Skip to content
ZK
ZAIN KHALIL KHAN
PORTFOLIO
All projects

Interactive build

Phish Sim | Awareness Campaign Modelling

Phishing simulation planner that models click rate, credential submission, and report rate per department across lure difficulty and completed training cycles, foregrounding credential entry on privileged accounts rather than raw click counts.

Live demo readySecurity Awareness + Phishing
Security AwarenessPhishingMetricsTrainingHuman RiskBlue TeamCase study / interactive demo

Case study

From problem to working system

Problem

Phishing simulation planner that models click rate, credential submission, and report rate per department across lure difficulty and completed training cycles, foregrounding credential entry on privileged accounts rather than raw click counts.

My role

Security engineer and full-stack developer

Solution

Phishing simulation planner that models click rate, credential submission, and report rate per department across lure difficulty and completed training cycles, foregrounding credential entry on privileged accounts rather than raw click counts.

Architecture

The implementation combines the following technologies and system concerns.

Security AwarenessPhishingMetricsTrainingHuman RiskBlue Team

How it was built

  • Modelled per-cohort baselines and trainability, because a single organisation-wide click rate hides where the residual risk actually sits.

Security decisions

  • Modelled per-cohort baselines and trainability, because a single organisation-wide click rate hides where the residual risk actually sits.
  • Elevated credential submission on privileged accounts as the headline risk metric, since that is the number that predicts an incident.

Major challenges

  • Applied diminishing returns per training cycle instead of assuming linear improvement, which is what the published data supports.
  • Weighted lure difficulty so an MFA re-enrolment pretext and a generic package notice are not treated as equivalent tests.
  • Elevated credential submission on privileged accounts as the headline risk metric, since that is the number that predicts an incident.

Verified evidence

Results and measurable impact

  • Applied diminishing returns per training cycle instead of assuming linear improvement, which is what the published data supports.
  • Tracked report rate as the only metric that improves detection rather than merely measuring users.

Screenshots and access

Product view

Interactive Demo

A scoped, fully functional recreation of this project's core feature runs below, live in your browser. Reset it, resize it, or expand it to full screen.

Phish Sim

Security platform

Phish SimWorkspace1 updates
Phish Sim · Campaign Plannerclick rate against a 40% worst-case scale
19.4% clicked

An awareness campaign is only useful if it measures the right thing. Click rate is the headline number, but credentials entered on a privileged account is the one that predicts an incident, and report rate is the only metric that improves detection rather than just shaming users. Lure difficulty scales all three.

Targets finance workflow directly. High click rate and high realism.

Targeted

175

5 cohorts

Click rate

19.4%

34 clicks

Credentials entered

14

5 on privileged accounts

Report rate

38%

the metric that improves detection

Clicked
19.4%click rate
Reported
38%report rate
Where the risk actually sits5 privileged credentials
Clicks that became credential submissions14 of 34
Submissions on privileged accounts5 of 14

Click rate is the number that gets reported. Credential submission on a privileged account is the number that predicts an incident.

Cohorts

After 1 cycle, residual risk concentrates in the cohorts with the lowest trainability. Those are the ones that need a control change, not another email.

Zain Khalil Khan