Recreate a real phishing mail, or Recreate attack, uses AI to turn a screenshot of an actual email into an editable phishing template for your SoSafe simulation. This article explains the creation and editing process.
Recreate attack
- Take a high-quality screenshot of an email you want to recreate. For best results, include the full email, including subject and sender. Both Windows (Snipping Tool) and MacOS (Screenshot) have built-in tools to help with this.
-
Navigate to Phishing Simulation / Template Studio in the SoSafe Manager. There, select + Create custom template, followed by Recreate from a real phishing mail.
-
In this dialog window, you can either drag and drop a file into the field or click to open your system's file picker. You can also select additional languages for translation here, but you can also do that in the template editing step, if you prefer editing it first.
-
In the bottom right, you will now see a progress indicator. Generating the template can take a few minutes. You can keep using the entire Manager and generation will continue in the background, but not that you will only see the progress indicator on pages in Phishing Simulation / Template Studio.
-
Once template generation is done, at any point that you return to Template Studio, you will find the newly generate template at the top your list. You can select the Pen icon to edit it or the Eye icon to preview it.
Template editing basics
Template Studio's template editor allows for comprehensive editing of email templates and seeks to strike a balance between customization capabilities and ease of use. This section seeks to explain the most important editing features but we encourage you to play around a bit if this is your first time using it.
The editor is split into 3 parts:
- Layers on the left gives you a hierarchical list of all elements in your template. You can click on elements to select and edit them, but you cannot rearrange the individual components here.
- The template view in the middle works similar to a word processing program. A single click will select elements (similar to the Layers view). With some elements, namely Text and Button, you can click again to edit their content.
- The view on the right is adaptive:
- When no element is selected, you will see the Add elements view. This allows you to simply drag and drop new elements such as a header, text field or button into your template. An indicator will show you where exactly it will be inserted.
- Once you select an element, you will see its properties. If you select an image, for instance, you can replace it with a new one or change its layout.
Tutorial: making an email look more official
Let's take the generate template above as an example and tailor it more to a fictional org called "Example company".
Changing text
Let's assume that Example company's "HR Team" is actually called the "People Team" internally.
-
Select the "Dear HR Team," text field by clicking on it.
- Now we click on it again to enter edit mode.
- Now we simply select the "HR" and replace it by typing "People".
Adding placeholders
Another option would be to use the recipient's actual name. This can be achieve using placeholders, which are filled by the actual info when the email is sent to the recipient. The process here is almost the same.
When editing templates, placeholders always have curly braces around them: {placeholder}
-
Select the "Dear HR Team," text field by clicking on it.
- Now we click on it again to enter edit mode.
-
Click on the curly braces { } to open the list of placeholders. Select Recipient first name. Then, select the curly braces again and select Recipient last name. Make sure to add a space between the placeholders so the name is shown correctly.
- Optional: Save the template and preview it to make sure the placeholders work as intended.
Changing subject and sender
At the top of the template editing section, you can change the subject, sender name and sender email address. Editing the subject and sender name is straightforward. For the sender email, you can change both the part before and after the @ symbol. For the latter, we have a variety of domains available - pick whichever fits the template best.
While the placeholder search is not available in the subject field, you can use the same placeholders here. If you don't know the placeholder by heart, simply add it in a regular text field and use copy & paste.
Adding a header
We can make our template more realistic by adding our company's email header.
-
In the Add elements section to the right, start dragging Header, move it to the template and drop it towards the top once you see a green line appear.
- Now you can customize the background color. Click in the field to select a color or select the eye dropper icon to the right and reuse a color from the template itself. In our case, we'll go with a simple white.
- Next we can replace the image itself. Click on it to select it. The image properties will now be shown in the right. Select Drop your image here or click to select and pick your file. The file will be uploaded and the new image should appear in the middle. You might have to change some additional properties, for instance the Image size.
Changing link destinations
Note: all clickable elements in a template will always lead to the same destination. No matter where you change it in a template, the change always applies to the entire template.
There are 2 options for link destinations:
- Learning page: When a recipient clicks on an interactive element, they get taken directly to the learning page. This is the page that reassures tham that this was not a real attack and then shows 5 learning hints to teach how the recipient can identify real threats in the future.
- Landing page + learning page: When a recipient clicks on an interactive element, they are first taken to a landing page that can simulate certain scenarios (i.e. a fake LinkedIn page or a fake login page). Once they interact with any element on this page, they are taken to the corresponding learning page.
To change this setting for your template, select any interactive element such as a link or button and select from the available options: