Sometimes I wonder whether all this "security awareness training" has any effect at all.
About 9 years ago I wrote a script that looked for links to domains registered to wombat (the company that most companies seem to use for phishing simulation) and would autoreport and delete them. So just never saw them.
Still had to do the training. Every six months.
One of my former managers had this habit of setting up email rules for known phishing simulation domains whenever he started somewhere new.
Microsoft domains listed in a table here for anyone else unfortunate enough to have to use their products within your org.
Only the hottest memes in Cybersecurity
About 9 years ago I wrote a script that looked for links to domains registered to wombat (the company that most companies seem to use for phishing simulation) and would autoreport and delete them. So just never saw them.
Still had to do the training. Every six months.
One of my former managers had this habit of setting up email rules for known phishing simulation domains whenever he started somewhere new.
Microsoft domains listed in a table here for anyone else unfortunate enough to have to use their products within your org.