All services
Phishing & Human Risk

Your firewall is solid.
But one employee clicked a link.

Technical controls don't stop social engineering. Phishing is the leading initial access vector because it bypasses everything you've hardened. The only defense is knowing who on your team would click, before attackers find out.

Authorization required before sending campaigns

Phishing simulations require prior written authorization from HR, legal counsel, and management. Horus enforces an explicit org-level approval step before any campaign is sent: the platform will not dispatch emails without it. Depending on your jurisdiction and sector (finance, healthcare, public administration), employee notification obligations or a Data Protection Impact Assessment may also apply. Check with your DPO or legal team before the first campaign.

Without phishing simulation
You don't know which employees would click a credential-harvesting lure. Attackers are willing to find out. You aren't running the test first.
Three of your finance employees have had their credentials leaked in third-party breaches. Nobody checked. Those passwords may still be in use.
Annual security awareness training is a checkbox. A PDF nobody reads, with no measurement of how people behave under pressure.
With Horus Phishing
PhishingAgent uses your asset inventory to craft context-aware lures, branded to your own domains and referencing real tools your team uses. Click tracking per target.
HIBP Domain Search runs against your org's email domain. Leaked employees flagged with the breach source and which data was exposed.
Repeat clickers identified automatically. Awareness landing page shown on click: education at the moment of failure instead of months later.
How it works

Profile. Craft. Send. Measure.

Campaigns are built from your own asset inventory, not generic templates. Every lure references something real about your org.

01 / PROFILE

Target list from your inventory

PhishingAgent reads your asset inventory: domain names, technologies in use, integrations. Builds a target profile per employee. Lures reference the tools they use day to day.

02 / CRAFT + SEND

Context-aware lure generated

Choose objective: click-only, credential harvest drill, or report-to-security training. MFA/OTP simulation available. Campaign sent on schedule, tracking pixel embedded.

03 / TRACK + EDUCATE

Analytics, then awareness

Click rate, credential entry rate, report rate. Department and repeat-offender breakdown. Clickers hit an awareness landing page immediately. Results feed into your security posture score.

Campaign results · acmecorp.io · 142 targets
Campaigns
Targets
Credential Exposure
1 running
3 campaigns · acmecorp.io sorted by launch date
Vendor Impersonation test
RunningClick test
156 targets · launched today
click rate —report rate —
Q2 Awareness · "IT password reset" lure
CompletedCredential lure
142 targets · launched 3 weeks ago
click rate 16.9%report rate 0.7%
Q1 IT Password Reset drill
CompletedCredential lure
138 targets · launched 4 months ago
click rate 34.2%report rate 3.6%
Q2 awareness drill · "IT password reset" lure launched 2026-06-20
j.smith@acmecorp.io · Finance
Clicked
m.rodriguez@acmecorp.io · Engineering
Clicked
a.chen@acmecorp.io · Security
Reported
d.walsh@acmecorp.io · Sales
Sent
t.nguyen@acmecorp.io · Support
Sent
24 clicked · 1 reported · 117 sent, no interaction 139 targets not shown Show all → Show less ↑
3 breaches found · 3 employees affected checked against HIBP daily
J. Smith · j.smith@acmecorp.io
Finance
SaaSVendor 2024 breach · emails, passwords, +1
2024-11-02
Sensitive
M. Rodriguez · m.rodriguez@acmecorp.io
Engineering
Combolist 2026 · emails, passwords
2026-05-02
Low risk
R. Patel · r.patel@acmecorp.io
Sales
Forum breach 2019 · usernames
2019-08-14
Low risk
Full capability set

Everything in Phishing & Human Risk.

Phishing simulation campaigns and credential exposure monitoring. Two sides of the same human-vector risk.

Social engineering

Phishing Campaigns

PhishingAgent reads your asset inventory to craft context-aware lures, branded to your domains and referencing real tools your team uses instead of generic templates. Choose objective: click-only, credential harvest drill, or report-to-security. Awareness landing page shown on click.

  • Asset-inventory-aware lure generation
  • Objective: click / credential / report drill
  • Per-target click and credential tracking
  • Fake MFA/OTP simulation
  • Department-level analytics
  • Repeat-offender identification
  • Awareness landing page on click
  • Schedule: one-off or recurring
HIBP integration

Credential Exposure

Have I Been Pwned Domain Search checks if your org's employees appear in public breach databases. Sensitive breach flag for passwords, tokens and other high-value data classes.

  • HIBP Domain Search integration
  • Sensitive breach detection
  • Breach source and data classes exposed
  • Per-employee and department breakdown
Posture impact

Human Risk Score

Click rates, credential entry rates and breach exposure combine into a human risk score that feeds into the org's overall security posture timeline. Drill down by department or individual.

  • Click rate and credential rate
  • Breach exposure count
  • Feeds posture timeline
  • Department vs overall comparison

Know who would click
before attackers test it.

The demo includes a live phishing campaign with click tracking and credential exposure results.