SimuPhish: Product & Feature Guide¶
Welcome to the SimuPhish Product & Feature Guide. This documentation provides security leaders, CISOs, risk committees, IT directors, and marketing teams with an exhaustive, business-oriented guide to the SimuPhish platform.
SimuPhish is an enterprise-grade Human Risk Management (HRM) and Multi-Vector Phishing Simulation platform designed to transform employees from an organization's greatest vulnerability into an active, resilient human defense perimeter.
🌟 The Executive Value Proposition¶
Modern cyber threats have expanded beyond standard email phishing. Threat actors orchestrate coordinated, multi-channel campaigns combining QR codes (Quishing), AI-cloned voice calls (Vishing), SMS (Smishing), WhatsApp messaging, malware payloads, and conversational social engineering.
Legacy Security Awareness Training (SAT) tools fail because they: * Rely on predictable, once-a-year generic slide decks that employees forget within 30 days. * Trigger false-positive clicks caused by automated corporate email scanners (Microsoft Defender Safe Links, Proofpoint URL Defense). * Only test basic email, leaving mobile, voice, physical, and messaging channels unaddressed. * Treat security training as a punitive "gotcha" exercise rather than an educational culture builder.
SimuPhish solves this by delivering continuous, 10-vector simulations, real-time behavioral telemetry, just-in-time teachable moments, AI incident triage, and audit-ready compliance reporting in a single unified SaaS platform.
graph TD
subgraph "The Multi-Vector Threat Landscape"
EmailThreat["Email Phishing & BEC"]
QRThreat["Quishing (QR Codes)"]
VoiceThreat["DeepFake AI Vishing"]
SMSThreat["Smishing (SMS)"]
MobileThreat["WhatsApp & Messaging"]
MalwareThreat["Ransomware & Droppers"]
PhysicalThreat["USB Baiting"]
end
subgraph "The SimuPhish Platform Defense"
Command["Operational Command Center"]
SimEngine["Attack Vector Arsenal (10 Vectors)"]
LMS["Resilience Academy & Gamification"]
Visual["Visual Strike & Comic Campaigns"]
Triage["Phish Detect & AI Incident Triage"]
Intel["Live Threat Watch & Attack Surface"]
Compliance["Compliance Shield (11 Frameworks)"]
end
subgraph "Measurable Business Outcomes"
RiskDrop["85%+ Drop in Phish-Prone %"]
AuditReady["Audit-Ready Proof (SOC 2, ISO, HIPAA)"]
Culture["Active Employee Defense Culture"]
SOAR["Automated SOC Incident Response"]
end
EmailThreat --> SimEngine
QRThreat --> SimEngine
VoiceThreat --> SimEngine
SMSThreat --> SimEngine
MobileThreat --> SimEngine
MalwareThreat --> SimEngine
PhysicalThreat --> SimEngine
SimEngine --> LMS
SimEngine --> Triage
SimEngine --> Intel
SimEngine --> Compliance
Command --> SimEngine
LMS --> RiskDrop
Compliance --> AuditReady
Visual --> Culture
Triage --> SOAR
🏛️ The 12 Strategic Pillars of SimuPhish¶
The platform is organized into twelve comprehensive operational modules:
- Platform Command Center: The executive overview dashboard, quick-launch campaign wizards, real-time security scorecards, and frictionless 60-second corporate domain email OTP verification.
- Human Attack Surface: Enterprise employee directory management, granular Human Risk Scores (HRS), dynamic Smart Groups, manager escalation hierarchies, and field workforce coverage.
- Attack Vector Arsenal (Simulations): 10 hyper-realistic attack vectors covering Email (PhishStrike), QR Codes (QuishFire), SMS (PingBreach), AI Voice (VoiceSnare), WhatsApp (MsgBreach), Ransomware (LockChain), USB Baiting (DriveDrop), Third-Party TPRM (VendorProbe), and Conversational AI (SimuGPT).
- Threat Forge Studio: Creative attack simulation lab with visual email drag-and-drop builder, real-time website cloner, QR generator, deepfake voice synthesis library, and realistic malware payload templates.
- Resilience Academy (LMS): Engaging micro-learning course catalog, Generative AI course builder, SCORM ingestion, automated remediation rules, learning intelligence, gamification leaderboards, and custom certificate design.
- Visual Strike, Comics & Broadcast: High-retention visual security education featuring 60-second visual drills, an AI-powered comic strip campaign studio, and branded monthly threat bulletins.
- Live Threat Watch: Continuous human attack surface monitoring, including Risk Radar, brand lookalike typosquatting detection, Shadow IT SaaS OAuth audits (Exposure Radar), and dark web credential exposure tracking.
- Phish Detect & Incident Triage: 1-Click threat reporting add-in for Outlook and Google Workspace, automated AI threat analysis, SOC inbox triage, and automated SOAR response workflows.
- Compliance Shield: Pre-mapped regulatory compliance frameworks (ISO 27001, SOC 2 Type II, HIPAA, GDPR, PCI-DSS v4.0, DORA) and deployable corporate policy acknowledgment workflows.
- Posture Reports & Executive Analytics: Modular C-suite executive dashboard widgets, domain-wise subsidiary posture reports, gamification engagement analytics, audit-ready compliance dossiers, live SSE monitoring, and industry risk benchmarking.
- Ecosystem Bridge & Evidence Vault: Automated SCIM 2.0 and IdP directory synchronization (Microsoft Entra ID, Google Workspace), tamper-evident administrative compliance trails, and real-time organization activity logs.
- Platform Settings & Configuration Guide: Exhaustive operational configuration guide covering personal profiles, white-label branding, RBAC permissions, custom domains, MFA/SSO, SIEM streaming, notification cadences, Direct Message Injection (DMI), and learner feedback surveys.
📊 Key Platform Metrics at a Glance¶
- Average Susceptibility Reduction: Drops from an industry baseline of 34.2% down to below 4.5% within 90 days of continuous multi-vector drills.
- Threat Reporting Velocity: Increases the percentage of employees actively reporting suspicious emails by over 400%.
- Audit Preparation Efficiency: Reduces compliance preparation time for SOC 2, ISO 27001, and HIPAA audits by up to 80% via automated evidence dossiers.
- Zero Mail Gateway False Positives: Built-in scanner defense heuristics filter out automated bot clicks (Microsoft Defender Safe Links, Proofpoint URL Defense), guaranteeing 100% human-accurate metrics.