The Click Report displays your learner's Phishing activity via Baseline, Campaign and Spear Phishing emails.
Important
- The click-through rate (CTR) is determined by 'unique clicks', which is the first time an employee interacts with a simulated phishing email.
- CTR shows in 2 decimal places and quickly shows which learners are engaging with simulated phishing emails.
- CTR encompasses various actions performed by the learners such as Clicks, Opened Attachment, Submitted Credential and QR Code included in the phishing simulation email.
Benefits of the Click Report
- It lists the learners who engage with simulated phishing emails
- There are a range of filters that can be applied to customise your report
- Reports can be downloaded as a CSV
- Reports can be extracted Reporting API
- Reports can be scheduled for sending via Report Scheduling: Click Report
Click Report Definitions
Action |
Definition |
|---|---|
| Opened |
When a learner has opened an email. Note:
|
| Clicked Link | When a learner has clicked on a link in a simulated phishing email. |
| Opened Attachment | When a learner opens an attachment in a link in a simulated phishing email. |
| QR Code | When a learner scans a QR Code in a simulated phishing email. |
| Credential Capture | When a learner submits log-in credentials or details on the simulated landing page. |
How to Run a Click Report
- Select Dashboard > Click Report and choose the preferred phishing simulation block (Baseline, Campaign, Spear Phishing).
-
Filter from the relevant or preferred fields:
- Date range = desired date range or the dates phishing simulation was scheduled
- Segment = Microsoft Entra ID Attributes or Security Group/s synched to Phriendly Phishing
- Action = actions taken by learners
- IPs = Included IPs means, actions that are reflected in your CTR ; Excluded IPs means actions received but were excluded from your CTR. These IPs are part of our Global Exclusion List
- Attachment
- Credential Capture
- QR Code
- After selecting the filters, click Apply Filters button.
- The report lists the learner's:
- Email address
- Zone Name
- Segment
- Timestamp (time when the action occurred)
- Phishing Email (Subject of the phishing email that the learner received)
- Name of the Phishing block (Baseline, Campaign, Spear Phishing)
- IP address
- User Agent's workstation
- Attachment (Yes/No)
- Credential Capture link (Yes/No)
- QR Code (Yes/No)
- Action
- Excluded (If IP is part of CTR or not ; Yes/No)
- Department (if synched to Phriendly Phishing)
Warning
If you notice some of the results are not from your organisation this might indicate there are false positives in your data. For more information on false positives, refer to this article.
How to Download a Click Report
-
After selecting the filters of the report as documented in How to Run a Click Report, click the Download CSV button.
- Below definitions per report
- Historical Reports = Click Report since account creation
- Filtered Report = Click Report per current filters
- Click report by month = monthly click report
Comments
Article is closed for comments.