InfoSec and Security Operations team cut through the inbox noise and respond to the most dangerous threats more quickly.

Cofense Triage, Infosec IQ, and Proofpoint Threat Response Auto-Pull are common alternatives for KnowBe4 PhishER.

Reviewers rate Company-wide Incident Reporting and Centralized Dashboard and Live Response for Rapid Remediation highest, with a score of 7.8.

The most common users of KnowBe4 PhishER are from Mid-sized Companies (51-1,000 employees).
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(160)

Attribute Ratings

Reviews

(1-5 of 5)
Companies can't remove reviews or game the system. Here's why
Score 10 out of 10
Vetted Review
Verified User
Incentivized
Currently KnowBe4 PhishER is being used across all departments within the organization. This has addressed the business problem of suspected phishing remediation. Through machine learning, integrations with VirusTotal, the PhishAlert button, and the ability to automatically respond to messages, we have drastically slashed the amount of time that analysts and end-users spend in phishing responses.
  • Machine learning evaluation
  • Automation of response
  • Setting custom thresholds
  • Quarantining messages before end-users read them
  • Search inboxes for similar messages
  • Custom rules can be bothersome to create
  • Inability to log directly into PhishER, must go through main console first
  • PhishRIP can require too much information when searching for similar messages
PhishER works wonderfully for organizations in which end-users are prone to reporting all messages. By having automated responses it allows for non-malicious messages to be responded to without requiring analyst intervention. The PhishRIP functionality can be less useful because it requires a minimum of two fields to be selected for searching. This can result in issues where a threat actor has modified the body or subject to add a more personal touch to the malicious email.
  • Automated response
  • Integration with Virus Total
  • PhishRIP
Incident Response Platforms (4)
70%
7.0
Company-wide Incident Reporting
60%
6.0
Integration with Other Security Systems
80%
8.0
Centralized Dashboard
60%
6.0
Live Response for Rapid Remediation
80%
8.0
  • Less analyst time spent on phishing emails
  • Reduced number of missed messages
  • PhishRIP has allowed phishing messages to be removed before they have been read
PhishER has saved my organization time through the incorporation of automated responses and the ability to manage quaranting messages and block lists from within the PhishER console and not needing to log into another dash board.
My organization has utilized PhishML, PhishRIP, and PhishER Blocklist with great success.
PhishML has allowed me to drastically reduce the number of messages my staff review on a daily basis, and provide after hours responses to colleagues working different shifts or checking messages after hours. PhishRIP has allowed me to remove threatening messages that have been reported before all recipients have read them, and this has combined with the PhishER Blocklist to eliminate recurring threats.
I have previously used Infosec IQ and Mimecast for similar purposes. Infosec IQ allowed my users to report messages, but the interface was clumsy and there weren't any features to allow me to quarantine or block message from within that dashboard. Mimecast was similar, but the granularity of the controls was overwhelming for new staff.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
Helps address the increasing threat of phishing attacks. The product addresses business problems such as preventing sensitive information from falling into the hands of attackers, maintaining the security of corporate data, and preserving the trust of customers and employees. The product can be used to detect and respond to phishing attempts across a wide range of channels, including email, web, and social media
  • Phishing threat detection and response
  • Centralized management
  • Employee training
  • Integration with other tools
  • Mobile support
  • Improved reporting and analytics
KnowBe4 PhishER provides a centralized platform for managing phishing incidents, making it well suited for organizations with a large number of employees who are at risk of receiving phishing emails. Great for being able to just set up and forget, the support staff can help with the initial setup to have reoccurring tests
  • Threat Detection
  • Incident response
  • Phishing simulation
Incident Response Platforms (5)
76%
7.6
Company-wide Incident Reporting
90%
9.0
Integration with Other Security Systems
20%
2.0
Centralized Dashboard
90%
9.0
Machine Learning to Prevent Incidents
90%
9.0
Live Response for Rapid Remediation
90%
9.0
  • Reduction in users falling for phishing
  • Identifying staff that need more training
Much easier interface to use, great support. Very easy to set up and works out of the box. Great content and new videos are constantly being added. Themed phishing around holidays is a great idea and has made users far more aware. Phishing based on current events in the news is a great idea.
February 02, 2023

Great Product Suite

Score 9 out of 10
Vetted Review
Verified User
Incentivized
Our organization utilizes PhishER in several ways. We utilize PhishML to assist with our research of messages and our prioritization of the messages we deem as "Vaild". We utilize PhishRIP to assist our O365 quarantining of new incoming messages so that our users experience less spam. We have integrated the Phish Alert button across all our Office 2016 users as well as into our Office 365 users so that they can reported suspected phishing emails to our team. We have also started using PhishFLIP to replace active Phishing attempts into simulated spoofs to test user responses.
  • Phish Alert button is a simple way for users to report phishing attempts.
  • PhishFLIP really increases the look and feel of simulated attempts that we test our users with.
  • PhishRIP cut down on our average email/user counts and have increased our quarantining abilities.
  • Scheduling of simulated emails.
  • Setup of the rules to categorize messages
KnowBe4 is an amazing company and has several products that can really increase your Situational Awareness training program. PhishER is just a suite of programs that assist in user knowledge for phishing attempts, and the filtering, analyzing and quarantining of theose Real Phishing attempts. It's an amazing product that should be in all IT Team's arsenal.
  • Phish Alert Button (PAB)
  • PhishFLIP
  • PhishRIP
Incident Response Platforms (5)
90%
9.0
Company-wide Incident Reporting
90%
9.0
Integration with Other Security Systems
100%
10.0
Centralized Dashboard
80%
8.0
Machine Learning to Prevent Incidents
90%
9.0
Live Response for Rapid Remediation
90%
9.0
  • Having this system in place has assisted in keeping 250+ users knowledgeable and trained them to report phishing attempts.
  • Assisted our Cyber Liability Insurance acceptance.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
We had a fairly serious phishing problem and needed to combine some awareness training along with simulated phishing and quarantine capability and PhishER from KnowBe4 checked all the boxes.
  • PhishER's connection to our O365 environment is good, it allows users to click the Phish Alert button to report a phish and this kicks off a back-end action that scans all users' inboxes and quarantines similar phishing emails it finds.
  • The KnowBe4 security awareness training, the Phish Alert Button, and simulated phishing are all tightly integrated, it's a "system" rather than ad hoc solutions.
  • #1 thing KnowBe4 needs to improve is using their PhishML to proactively find and quarantine phishing emails rather than only relying on the reactive click by a user. There's still a huge risk hole they are not filled by not providing this functionality.
I think KnowBe4's customer service is outstanding, we have a "Customer Success Manager" who is very helpful and proactive and support was also very helpful during our implementation.
  • Security Awareness Training
  • Simulated Phishing and reporting dashboard
  • Phish Alert Button quarantine process
Incident Response Platforms (5)
36%
3.6
Company-wide Incident Reporting
N/A
N/A
Integration with Other Security Systems
N/A
N/A
Centralized Dashboard
100%
10.0
Machine Learning to Prevent Incidents
80%
8.0
Live Response for Rapid Remediation
N/A
N/A
  • Employees needed a way to report phishing to IT but rather than simply forwarding a suspicious mail, the PhishER system turns the whole thing into an automated process.
  • Combining the Awareness Training, simulated phishing, and Phish Alert Button has conditioned our employees on how to appropriately respond to suspected phishes.
  • We implemented KnowBe4 and PhishER before our cyber liability insurance company began asking about things like this, I now have dashboards and stats I can snapshot to demonstrate our anti-phishing ecosystem's effectiveness.
We evaluated Proofpoint and two other phishing-related products but I was disappointed by the high rate of false-positive quarantines, this makes for a poor end-user experience and complaints to IT.
August 11, 2021

Time saver!

Score 9 out of 10
Vetted Review
Verified User
Incentivized
KnowBe4 is currently used throughout the organization. It helps us categorize and quarantine all threats that arrive in our users' email inboxes. By integrating KnowBe4 into our security infrastructure, we have found that it has saved us time and money. It helps us save time and allows us to focus on more important issues and projects.
  • Machine learning
  • Automating threat management
  • Alert configuration
  • Better integration to outlook
  • Better explanations on email structure presentation
  • More training available regarding email threat analysis
This is a necessity if you don't want to find yourself dealing with all the reported threats one by one.
You will see the benefits from day one and the more the machine learning algorithm is fed, the better it gets.
An example scenario is when an employee reports a threat through the add-in installed and deployed on all Outlook clients. The threat is then sent to the PhishER platform, where the administrator inspects it, analyzes it and takes action based on the results.
If it is a threat, it is retained and used as an example to feed the machine learning algorithm, if not, the email is released and sent back to the user with a comment telling the user it's a safe email.
  • Machine learning
  • Automation
  • Quick actions allow you to easily start a series of actions from one click of a button
Incident Response Platforms (5)
96%
9.6
Company-wide Incident Reporting
100%
10.0
Integration with Other Security Systems
80%
8.0
Centralized Dashboard
100%
10.0
Machine Learning to Prevent Incidents
100%
10.0
Live Response for Rapid Remediation
100%
10.0
  • Time saver
  • Allows us to focus on more important matters
  • Threat management
To be honest, this is the first time I have used a tool like this. So I can't compare it to other tools that offer this kind of service. I did do my due diligence and based on several comparative studies and research, I decided to go with KnowBe4 because they are the industry leader.
Jira Service Management (Jira Service Desk), Microsoft Power BI, Epicor Eclipse
Return to navigation